endurer - 2008-6-17 14:17:00
附件:
您所在的用户组无法下载或查看附件文件 aaa.exe 接收于 2008.06.17 08:09:58 (CET)
反病毒引擎 | 版本 | 最后更新 | 扫描结果 |
AhnLab-V3 | 2008.6.17.0 | 2008.06.16 | - |
AntiVir | 7.8.0.55 | 2008.06.17 | TR/Inject.HN.1 |
Authentium | 5.1.0.4 | 2008.06.17 | W32/Heuristic-210!Eldorado |
Avast | 4.8.1195.0 | 2008.06.16 | - |
AVG | 7.5.0.516 | 2008.06.16 | - |
BitDefender | 7.2 | 2008.06.17 | Trojan.Inject.HN |
CAT-QuickHeal | 9.50 | 2008.06.16 | - |
ClamAV | 0.93.1 | 2008.06.17 | PUA.Packed.UPack |
DrWeb | 4.44.0.09170 | 2008.06.17 | - |
eSafe | 7.0.15.0 | 2008.06.16 | Win32.Looked.gen |
eTrust-Vet | 31.6.5880 | 2008.06.17 | Win32/Zuten!generic |
Ewido | 4.0 | 2008.06.16 | - |
F-Prot | 4.4.4.56 | 2008.06.12 | W32/Heuristic-210!Eldorado |
F-Secure | 6.70.13260.0 | 2008.06.17 | W32/Suspicious_U.gen |
Fortinet | 3.14.0.0 | 2008.06.17 | - |
GData | 2.0.7306.1023 | 2008.06.17 | - |
Ikarus | T3.1.1.26.0 | 2008.06.17 | Trojan-Dropper.Win32.Agent.ane |
Kaspersky | 7.0.0.125 | 2008.06.17 | - |
McAfee | 5318 | 2008.06.16 | New Malware.n |
Microsoft | 1.3604 | 2008.06.17 | VirTool:Win32/Obfuscator.C |
NOD32v2 | 3192 | 2008.06.17 | probably a variant of Win32/TrojanDownloader.Small.NZK |
Norman | 5.80.02 | 2008.06.16 | W32/Suspicious_U.gen |
Panda | 9.0.0.4 | 2008.06.16 | Suspicious file |
Prevx1 | V2 | 2008.06.17 | - |
Rising | 20.49.10.00 | 2008.06.17 | - |
Sophos | 4.30.0 | 2008.06.17 | Mal/EncPk-BW |
Sunbelt | 3.0.1153.1 | 2008.06.15 | - |
Symantec | 10 | 2008.06.17 | Infostealer |
TheHacker | 6.2.92.352 | 2008.06.17 | W32/Behav-Heuristic-060 |
TrendMicro | 8.700.0.1004 | 2008.06.17 | TSPY_ONLNEG.AN |
VBA32 | 3.12.6.7 | 2008.06.17 | - |
VirusBuster | 4.3.26:9 | 2008.06.12 | Packed/Upack |
Webwasher-Gateway | 6.6.2 | 2008.06.17 | Trojan.Inject.HN.1 |
|
附加信息 |
File size: 11907 bytes |
MD5...: fe4402d5e3d1579ed56a777bec486506 |
SHA1..: 52617bf6d9dbb5700558d50535c008604ed4cad9 |
SHA256: eb22b94ae3796796247d410a423ac50e521081485b00cf33f7284b81c86e728b |
SHA512: 4b1227e45a527710d9faa4cf144aad158e73ae751f347f1dacb8908df811eb06<BR>702c435023a67136ec48accc43f72c00364dd0c554e9c2808bc686d8f9f9b5e6 |
PEiD..: WinUpack v0.39 final (relocated image base) -> By Dwing (c)2005 (h2) |
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x41088f<BR>timedatestamp.....: 0x1000 (Thu Jan 01 01:08:16 1970)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 2 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.Upack 0x1000 0xd000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR>.rsrc 0xe000 0xa000 0x2b6b 7.96 28c842afe98d6752398d248e462eb4f8<BR><BR>( 1 imports ) <BR>> KERNEL32.DLL: LoadLibraryA, GetProcAddress<BR><BR>( 0 exports ) <BR> |
packers (Authentium): UPack |
packers (F-Prot): UPack |
packers (Kaspersky): UPack, PE_Patch, PE_Patch |
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; Maxthon; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
轩辕小聪 - 2008-6-17 15:42:00
PEiD..: WinUpack v0.39 final (relocated image base) -> By Dwing (c)2005 (h2)
这个壳版本报得不对,不是final的,是beta2的。
艾玛 - 2008-6-17 15:51:00
我这里Upack V0.36-V0.37 (DLL) :default2:
瑞星查的upack0.34>>66
各家定义不一样?
endurer - 2008-6-17 18:02:00
VMUnpacker的检测结果为:
Upack V0.36-V0.37(DLL) -> Dwing [Overlay]:default6:
轩辕小聪 - 2008-6-17 21:04:00
分析:
http://bbs.ikaka.com/showtopic-8515537.aspx这只类机器狗的驱动,直接构造IRP并发送给文件系统的处理例程,这在以前的机器狗中比较少见。
RisingCSC - 2008-6-18 14:16:00
文件名:aaa.exe
病毒名:Rootkit.Win32.Agent.bcj
分析说明:
您所上报的病毒文件将在瑞星2008的20.49.20版本(瑞星2007的19.80.20版本)中处理解决,如遇到特殊问题可能会推后几个版本。
ruby_ghost - 2008-6-19 16:31:00
测试一下看看
© 2000 - 2025 Rising Corp. Ltd.