瑞星卡卡安全论坛技术交流区可疑文件交流 C:\Documents and Settings\user\Local Settings\Temp\mmc.exe

1   1  /  1  页   跳转

C:\Documents and Settings\user\Local Settings\Temp\mmc.exe

C:\Documents and Settings\user\Local Settings\Temp\mmc.exe


 附件: 您所在的用户组无法下载或查看附件

解压密码:virus

文件说明符 : C:\Documents and Settings\user\Local Settings\Temp\mmc.exe
属性 : A---
数字签名:否
PE文件:是
获取文件版本信息大小失败!
创建时间 : 2008-9-5 16:8:56
修改时间 : 2008-9-5 16:8:58
大小 : 18576 字节 18.144 KB
MD5 : 031f54c108e06d032a39a47fc87eb447
SHA1: 7C236055A371644348B5DDC519B77F1B5C1917CF
CRC32: 5d9472aa


文件 mmc.exe 接收于 2008.09.07 17:18:21 (CET)
反病毒引擎版本最后更新扫描结果
AhnLab-V32008.9.6.02008.09.07Win-Trojan/OnlineGameHack.B
AntiVir7.8.1.282008.09.05TR/Dropper.Gen
Authentium5.1.0.42008.09.07W32/Agent.L.gen!Eldorado
Avast4.8.1195.02008.09.06Win32:Agent-ZMQ
AVG8.0.0.1612008.09.07Generic11.QAX
BitDefender7.22008.09.07Dropped:Generic.Malware.P!dldPk!.B2BE84F9
CAT-QuickHeal9.502008.09.06(Suspicious) - DNAScan
ClamAV0.93.12008.09.07-
DrWeb4.44.0.091702008.09.07Trojan.MulDrop.18752
eSafe7.0.17.02008.09.07Suspicious File
eTrust-Vet31.6.60722008.09.05-
Ewido4.02008.09.07-
F-Prot4.4.4.562008.09.07W32/Agent.L.gen!Eldorado
F-Secure8.0.14332.02008.09.07Trojan-GameThief.Win32.OnLineGames.tbdi
Fortinet3.112.0.02008.09.07W32/Heuri.E
GData192008.09.07Trojan-GameThief.Win32.OnLineGames.tbdi
IkarusT3.1.1.34.02008.09.07-
K7AntiVirus7.10.4432008.09.05Trojan-GameThief.Win32.OnLineGames.tbdi
Kaspersky7.0.0.1252008.09.07Trojan-GameThief.Win32.OnLineGames.tbdi
McAfee53782008.09.05PWS-Mmorpg.gen
Microsoft1.39032008.09.07VirTool:WinNT/Idicaf.C
NOD32v234232008.09.06probably unknown NewHeur_PE virus
Norman5.80.022008.09.05W32/Packed_Upack.A
Panda9.0.0.42008.09.07Trj/Lineage.BZE
PCTools4.4.2.02008.09.07Packed/Upack
Prevx1V22008.09.07-
Rising20.60.62.002008.09.07-
Sophos4.33.02008.09.07Mal/Emogen-N
Sunbelt3.1.1610.12008.09.05VIPRE.Suspicious
Symantec102008.09.07Infostealer.Onlinegame
TheHacker6.3.0.8.0752008.09.06W32/Behav-Heuristic-060
TrendMicro8.700.0.10042008.09.05TSPY_ONLINEG.NHD
VBA323.12.8.52008.09.07Trojan.Win32.KillAV.alu
ViRobot2008.9.5.13652008.09.06Spyware.PSW.OnLineGames.18576
VirusBuster4.5.11.02008.09.07Packed/Upack
Webwasher-Gateway6.6.22008.09.05Trojan.Dropper.Gen


附加信息
File size: 18576 bytes
MD5...: 031f54c108e06d032a39a47fc87eb447
SHA1..: 7c236055a371644348b5ddc519b77f1b5c1917cf
SHA256: 838f8f99c9cbf1e4fb9c8f50524cc581c6e90e4f0b9baaf0ca0a1745378d098c
SHA512: 385f7c1438f61bb086f5b0a2b6653aec575e25b9e986927f14e2c25db13bef32
d27c4eda5336dd21e4b995d8aac729292ee0610e1a67972d5465db57d825c3c1
PEiD..: -
TrID..: File type identification
DOS Executable Generic (100.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x401018
timedatestamp.....: 0x4011b0be (Fri Jan 23 23:39:42 2004)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
PS 0x1000 0xa000 0x1f0 5.14 4d2cb10b2466b13ac206b0c80cbf5923
@h@ 0xb000 0xc000 0x4690 7.99 8256043a7a1e8dd5ac61ed54516ed6b9
l@@ 0x17000 0x1000 0x1f0 5.14 4d2cb10b2466b13ac206b0c80cbf5923

( 0 imports )

( 0 exports )
packers (Kaspersky): PE_Patch, UPack
packers (Avast): Upack
packers (Authentium): UPack
packers (F-Prot): UPack


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Maxthon)
最后编辑麦青儿 最后编辑于 2008-09-08 00:12:48
http://blog.csdn.net/purpleendurer

宠辱不惊,笑看堂前花开花落; 去留无意,漫随天外云卷云舒。
分享到:
gototop
 

回复:C:\Documents and Settings\user\Local Settings\Temp...

该用户帖子内容已被屏蔽
最后编辑zg1_2004 最后编辑于 2008-09-08 00:21:01
gototop
 

回复:C:\Documents and Settings\user\Local Settings\Temp...

文件名:mmc.exe
病毒名:Trojan.Win32.Undef.qgo


您所上报的病毒文件将在瑞星2008的20.61.11版本中处理解决,如遇特殊问题可能会推后几个版本。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT