发新话题
打印

赤壁游戏盗号木马

赤壁游戏盗号木马

文件尺寸: 小于 2048 kb
木马病毒要3MB多,所以上传不了
下载地址:http://www.xwg8.com/cbxxwg.rar


=========以下是世界杀毒网的扫描报告============







文件 __________________.exe 接收于 2008.06.27 13:08:29 (CET)
反病毒引擎版本最后更新扫描结果
AhnLab-V32008.6.27.12008.06.27Win-Trojan/Xema.variant
AntiVir7.8.0.592008.06.27-
Authentium5.1.0.42008.06.27W32/Nuj.A.gen!Eldorado
Avast4.8.1195.02008.06.26-
AVG7.5.0.5162008.06.26-
BitDefender7.22008.06.27Trojan.Flystudio.AI
CAT-QuickHeal9.502008.06.26-
ClamAV0.93.12008.06.27Trojan.Dropper-2514
DrWeb4.44.0.091702008.06.27-
eSafe7.0.17.02008.06.26-
eTrust-Vet31.6.59112008.06.27Win32/Nuj.A
Ewido4.02008.06.27-
F-Prot4.4.4.562008.06.27W32/Nuj.A.gen!Eldorado
F-Secure7.60.13501.02008.06.26-
Fortinet3.14.0.02008.06.27-
GData2.0.7306.10232008.06.27-
IkarusT3.1.1.26.02008.06.27Virus.Win32.Rbot.CXN
Kaspersky7.0.0.1252008.06.27-
McAfee53262008.06.26-
Microsoft1.37042008.06.27Worm:Win32/Nuj.A
NOD32v232232008.06.27-
Norman5.80.022008.06.26-
Panda9.0.0.42008.06.26-
Prevx1V22008.06.27-
Rising20.50.42.002008.06.27-
Sophos4.30.02008.06.27Troj/Dropr-K
Sunbelt3.0.1176.12008.06.26-
Symantec102008.06.27-
TheHacker6.2.96.3622008.06.27-
TrendMicro8.700.0.10042008.06.27-
VBA323.12.6.82008.06.27-
VirusBuster4.5.11.02008.06.23-
Webwasher-Gateway6.6.22008.06.27Win32.Malware.gen (suspicious)

附加信息
File size: 3698307 bytes
MD5...: 0e9874217d0ec178970e978f8368ed16
SHA1..: 18eb909dbb5742b21ebd3b174d980fa807364ff2
SHA256: de9289bb80f83fd71332692cdb5963a02e1702f954701ba3571d4f2560f483c6
SHA512: 4e55c5c6728b3a5d93851311b20e425a00ffb0b37a7e2bf5e6ac5d0349287099<BR>e772bb833bacbc23a88f183898494fb6bde7d0fbd9e41fe9d404da9a75caf2d8
PEiD..: Armadillo v1.71
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x40389f<BR>timedatestamp.....: 0x3925136b (Fri May 19 10:11:55 2000)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 5 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x5a77 0x6000 6.45 3c3a2fc631e2e10352a7f1de7f1e1615<BR>.rdata 0x7000 0xab4 0x1000 3.73 463198fd8b2f88fd5103d98401bc4208<BR>.data 0x8000 0x3fa0 0x4000 1.63 4d10d5012dbf5bb91ac5ce1ef6fe5d8c<BR>.ecode 0xc000 0x310000 0x310000 7.73 2052e9487d01404d739bf7e179292bf2<BR>.rsrc 0x31c000 0x1160 0x2000 3.10 fcb7accf2a7a0c761f06e5d45865a7c7<BR><BR>( 2 imports ) <BR>> KERNEL32.dll: GetProcAddress, LoadLibraryA, CloseHandle, WriteFile, CreateDirectoryA, GetTempPathA, ReadFile, SetFilePointer, CreateFileA, GetModuleFileNameA, GetStringTypeA, LCMapStringW, LCMapStringA, HeapAlloc, HeapFree, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersion, ExitProcess, GetEnvironmentVariableA, GetVersionExA, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, RtlUnwind, GetCPInfo, GetACP, GetOEMCP, MultiByteToWideChar, GetStringTypeW<BR>> USER32.dll: MessageBoxA, wsprintfA<BR><BR>( 0 exports ) <BR>
packers (Kaspersky): PE_Patch.UPX, UPX


[ 本帖最后由 举报贱人 于 2008-6-27 19:10 编辑 ]

TOP

感谢楼主提供的样本,我们稍后鉴定,请实时更新毒霸!
爱毒霸社区感恩活动 好礼相送
★★★每周QQ表情和头像推荐★★★(9月1日~9月7日)
¤¤¤QQ技术攻略总汇¤¤¤(7月6日整理)
看帖必回,是一种美德
金山样本收集组2群号:34520456(求助人员禁止加入)
互联网的力量是无穷大的,毒霸现在把大家联成一线,让大家都成为反病毒的一线主体

TOP

发新话题