社区嘉宾
- 帖子:22020
- 注册:
2003-04-29
- 来自:pe_xscan Studio
|
发表于:
2008-06-16 09:41
|
只看楼主
短消息
资料
回复: 20.48.40 无反应的 guita.exe, fish.exe, explore.exe等9个
再补一个 这个是从马网的FTP下载的, 估计是最先下载的东东, 上面那些都是这个down 下来的 解压密码:virus 附件: 您所在的用户组无法下载或查看附件文件 ok.exe 接收于 2008.06.16 03:30:43 (CET) 反病毒引擎 | 版本 | 最后更新 | 扫描结果 | AhnLab-V3 | 2008.6.13.1 | 2008.06.15 | - | AntiVir | 7.8.0.55 | 2008.06.15 | DR/PcClient.Gen | Authentium | 5.1.0.4 | 2008.06.16 | - | Avast | 4.8.1195.0 | 2008.06.15 | - | AVG | 7.5.0.516 | 2008.06.15 | BackDoor.PcClient.2.Y | BitDefender | 7.2 | 2008.06.16 | Trojan.Crypt.DG | CAT-QuickHeal | 9.50 | 2008.06.14 | - | ClamAV | 0.92.1 | 2008.06.16 | - | DrWeb | 4.44.0.09170 | 2008.06.15 | - | eSafe | 7.0.15.0 | 2008.06.15 | - | eTrust-Vet | 31.6.5873 | 2008.06.14 | - | Ewido | 4.0 | 2008.06.15 | - | F-Prot | 4.4.4.56 | 2008.06.12 | - | F-Secure | 6.70.13260.0 | 2008.06.15 | PCClient.gen4 | Fortinet | 3.14.0.0 | 2008.06.15 | - | GData | 2.0.7306.1023 | 2008.06.16 | Backdoor.Win32.PcClient.dyd | Ikarus | T3.1.1.26.0 | 2008.06.16 | - | Kaspersky | 7.0.0.125 | 2008.06.16 | Backdoor.Win32.PcClient.dyd | McAfee | 5317 | 2008.06.13 | BackDoor-CKB | Microsoft | 1.3604 | 2008.06.16 | - | NOD32v2 | 3188 | 2008.06.15 | - | Norman | 5.80.02 | 2008.06.13 | PCClient.gen4 | Panda | 9.0.0.4 | 2008.06.15 | - | Prevx1 | V2 | 2008.06.16 | - | Rising | 20.48.62.00 | 2008.06.15 | - | Sophos | 4.30.0 | 2008.06.15 | - | Sunbelt | 3.0.1153.1 | 2008.06.15 | - | Symantec | 10 | 2008.06.15 | - | TheHacker | 6.2.92.350 | 2008.06.14 | - | VBA32 | 3.12.6.7 | 2008.06.14 | suspected of Malware.Agent.22 (paranoid heuristics) | VirusBuster | 4.3.26:9 | 2008.06.12 | Backdoor.PcClient.Gen.3 | Webwasher-Gateway | 6.6.2 | 2008.06.15 | Trojan.Dropper.PcClient.Gen |
| 附加信息 | File size: 65112 bytes | MD5...: 94a91d07d6fd5a7be6ff676c4f29bb56 | SHA1..: f494c598112ebdca320be07b77a4003a6e34f079 | SHA256: a3fe0526a1417d05b21ec700263a404e2590c3769fe986f853da387a44be5513 | SHA512: 0b522d25d5be2ea7a0d6fd64871c4ca4b6ade42badee48dce90d33d787fe8fbe<BR>3696f0dd3b4c7e0a7f88de0752faa5f3fafc2d54636da0aff617de3c92bd6762 | PEiD..: - | PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x40256f<BR>timedatestamp.....: 0x47496e1e (Sun Nov 25 12:44:14 2007)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x1712 0x1800 5.94 44e0a4c0df91414bd73f57e96ecd9eca<BR>.rdata 0x3000 0x662 0x800 4.20 1268ec43246e2b5cad3338b1b69b1c57<BR>.data 0x4000 0x1158 0x200 1.71 a2f6b868c40b8dd64fa0213057c3453d<BR><BR>( 6 imports ) <BR>> SHLWAPI.dll: StrChrA, StrStrA, StrToIntA<BR>> USER32.dll: PostThreadMessageA, wsprintfA<BR>> ADVAPI32.dll: DeleteService, OpenSCManagerA, OpenServiceA, CloseServiceHandle, QueryServiceStatus, ControlService<BR>> ole32.dll: CoCreateGuid<BR>> MSVCRT.dll: __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp, _adjust_fdiv, __setusermatherr, _initterm, _acmdln, exit, _XcptFilter, _exit, __CxxFrameHandler, time, srand, rand, memcpy, memset, __2@YAPAXI@Z, __3@YAXPAX@Z, __getmainargs<BR>> KERNEL32.dll: SetFilePointer, GetModuleFileNameA, DeleteFileA, GetModuleHandleA, GetStartupInfoA, ReadFile, CreateMutexA, GetLastError, GetFileAttributesExA, ReleaseMutex, lstrcpyA, lstrlenA, Sleep, LoadLibraryA, GetProcAddress, FreeLibrary, CreateFileA, WriteFile, GetSystemDirectoryA, lstrcatA, WaitForSingleObject, CloseHandle, GetFileTime, SetFileTime<BR><BR>( 0 exports ) <BR> |
这个FTP上面的马好多~
endurer 最后编辑于 2008-06-16 09:44:31
|