瑞星卡卡安全论坛技术交流区可疑文件交流 关于局域网共享文件夹setup.exe的问题

1   1  /  1  页   跳转

关于局域网共享文件夹setup.exe的问题

关于局域网共享文件夹setup.exe的问题


反病毒引擎
版本最后更新扫描结果
a-squared4.5.0.182009.07.10Packed.Win32.Klone!IK
AhnLab-V35.0.0.22009.07.09Win-Trojan/Pakes.82439
AntiVir7.9.0.2042009.07.10TR/Crypt.NSPM.Gen
Antiy-AVL2.0.3.12009.07.10Trojan/Win32.Pakes.gen
Authentium5.1.2.42009.07.09W32/Downloader.AT.gen!Eldorado
Avast4.8.1335.02009.07.09Win32:Trojan-gen {Other}
AVG8.5.0.3872009.07.09Generic13.AZVS
BitDefender7.22009.07.10Trojan.Generic.1999850
CAT-QuickHeal10.002009.07.10Trojan.Pakes.nkm
ClamAV0.94.12009.07.09Trojan.Pakes-2474
Comodo16012009.07.10-
DrWeb5.0.0.121822009.07.10Win32.HLLP.Whboy.113
eSafe7.0.17.02009.07.09Win32.TRCrypt.Nspm
eTrust-Vet31.6.66062009.07.09Win32/Emerleox.HA
F-Prot4.4.4.562009.07.09W32/Downloader.AT.gen!Eldorado
F-Secure8.0.14470.02009.07.10Trojan.Win32.Pakes.nkm
Fortinet3.117.0.02009.07.03-
GData192009.07.10Trojan.Generic.1999850
IkarusT3.1.1.64.02009.07.10Packed.Win32.Klone
Jiangmin11.0.7062009.07.09-
K7AntiVirus7.10.7882009.07.09-
Kaspersky7.0.0.1252009.07.10Trojan.Win32.Pakes.nkm
McAfee56712009.07.09W32/Fujacks.aw
McAfee+Artemis56712009.07.09W32/Fujacks.aw
McAfee-GW-Edition6.8.52009.07.10Heuristic.BehavesLike.Packed.H
Microsoft1.48032009.07.10Trojan:Win32/Pakes.K
NOD3242302009.07.10Win32/Fujacks.BK
Norman6.01.092009.07.09Packed_Nspack.K
nProtect2009.1.8.02009.07.10Trojan/W32.Packer.164904.B
Panda10.0.0.142009.07.09W32/Radoppan.AT
PCTools4.4.2.02009.07.09Packed/NSPack
Prevx3.02009.07.10-
Rising21.37.41.002009.07.10Win32.BMW.ba
Sophos4.43.02009.07.10W32/Fujacks-BD
Sunbelt3.2.1858.22009.07.10Trojan.Win32.Packer.NsPackv3.1 (v)
Symantec1.4.4.122009.07.10W32.Fujacks.CA
TheHacker6.3.4.3.3632009.07.08Trojan/Pakes.nkm
TrendMicro8.950.0.10942009.07.10PE_FUJACKS.DE
VBA323.12.10.82009.07.10Trojan.Win32.Pakes.nkm
ViRobot2009.7.10.18282009.07.10Trojan.Win32.Pakes.82439
VirusBuster4.6.5.02009.07.09Packed/NSPack
附加信息
File size: 164904 bytes
MD5...: 96463b8a480bef59d354d7c8907883b2
SHA1..: 749e73985dc66de9cce468dcfcf948ffa364e0a7
SHA256: 19f201fbfce1c4643b8095df2cffe4743b504bf3aafcde8f2ba20cfcf123a216
ssdeep: 3072:W3YE69JIao5rxC7DKu83YE69JIao5rxC7DKuL:Al5rxCfGl5rxCfL
PEiD..: NsPack v3.1 -> North Star (h)
TrID..: File type identification
Win32 Executable Generic (38.4%)
Win32 Dynamic Link Library (generic) (34.1%)
Win16/32 Executable Delphi generic (9.3%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4c3d3
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.nsp0 0x1000 0x4b000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.nsp1 0x4c000 0x13a8d 0x12800 7.98 541c6d055a7c498eeabcb8305f1752bc
.rsrc 0x60000 0x144c 0x1600 1.72 7d0e3508ca80810d12fb15ae3649158d

( 12 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> USER32.DLL: GetKeyboardType
> ADVAPI32.DLL: RegQueryValueExA
> OLEAUT32.DLL: SysFreeString
> MPR.DLL: WNetCancelConnectionA
> GDI32.DLL: UnrealizeObject
> SHELL32.DLL: ShellExecuteExA
> OLE32.DLL: CoUninitialize
> WININET.DLL: InternetGetConnectedState
> URLMON.DLL: URLDownloadToFileA
> WSOCK32.DLL: WSACleanup
> NETAPI32.DLL: NetRemoteTOD

( 0 exports )
PDFiD.: -
RDS...: NSRL Reference Data Set
-
packers (Avast): NsPack
packers (Authentium): NSPack
packers (F-Prot): NSPack


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)

附件附件:

您所在的用户组无法下载或查看附件

分享到:
gototop
 

回复: 关于局域网共享文件夹setup.exe的问题

以上是在 VirusTotal 扫描的结果
但这究竟是个啥东西呢 杀毒软件也杀不到,删掉过会又出现,能彻底清除掉吗?
局域网内几乎每个可读写的共享文件夹下都有一个。
gototop
 

回复:关于局域网共享文件夹setup.exe的问题

谢谢两位了  周末 全网杀毒看看
但这个病毒会不会使其他执行程序也都中毒呢
目前发现中毒的机子会运行缓慢,而且会死机。
有的电脑里存些软件的安装程序,需要一起删除吗?
最后编辑markari_office 最后编辑于 2009-07-11 10:36:48
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT