12   2  /  2  页   跳转

[求助] 看看是不是病毒?

回复: 看看是不是病毒?



引用:
原帖由 帝国皇族 于 2009-8-10 11:09:00 发表
希望你们拿到多引擎扫描去看...连卡巴都报病毒

呵呵,两天前的在线扫描结果确实不是,今天就有报毒了

反病毒引擎版本最后更新扫描结果
a-squared4.5.0.242009.08.09Trojan.Win32.DrvFormat!IK
AhnLab-V35.0.0.22009.08.08-
AntiVir7.9.0.2482009.08.07-
Antiy-AVL2.0.3.72009.08.07-
Authentium5.1.2.42009.08.09-
Avast4.8.1335.02009.08.08-
AVG8.5.0.4062009.08.09Generic14.TBD
BitDefender7.22009.08.09-
CAT-QuickHeal10.002009.08.08-
ClamAV0.94.12009.08.07-
Comodo19182009.08.09-
DrWeb5.0.0.121822009.08.09-
eSafe7.0.17.02009.08.06-
eTrust-Vet31.6.66672009.08.08-
F-Prot4.4.4.562009.08.09-
F-Secure8.0.14470.02009.08.09Trojan.Win32.FormatAll.t
Fortinet3.120.0.02009.08.09W32/FormatAll.T!tr
GData192009.08.09-
IkarusT3.1.1.64.02009.08.09Trojan.Win32.DrvFormat
Jiangmin11.0.8002009.08.09-
K7AntiVirus7.10.8142009.08.08-
Kaspersky7.0.0.1252009.08.09Trojan.Win32.FormatAll.t
McAfee57032009.08.08-
McAfee+Artemis57032009.08.08Artemis!7A947821ED51
McAfee-GW-Edition6.8.52009.08.09-
Microsoft1.49032009.08.09-
NOD3243182009.08.08Win32/KillDisk.NAK
Norman6.01.092009.08.07-
nProtect2009.1.8.02009.08.09-
Panda10.0.0.142009.08.08Suspicious file
PCTools4.4.2.02009.08.08-
Prevx3.02009.08.09-
Rising21.41.62.002009.08.09-
Sophos4.44.02009.08.09-
Sunbelt3.2.1858.22009.08.08-
Symantec1.4.4.122009.08.09-
TheHacker6.3.4.3.3782009.08.08-
TrendMicro8.950.0.10942009.08.08-
VBA323.12.10.92009.08.09-
ViRobot2009.8.8.18752009.08.08-
VirusBuster4.6.5.02009.08.08-
附加信息
File size: 28672 bytes
MD5  : 7a947821ed51462b8e59e7cbf04def17
SHA1  : 0d7d0becfd0a81e78c6ea826f20d95b9a199f4a0
SHA256: 247da800cdf90f02b30b20dcd34b873d1716d3cbe1c06489ad956023a668cafb
PEInfo: PE Structure information
       
        ( base data )
        entrypointaddress.: 0x1248
        timedatestamp.....: 0x4A7ADD7D (Thu Aug  6 15:41:17 2009)
        machinetype.......: 0x14C (Intel I386)
       
        ( 3 sections )
        name viradd virsiz rawdsiz ntrpy md5
        .text 0x1000 0x3028 0x4000 4.05 fa64925961b3bb39987c8cd4e0e9f0fe
.data 0x5000 0xA04 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rsrc 0x6000 0x6D4 0x1000 1.06 d6ffa1c1b3b54cbd7fb8966f63737f62
       
        ( 1 imports )
       
>msvbvm60.dll: _CIcos, _adj_fptan, __vbaVarMove, __vbaFreeVar,__vbaFreeVarList, __vbaEnd, _adj_fdiv_m64, __vbaFreeObjList,_adj_fprem1, __vbaStrCat, __vbaHresultCheckObj, _adj_fdiv_m32,__vbaObjSet, -, _adj_fdiv_m16i, _adj_fdivr_m16i, _CIsin, __vbaChkstk,__vbaFileClose, EVENT_SINK_AddRef, __vbaStrCmp, _adj_fpatan,EVENT_SINK_Release, -, _CIsqrt, EVENT_SINK_QueryInterface,__vbaExceptHandler, __vbaPrintFile, _adj_fprem, _adj_fdivr_m64,__vbaFPException, __vbaStrVarVal, -, _CIlog, __vbaFileOpen, __vbaNew2,_adj_fdiv_m32i, _adj_fdivr_m32i, __vbaFreeStrList, -, _adj_fdivr_m32,_adj_fdiv_r, -, __vbaVarDup, __vbaVarCopy, _CIatan, __vbaStrMove,_allmul, _CItan, _CIexp, __vbaFreeStr, __vbaFreeObj
       
        ( 0 exports )
       
TrID  : File type identification
Win32 Executable Microsoft Visual Basic 6 (96.9%)
Generic Win/DOS Executable (1.5%)
DOS Executable Generic (1.5%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=7a947821ed51462b8e59e7cbf04def17
ssdeep: 384:tSD+HSp2fRNajIR+Hs1CrwZQdojZXC2Nl:tg+maZS2v
PEiD  : -
RDS  : NSRL Reference Data Set
gototop
 

回复:看看是不是病毒?

好熟悉的文件名字,好像有人在2010区提过
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT