星期五, 6月 27, 2008

病毒報告

恩..一段時間沒上來了

這是某個主席傳來的東西 (下載沒差...exe攻擊無效)

File jia.exe received on 06.26.2008 18:08:49 (CET)
Current status: finished
Result: 15/33 (45.46%)
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:

Antivirus Version Last Update Result
AhnLab-V32008.6.26.02008.06.26-
AntiVir7.8.0.592008.06.26DR/Dldr.Delf.OGH
Authentium5.1.0.42008.06.25W32/Hupigon.G.gen!Eldorado
Avast4.8.1195.02008.06.26Win32:Neptunia-KN
AVG7.5.0.5162008.06.26PSW.OnlineGames.AUJL
BitDefender7.22008.06.26Dropped:Trojan.Downloader.Delf.OGH
CAT-QuickHeal9.502008.06.26(Suspicious) - DNAScan
ClamAV0.93.12008.06.26-
DrWeb4.44.0.091702008.06.26-
eSafe7.0.17.02008.06.26-
eTrust-Vet31.6.59072008.06.26-
Ewido4.02008.06.26-
F-Prot4.4.4.562008.06.25W32/Hupigon.G.gen!Eldorado
F-Secure7.60.13501.02008.06.24-
Fortinet3.14.0.02008.06.26-
GData2.0.7306.10232008.06.26Trojan-PSW.Win32.OnLineGames.rxrn
IkarusT3.1.1.26.02008.06.26Virus.Win32.Neptunia.KN
Kaspersky7.0.0.1252008.06.26Trojan-PSW.Win32.OnLineGames.rxrn
McAfee53252008.06.25-
MicrosoftNone2008.06.26-
NOD32v232212008.06.26a variant of Win32/PSW.OnLineGames.NHY
Norman5.80.022008.06.26-
Panda9.0.0.42008.06.26Suspicious file
Prevx1V22008.06.26-
Rising20.50.32.002008.06.26Trojan.Win32.Agent.zri
Sophos4.30.02008.06.26-
Sunbelt3.0.1153.12008.06.15VIPRE.Suspicious
Symantec102008.06.26-
TheHacker6.2.92.3622008.06.26-
TrendMicro8.700.0.10042008.06.26-
VBA323.12.6.82008.06.26-
VirusBuster4.5.11.02008.06.23-
Webwasher-Gateway6.6.22008.06.26Trojan.Dropper.Dldr.Delf.OGH
Additional information
File size: 439808 bytes
MD5...: 867da58b68495b913648b901bbc71d34
SHA1..: 7294986189cc1b258e0567e32904004f1274976b
SHA256: 173f48fee8cfab3d8452b93a274d413267345ca06ec0b6fa34df80a08143d2ff
SHA512: 7e0eadcdeaa488724c52b971db674bc02319ab63ea1b44a51019b5f362871172
07836c4a6439fbeee09b46935872e46eab60a73c351d14e03469974faa32892c
PEiD..: ASProtect v1.23 RC1
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x401000
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)

( 10 sections )
name viradd virsiz rawdsiz ntrpy md5
0x1000 0x5000 0x3000 7.99 6fe0356b4e60069ba3746023f0d86a8f
0x6000 0x1000 0x200 7.60 0c4a80450048db73680b3bf617b6b719
0x7000 0x1000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
0x8000 0x1000 0x600 7.88 d350e679c6122a28cdd7da9e4e338c6e
0x9000 0x1000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
0xa000 0x1000 0x200 0.20 7cd66032ccbad0330bf6fdf8d151d54c
0xb000 0x1000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0xc000 0x24000 0x11200 8.00 490c2776648b424d632627ab1e6cc76e
.data 0x30000 0x57000 0x56600 7.94 5f9624df4f3d2161917cb1db2a897539
.adata 0x87000 0x1000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e

( 7 imports )
> kernel32.dll: GetProcAddress, GetModuleHandleA, LoadLibraryA
> user32.dll: GetKeyboardType
> advapi32.dll: RegQueryValueExA
> advapi32.dll: RegSetValueExA
> user32.dll: PostMessageA
> oleaut32.dll: VariantChangeTypeEx
> kernel32.dll: RaiseException

( 0 exports )
packers (Avast): ASProtect