1   1  /  1  页   跳转

Trojan.Win32.StartPage.cyk

Trojan.Win32.StartPage.cyk

文件 taskmagr.exe 接收于 2008.11.12 11:42:31 (CET)
结果: 21/36 (58.34%)

反病毒引擎版本最后更新扫描结果
AhnLab-V32008.11.11.22008.11.12-
AntiVir7.9.0.312008.11.12TR/StartPage.cyk
Authentium5.1.0.42008.11.12-
Avast4.8.1248.02008.11.11Win32:Trojan-gen {Other}
AVG8.0.0.1612008.11.11Startpage.DGL
BitDefender7.22008.11.12-
CAT-QuickHeal9.502008.11.12-
ClamAV0.94.12008.11.12-
DrWeb4.44.0.091702008.11.12-
eSafe7.0.17.02008.11.11-
eTrust-Vet31.6.62032008.11.11-
Ewido4.02008.11.11-
F-Prot4.4.4.562008.11.11-
F-Secure8.0.14332.02008.11.12Trojan.Win32.StartPage.cyk
Fortinet3.117.0.02008.11.12W32/StartPage.CYK!tr
GData192008.11.12Win32:Trojan-gen {Other}
IkarusT3.1.1.45.02008.11.12Trojan.Win32.StartPage.cyk
K7AntiVirus7.10.5222008.11.11Trojan.Win32.StartPage.cyk
Kaspersky7.0.0.1252008.11.12Trojan.Win32.StartPage.cyk
McAfee54312008.11.12Generic StartPage
Microsoft1.41042008.11.12Trojan:Win32/Dreammon.C
NOD3236052008.11.12Win32/Agent.OKM
Norman5.80.022008.11.11W32/Startpage.KBG
Panda9.0.0.42008.11.11Suspicious file
PCTools4.4.2.02008.11.11-
Prevx1V22008.11.12Worm
Rising21.03.22.002008.11.12-
SecureWeb-Gateway6.7.62008.11.12Trojan.StartPage.cyk
Sophos4.35.02008.11.12Mal/Behav-204
Sunbelt3.1.1785.22008.11.11Backdoor.Win32.S (vf)
Symantec102008.11.12-
TheHacker6.3.1.1.1492008.11.12-
TrendMicro8.700.0.10042008.11.12TROJ_STARTPA.JE
VBA323.12.8.92008.11.11Trojan.Win32.StartPage.cyk
ViRobot2008.11.12.14632008.11.12Spyware.StartPage.91648
VirusBuster4.5.11.02008.11.11-
附加信息
File size: 91648 bytes
MD5...: 8e4dc48b5b3595378f5a157acd9137d0
SHA1..: 5254c1124e6378363bd5a632cc6643c137337c31
SHA256: 2f5b8cba8649a58313702ec93599f811b45b747862b90c447154a43b009d100b
SHA512: 54f68ef7a1228e4a367fd9c05f4c8d3722aa692f9cbc5d914d99c20c7cae7ac9
77952667979a55e9e3c4a8c9f7939cdf43e9de4e8d1bda5323bf46289317ce0d
PEiD..: Armadillo v1.71
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4150ef
timedatestamp.....: 0x490f0548 (Mon Nov 03 14:06:00 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1461e 0x14800 6.92 2de2ed2ae7bb3a0d25a55adc8c25e3e0
.rdata 0x16000 0xde0 0xe00 4.98 2a41abb675b2a4d182a9ff70af3a1b49
.data 0x17000 0xd4c 0xc00 4.67 d55d9a520d1087dbda0f6bfedc59a600

( 7 imports )
> KERNEL32.dll: Sleep, SuspendThread, DeleteFileA, WinExec, ResumeThread, MoveFileExA, CreateThread, MultiByteToWideChar, lstrlenA, WideCharToMultiByte, lstrlenW, LeaveCriticalSection, EnterCriticalSection, WriteFile, DeleteCriticalSection, ReadFile, GetFileSize, CreateFileA, GetVolumeInformationA, GetProcAddress, FreeLibrary, LoadLibraryA, ReleaseMutex, WaitForSingleObject, WaitNamedPipeA, GetLastError, CreateMutexA, GetStartupInfoA, GetModuleHandleA, InitializeCriticalSection, GetTempPathA, GetSystemDirectoryA, CloseHandle, GetPrivateProfileStringA
> USER32.dll: CharLowerA, SystemParametersInfoA, CharUpperA, ShowWindow, SendMessageA, SetCursorPos, ClientToScreen, FindWindowExA, RegisterWindowMessageA, SendMessageTimeoutA, FindWindowA, GetWindowThreadProcessId, mouse_event, SetForegroundWindow
> ADVAPI32.dll: RegCloseKey, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA
> ole32.dll: CoCreateInstance, CoInitialize, CoUninitialize
> OLEAUT32.dll: -, -, -, -
> MSVCRT.dll: __CxxFrameHandler, _stricmp, _controlfp, _except_handler3, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _XcptFilter, _exit, strncmp, strstr, srand, rand, sprintf, atoi, malloc, free, localtime, time, _strlwr, wcscmp, strncpy
> NETAPI32.dll: Netbios

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogr ... 1D866228100984524B5

附件附件:

您所在的用户组无法下载或查看附件

最后编辑hyperion 最后编辑于 2008-11-12 18:58:39
分享到:
gototop
 

回复:Trojan.Win32.StartPage.cyk

一个样本最早可以追溯到11.5日的病毒,现在(20.70.22 2008-11-12 15:26)还无法查杀!!

我只是一个普通用户,三个月内这是第三次提交类似的病毒样本了
gototop
 

回复:Trojan.Win32.StartPage.cyk

您好,您的文件已经收集并进行分析,有结果会给你回复。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT