瑞星卡卡安全论坛

首页 » 技术交流区 » 可疑文件交流 » 举报病毒taskmgr.exe
13岁帅哥 - 2009-3-16 21:16:00
你好管理员 该病毒仿冒windows管理器进程,隐藏在d:\目录下,并且自动联网,在c:\windows下建立文件(主动防御检测到的)我估计可能是QQ病毒。
大部分杀软检测是病毒:
File taskmgr.exe received on 03.16.2009 14:20:54 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED

Result: 17/38 (44.74%)

Loading server information...
Your file is queued in position: 4.
Estimated start time is between 57 and 81 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.


Compact
Print results



Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position:
) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. 
Email: 
  



AntivirusVersionLast UpdateResult
a-squared4.0.0.1012009.03.16-
AhnLab-V35.0.0.22009.03.16-
AntiVir7.9.0.1142009.03.16-
Authentium5.1.0.42009.03.15W32/Heuristic-210!Eldorado
Avast4.8.1335.02009.03.16-
AVG8.0.0.2372009.03.16Suspicion: unknown virus
BitDefender7.22009.03.16Gen:Trojan.Heur.2004C4E5E5
CAT-QuickHeal10.002009.03.16(Suspicious) - DNAScan
ClamAV0.94.12009.03.16-
Comodo10592009.03.16-
DrWeb4.44.0.091702009.03.16-
eSafe7.0.17.02009.03.15Suspicious File
eTrust-Vet31.6.63882009.03.09-
F-Prot4.4.4.562009.03.15W32/Heuristic-210!Eldorado
F-Secure8.0.14470.02009.03.16Backdoor.Win32.VB.hzm
Fortinet3.117.0.02009.03.16-
GData192009.03.16Gen:Trojan.Heur.2004C4E5E5
IkarusT3.1.1.45.02009.03.16-
K7AntiVirus7.10.6712009.03.14-
Kaspersky7.0.0.1252009.03.16Backdoor.Win32.VB.hzm
McAfee55542009.03.15-
McAfee+Artemis55542009.03.15-
McAfee-GW-Edition6.7.62009.03.16Trojan.Crypt.FKM.Gen
Microsoft1.44052009.03.16-
NOD3239382009.03.16-
Norman6.00.062009.03.13Suspicious_F.gen
nProtect2009.1.8.02009.03.16-
Panda10.0.0.102009.03.15-
PCTools4.4.2.02009.03.16Packed/FSG
Rising21.21.02.002009.03.16Trojan.Win32.Nodef.fxj
Sophos4.39.02009.03.16Mal/Behav-160
Sunbelt3.2.1858.22009.03.15VIPRE.Suspicious
Symantec1.4.4.122009.03.16-
TheHacker6.3.3.0.2832009.03.16-
TrendMicro8.700.0.10042009.03.16PAK_Generic.002
VBA323.12.10.12009.03.16-
ViRobot2009.3.16.16502009.03.16-
VirusBuster4.6.5.02009.03.15Packed/FSG
Additional information
File size: 42965 bytes
MD5...: 916e289de783274cd5e3a8f6a5673e67
SHA1..: 113760fe9006b74f6b5ec084e029f2952232220d
SHA256: 9d347bc415f68e41dd9b362ccd0717627930e1f136ce81a9aef1f191871a38e6
SHA512: 2a018ab8a78c2925b9324f395b19b5db5fd91920830ccb7d6d69f56c967df695
76344a859d11dacf9da58320f7e1caf36e1285e3b3edf08e3104feaee9b3057a
ssdeep: 768:tEbdRrMlikwMbIQV482sNaI9Uj4ISvOyUQLfeoQUih8GXE/dMWXwUfoP816/
C84R:aLMl0ag7eYa2CLeo8h83bXQ016/pQt
PEiD..: FSG v2.0 -> bart/xt
TrID..: File type identification
Win32 Executable Generic (67.9%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Targa bitmap (Original TGA Format) (0.0%)
MS Flight Simulator Aircraft Performance Info (0.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x154
timedatestamp.....: 0x21475346 (Fri Sep 11 01:35:02 1987)
machinetype.......: 0x14c (I386)

( 2 sections )
name viradd virsiz rawdsiz ntrpy md5
0x1000 0x1d000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
0x1e000 0xb000 0xa5d5 7.83 2d16a88ef4ee39874d9e88e7e75edfc5

( 1 imports )
> KERNEL32.dll: LoadLibraryA, GetProcAddress

( 0 exports )
packers (Kaspersky): FSG
packers (Authentium): FSG
packers (F-Prot): FSG


附件: taskmgr.rar
RisingCSC - 2009-3-17 9:10:00
瑞星杀毒软件病毒库版本21.21.02
Trojan.Win32.Nodef.fxj    taskmgr.exe>>fsg2.0
1
查看完整版本: 举报病毒taskmgr.exe