瑞星卡卡安全论坛

首页 » 技术交流区 » 可疑文件交流 » DR/StartPage.BG
qihuakai - 2009-3-12 14:12:00
文件 P2P_worm_gen.zip 接收于 2009.03.12 07:11:12 (CET)
当前状态: 完成
结果: 4/39 (10.26%)


格式化文本
打印结果




反病毒引擎版本最后更新扫描结果
a-squared4.0.0.1012009.03.12-
AhnLab-V35.0.0.22009.03.12-
AntiVir7.9.0.1092009.03.11DR/StartPage.BG
Authentium5.1.0.42009.03.11-
Avast4.8.1335.02009.03.11-
AVG8.0.0.2372009.03.12-
BitDefender7.22009.03.12-
CAT-QuickHeal10.002009.03.11Trojan.Genome.aku
ClamAV0.94.12009.03.12-
Comodo10492009.03.11-
DrWeb4.44.0.091702009.03.12-
eSafe7.0.17.02009.03.11-
eTrust-Vet31.6.63882009.03.09-
F-Prot4.4.4.562009.03.11-
F-Secure8.0.14470.02009.03.12-
Fortinet3.117.0.02009.03.11-
GData192009.03.12-
IkarusT3.1.1.45.02009.03.12-
K7AntiVirus7.10.6672009.03.11Non-Virus:
Kaspersky7.0.0.1252009.03.12-
McAfee55502009.03.11-
McAfee+Artemis55502009.03.11-
Microsoft1.44052009.03.12-
NOD3239292009.03.11-
Norman6.00.062009.03.11-
nProtect2009.1.8.02009.03.12-
Panda10.0.0.102009.03.12-
PCTools4.4.2.02009.03.11-
Prevx1V22009.03.12-
Rising21.20.30.002009.03.12-
SecureWeb-Gateway6.7.62009.03.12Trojan.Dropper.StartPage.BG
Sophos4.39.02009.03.12-
Sunbelt3.2.1858.22009.03.12-
Symantec1.4.4.122009.03.12-
TheHacker6.3.3.0.2802009.03.12-
TrendMicro8.700.0.10042009.03.12-
VBA323.12.10.12009.03.11-
ViRobot2009.3.11.16452009.03.11-
VirusBuster4.5.11.02009.03.11-
附加信息
File size: 289521 bytes
MD5...: 3b1cde11da64467e9dcd0cafd84127ce
SHA1..: 8b4bccd959459cc61b9087350b6df6801641d4be
SHA256: 1be895cccb84cccf51a0930a3024a15738e3a5de50077178db805ddf06ff7f3a
SHA512: 2fd76ecf3818a1da54c44f5bcf8f1e559a9b527f9428860811a1ccf4054ea666
25618e39738be9760811b0e5b56552273da3a2414eadf9e9f770fdd640ffe09c
ssdeep: 6144:QZuuObR8sVImcyY+giJXRSPveOfSOG4HktSPveOfSOG4HmhmpSPveOfSOG4
HyVE:HV+mz/gXeOfk4HeOfk4GhmqeOfk4SVE
PEiD..: -
TrID..: File type identification
WinRAR Self Extracting archive (96.2%)
Win32 Executable Generic (1.5%)
Win32 Dynamic Link Library (generic) (1.4%)
Generic Win/DOS Executable (0.3%)
DOS Executable Generic (0.3%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1000
timedatestamp.....: 0x46f268e6 (Thu Sep 20 12:34:46 2007)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x14000 0x13800 6.47 8c499086717691066d921075ed5bdb09
.data 0x15000 0x7000 0xa00 4.91 0cb811e47f78b5404a658fb36b591857
.idata 0x1c000 0x1000 0x1000 5.12 8bf175092a70a21f11fd06cc4087c7d0
.rsrc 0x1d000 0x79c0 0x7a00 5.83 17df5212b2230246fe531ebdc58b4756

( 8 imports )
> ADVAPI32.DLL: AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA, SetFileSecurityA, SetFileSecurityW
> KERNEL32.DLL: CloseHandle, CompareStringA, CreateDirectoryA, CreateDirectoryW, CreateFileA, CreateFileW, DeleteFileA, DeleteFileW, DosDateTimeToFileTime, ExitProcess, ExpandEnvironmentStringsA, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, FindFirstFileA, FindFirstFileW, FindNextFileA, FindNextFileW, FindResourceA, FreeLibrary, GetCPInfo, GetCommandLineA, GetCurrentDirectoryA, GetCurrentProcess, GetDateFormatA, GetFileAttributesA, GetFileAttributesW, GetFileType, GetFullPathNameA, GetLastError, GetLocaleInfoA, GetModuleFileNameA, GetModuleHandleA, GetNumberFormatA, GetProcAddress, GetProcessHeap, GetStdHandle, GetTempPathA, GetTickCount, GetTimeFormatA, GetVersionExA, GlobalAlloc, HeapAlloc, HeapFree, HeapReAlloc, IsDBCSLeadByte, LoadLibraryA, LocalFileTimeToFileTime, MoveFileA, MoveFileExA, MultiByteToWideChar, ReadFile, SetCurrentDirectoryA, SetEndOfFile, SetEnvironmentVariableA, SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFileTime, SetLastError, Sleep, SystemTimeToFileTime, WaitForSingleObject, WideCharToMultiByte, WriteFile, lstrcmpiA, lstrlenA
> COMCTL32.DLL: -
> COMDLG32.DLL: CommDlgExtendedError, GetOpenFileNameA, GetSaveFileNameA
> GDI32.DLL: DeleteObject
> SHELL32.DLL: SHBrowseForFolderA, SHChangeNotify, SHFileOperationA, SHGetFileInfoA, SHGetMalloc, SHGetSpecialFolderLocation, ShellExecuteExA, SHGetPathFromIDListA
> USER32.DLL: CharToOemA, CharToOemBuffA, CharUpperA, CopyRect, CreateWindowExA, DefWindowProcA, DestroyIcon, DestroyWindow, DialogBoxParamA, DispatchMessageA, EnableWindow, EndDialog, FindWindowExA, GetClassNameA, GetClientRect, GetDlgItem, GetDlgItemTextA, GetMessageA, GetParent, GetSysColor, GetSystemMetrics, GetWindow, GetWindowLongA, GetWindowRect, GetWindowTextA, IsWindow, IsWindowVisible, LoadBitmapA, LoadCursorA, LoadIconA, LoadStringA, MapWindowPoints, MessageBoxA, OemToCharA, OemToCharBuffA, PeekMessageA, PostMessageA, RegisterClassExA, SendDlgItemMessageA, SendMessageA, SetDlgItemTextA, SetFocus, SetMenu, SetWindowLongA, SetWindowPos, SetWindowTextA, ShowWindow, TranslateMessage, UpdateWindow, WaitForInputIdle, wsprintfA, wvsprintfA
> OLE32.DLL: CLSIDFromString, CoCreateInstance, CreateStreamOnHGlobal, OleInitialize, OleUninitialize

( 0 exports )
packers (F-Prot): RAR

http://www.virustotal.com/zh-cn/analisis/a83e45b61c379de17d935f5321193ea2

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)

附件: P2P_worm_gen.zip
RisingCSC - 2009-3-12 14:35:00
我们已经详细分析过您的问题和文件,以下是您上传的文件的分析结果:

1、文件名:boy.exe
  不是病毒

2、文件名:cat.exe
  不是病毒

3、文件名:dog.exe
  不是病毒
1
查看完整版本: DR/StartPage.BG