一个奇怪的病毒
里面有两个文件,杀毒网查杀没有毒,但用打开运行时360报灰鸽子;误报???????
我检查了,没有捆绑;
杀毒报告:
、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、、
文件 Demo.exe 接收于 2009.06.06 01:07:55 (UTC)
反病毒引擎 | 版本 | 最后更新 | 扫描结果 |
a-squared | 4.0.0.101 | 2009.06.04 | - |
AhnLab-V3 | 5.0.0.2 | 2009.06.05 | - |
AntiVir | 7.9.0.180 | 2009.06.05 | - |
Antiy-AVL | 2.0.3.1 | 2009.06.05 | - |
Authentium | 5.1.2.4 | 2009.06.05 | - |
Avast | 4.8.1335.0 | 2009.06.05 | - |
AVG | 8.5.0.339 | 2009.06.05 | - |
BitDefender | 7.2 | 2009.06.06 | - |
CAT-QuickHeal | 10.00 | 2009.06.05 | - |
ClamAV | 0.94.1 | 2009.06.05 | - |
Comodo | 1267 | 2009.06.06 | - |
DrWeb | 5.0.0.12182 | 2009.06.06 | - |
eSafe | 7.0.17.0 | 2009.06.04 | - |
eTrust-Vet | 31.6.6542 | 2009.06.05 | - |
F-Prot | 4.4.4.56 | 2009.06.05 | - |
F-Secure | 8.0.14470.0 | 2009.06.05 | - |
Fortinet | 3.117.0.0 | 2009.06.05 | - |
GData | 19 | 2009.06.06 | - |
Ikarus | T3.1.1.59.0 | 2009.06.06 | - |
K7AntiVirus | 7.10.754 | 2009.06.04 | - |
Kaspersky | 7.0.0.125 | 2009.06.06 | - |
McAfee | 5637 | 2009.06.05 | - |
McAfee+Artemis | 5637 | 2009.06.05 | - |
McAfee-GW-Edition | 6.7.6 | 2009.06.05 | - |
Microsoft | 1.4701 | 2009.06.05 | - |
NOD32 | 4134 | 2009.06.05 | - |
Norman | 6.01.09 | 2009.06.05 | - |
nProtect | 2009.1.8.0 | 2009.06.05 | - |
Panda | 10.0.0.14 | 2009.06.05 | - |
PCTools | 4.4.2.0 | 2009.06.05 | - |
Prevx | 3.0 | 2009.06.06 | - |
Rising | 21.32.44.00 | 2009.06.05 | - |
Sophos | 4.42.0 | 2009.06.06 | - |
Sunbelt | 3.2.1858.2 | 2009.06.06 | - |
Symantec | 1.4.4.12 | 2009.06.06 | - |
TheHacker | 6.3.4.3.340 | 2009.06.05 | - |
TrendMicro | 8.950.0.1092 | 2009.06.05 | - |
VBA32 | 3.12.10.6 | 2009.06.06 | - |
ViRobot | 2009.6.5.1771 | 2009.06.05 | - |
VirusBuster | 4.6.5.0 | 2009.06.05 | - |
|
附加信息 |
File size: 537600 bytes |
MD5...: 20e9e21276da0c6c901c5f3aa88a31fe |
SHA1..: a7b214926a0ec304b1ec70d2c8a6f0eb7877c2e0 |
SHA256: 88c882a1497be726c91ab92b5f4b075abf8a4f005306e103c5c4d3e1fb7e5279 |
ssdeep: -<BR> |
PEiD..: ASPack v2.12 |
TrID..: File type identification<BR>ASPack compressed Win32 Executable (generic) (90.1%)<BR>Win32 Executable Generic (5.7%)<BR>Win16/32 Executable Delphi generic (1.3%)<BR>Generic Win/DOS Executable (1.3%)<BR>DOS Executable Generic (1.3%) |
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x12d001<BR>timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 10 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>CODE 0x1000 0xde000 0x55e00 8.00 1ad7b3ff7fc3176530bbd5c78b7b33b8<BR>DATA 0xdf000 0x3000 0x1000 7.62 8b35566864a42753e24433a33b2c3ded<BR>BSS 0xe2000 0x1000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR>.idata 0xe3000 0x3000 0x1000 7.64 661fe8d38eb505eefba53aa4a66e667d<BR>.tls 0xe6000 0x1000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR>.rdata 0xe7000 0x1000 0x200 0.20 0b259a509b2e25bead53aee81575aee0<BR>.reloc 0xe8000 0xe000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR>.rsrc 0xf6000 0x37000 0x28e00 7.97 da087048316772c809de93292160ebf5<BR>.aspack 0x12d000 0x3000 0x2200 5.84 91e9c1e297705ab75831e75886437f0f<BR>.adata 0x130000 0x1000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR><BR>( 12 imports ) <BR>> kernel32.dll: GetProcAddress, GetModuleHandleA, LoadLibraryA<BR>> user32.dll: GetKeyboardType<BR>> advapi32.dll: RegQueryValueExA<BR>> oleaut32.dll: SysFreeString<BR>> advapi32.dll: RegQueryValueExA<BR>> version.dll: VerQueryValueA<BR>> gdi32.dll: UnrealizeObject<BR>> user32.dll: WindowFromPoint<BR>> oleaut32.dll: SafeArrayPtrOfIndex<BR>> comctl32.dll: ImageList_SetIconSize<BR>> winspool.drv: OpenPrinterA<BR>> comdlg32.dll: PrintDlgA<BR><BR>( 0 exports ) <BR> |
PDFiD.: - |
RDS...: NSRL Reference Data Set<BR>- |
packers (Kaspersky): ASPack |
packers (F-Prot): Aspack |
CWSandbox info: <a href='http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=20e9e21276da0c6c901c5f3aa88a31fe' target='_blank'>http://research.sunbelt-software ... 01c5f3aa88a31fe&;lt;/a> |
/////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; User-agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; http://bsalsa.com) ; .NET CLR 2.0.50727; TheWorld)