|
笑看山河
- 组别:初生襁褓狮
- 性别:
- 来自:
- 积分:92
- 帖子:37
- 注册:
2009-07-27
|
回复: adware.win32/rugo怎么杀?急!!!
C:\Windows\system32\ctc6.exe分析结果: | 反病毒引擎 | 版本 | 最后更新 | 扫描结果 | | a-squared | 4.5.0.24 | 2009.07.28 | Trojan.Win32.Jhee!IK | | AhnLab-V3 | 5.0.0.2 | 2009.07.28 | - | | AntiVir | 7.9.0.228 | 2009.07.28 | - | | Antiy-AVL | 2.0.3.7 | 2009.07.28 | - | | Authentium | 5.1.2.4 | 2009.07.27 | - | | Avast | 4.8.1335.0 | 2009.07.27 | Win32:BHO-WD | | AVG | 8.5.0.387 | 2009.07.27 | - | | BitDefender | 7.2 | 2009.07.28 | Trojan.Crypt.HY | | CAT-QuickHeal | 10.00 | 2009.07.28 | - | | ClamAV | 0.94.1 | 2009.07.28 | - | | Comodo | 1791 | 2009.07.28 | - | | DrWeb | 5.0.0.12182 | 2009.07.28 | Trojan.DownLoader.origin | | eSafe | 7.0.17.0 | 2009.07.27 | - | | eTrust-Vet | 31.6.6642 | 2009.07.27 | Win32/Gnuro!generic | | F-Prot | 4.4.4.56 | 2009.07.27 | - | | F-Secure | 8.0.14470.0 | 2009.07.28 | - | | Fortinet | 3.120.0.0 | 2009.07.28 | - | | GData | 19 | 2009.07.28 | Trojan.Crypt.HY | | Ikarus | T3.1.1.64.0 | 2009.07.28 | Trojan.Win32.Jhee | | Jiangmin | 11.0.800 | 2009.07.28 | Adware/MsLock.jy | | K7AntiVirus | 7.10.803 | 2009.07.27 | - | | Kaspersky | 7.0.0.125 | 2009.07.28 | Trojan.Win32.BHO.xsg | | McAfee | 5690 | 2009.07.27 | - | | McAfee+Artemis | 5690 | 2009.07.27 | Artemis!F39923544744 | | McAfee-GW-Edition | 6.8.5 | 2009.07.28 | Heuristic.BehavesLike.Win32.Downloader.H | | Microsoft | 1.4903 | 2009.07.28 | Trojan:Win32/Jhee.V | | NOD32 | 4283 | 2009.07.28 | a variant of Win32/Adware.BHO.GBP | | Norman | 6.01.09 | 2009.07.27 | - | | nProtect | 2009.1.8.0 | 2009.07.27 | - | | Panda | 10.0.0.14 | 2009.07.27 | Generic Trojan | | PCTools | 4.4.2.0 | 2009.07.27 | - | | Prevx | 3.0 | 2009.07.28 | - | | Rising | 21.40.11.00 | 2009.07.28 | - | | Sophos | 4.44.0 | 2009.07.28 | - | | Sunbelt | 3.2.1858.2 | 2009.07.28 | - | | Symantec | 1.4.4.12 | 2009.07.28 | - | | TheHacker | 6.3.4.3.375 | 2009.07.28 | - | | TrendMicro | 8.950.0.1094 | 2009.07.28 | - | | VBA32 | 3.12.10.9 | 2009.07.28 | - | | ViRobot | 2009.7.28.1856 | 2009.07.28 | - | | VirusBuster | 4.6.5.0 | 2009.07.27 | - |
| 附加信息 | | File size: 122880 bytes | | MD5 : f399235447443b579ee8dd9494168430 | | SHA1 : 737c6456a7ba7518930521af5cce8ffb85e7a2ce | | SHA256: 97ec680a159f7a8e9a66ec0fd2ddabd04ee89c38b4cd8e603647bd495d2d0124 | PEInfo: PE Structure information ( base data ) entrypointaddress.: 0xE1AE timedatestamp.....: 0x4A6D0545 (Mon Jul 27 03:39:17 2009) machinetype.......: 0x14C (Intel I386) ( 4 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x160A5 0x17000 6.50 6c80037a7c7ec52a6e5a0b93cbbbbf23 .rdata 0x18000 0x2BC2 0x3000 4.46 059c42e52e893d7896c5a1ed60c29287 .data 0x1B000 0x41E8 0x2000 3.60 d590fa267fa92ed6d06644667261a67c .rsrc 0x20000 0x3F8 0x1000 1.09 8d24a71953224e1fc7ff56f3f47629b0 ( 6 imports ) >advapi32.dll: RegisterServiceCtrlHandlerA, RegQueryValueExA,SetServiceStatus, StartServiceCtrlDispatcherA, ControlService,DeleteService, StartServiceA, QueryServiceStatus, CreateServiceA,ChangeServiceConfig2A, RegCreateKeyA, RegSetValueExA, OpenSCManagerA,OpenServiceA, CloseServiceHandle, DeregisterEventSource, RegSetValueA,GetUserNameA, CreateProcessAsUserA, OpenProcessToken,RegNotifyChangeKeyValue, RegOpenKeyA, RegEnumValueA, RegOpenKeyExA,RegCloseKey, RegQueryInfoKeyA > kernel32.dll: GetTempFileNameA,GetTempPathA, ReadFile, CreateFileA, DeviceIoControl, GetModuleHandleA,Sleep, GetLocalTime, lstrlenA, MultiByteToWideChar,WideCharToMultiByte, LocalFree, SetEndOfFile, SetStdHandle,IsBadCodePtr, GetLastError, GetModuleFileNameA, GetProcessHeap,CreateDirectoryA, GetSystemDirectoryA, GetShortPathNameA,GetLogicalDrives, GetVolumeInformationA, OpenMutexA,CreateToolhelp32Snapshot, Process32First, Process32Next, OpenProcess,GetFileAttributesA, DeleteFileA, CreateProcessA, WaitForSingleObject,CloseHandle, SetFileAttributesA, CopyFileA, SetPriorityClass,LoadLibraryA, GetProcAddress, GetVersionExA, FreeLibrary,GetWindowsDirectoryA, IsBadReadPtr, GetStringTypeW, GetStringTypeA,FlushFileBuffers, SetFilePointer, IsBadWritePtr, VirtualAlloc,WriteFile, VirtualFree, HeapCreate, HeapDestroy, GetStartupInfoA,GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW,GetEnvironmentStrings, FreeEnvironmentStringsW,FreeEnvironmentStringsA, UnhandledExceptionFilter, RtlUnwind,GetTimeZoneInformation, GetSystemTime, RaiseException, GetCommandLineA,GetVersion, ExitProcess, HeapFree, HeapAlloc, HeapReAlloc,TerminateProcess, GetCurrentProcess, LCMapStringA, LCMapStringW,GetCPInfo, CompareStringA, CompareStringW, HeapSize, GetACP, GetOEMCP,SetUnhandledExceptionFilter, SetEnvironmentVariableA > ole32.dll: CoUninitialize, CoGetClassObject, CoInitialize, StringFromCLSID > oleaut32.dll: - > urlmon.dll: URLDownloadToFileA >wininet.dll: InternetOpenA, InternetCrackUrlA,InternetGetConnectedState, DeleteUrlCacheEntry, InternetConnectA,HttpSendRequestA, HttpOpenRequestA, InternetReadFile,InternetCloseHandle ( 0 exports ) | TrID : File type identification Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) | | ssdeep: 3072:FjSC44f3QE3zf3c8VF8oF3X12+OnIyYzAFWoWI:Fj3gYsGV2+OnasFo | | PEiD : Armadillo v1.71 | RDS : NSRL Reference Data Set - |
|