瑞星卡卡安全论坛

首页 » 技术交流区 » 可疑文件交流 » xx1.exe.rar
endurer - 2009-10-12 20:53:00
解压密码:virus


 附件: 您所在的用户组无法下载或查看附件


文件说明符 : c:\documents and settings\administrator\local settings\temporary internet files\content.ie5\jiuz7hi5\xx1[1].exe
属性 : A---
数字签名:123.cn
PE文件:是
语言 : 中文(中国)
文件版本 : 4.05.0005
产品版本 : 4.05.0005
产品名称 : dfdf
公司名称 : dfdf
内部名称 : Mode8
源文件名 : Mode8.exe
创建时间 : 2009-10-12 15:16:56
修改时间 : 2009-10-12 15:18:12
大小 : 65260 字节 63.748 KB
MD5 : 558df6494d2571f9154b54f01759f0ab
SHA1: D98D336B64C632AB92A371B00BDE9E63FA8846EE
CRC32: 54f36926


文件 xx1_1_.exe 接收于 2009.10.12 12:47:11 (UTC)
反病毒引擎版本最后更新扫描结果
a-squared4.5.0.412009.10.12Trojan-PWS.Win32.QQPass!IK
AhnLab-V35.0.0.22009.10.12-
AntiVir7.9.1.352009.10.12TR/Crypt.CFI.Gen
Antiy-AVL2.0.3.72009.10.12-
Authentium5.1.2.42009.10.12W32/VBTrojan.4!Maximus
Avast4.8.1351.02009.10.11-
AVG8.5.0.4202009.10.12-
BitDefender7.22009.10.12Gen:Trojan.Heur.dmLfrDAVPApbP
CAT-QuickHeal10.002009.10.12-
ClamAV0.94.12009.10.12-
Comodo25842009.10.12-
DrWeb5.0.0.121822009.10.12-
eSafe7.0.17.02009.10.08Suspicious File
eTrust-Vet35.1.70632009.10.12-
F-Prot4.5.1.852009.10.12W32/VBTrojan.4!Maximus
F-Secure8.0.14470.02009.10.12Trojan-PSW.Win32.QQFish.cw
Fortinet3.120.0.02009.10.12-
GData192009.10.12Gen:Trojan.Heur.dmLfrDAVPApbP
IkarusT3.1.1.72.02009.10.12Trojan-PWS.Win32.QQPass
Jiangmin11.0.8002009.10.08Trojan/QQFishing.jn
K7AntiVirus7.10.8672009.10.10-
Kaspersky7.0.0.1252009.10.12Trojan-PSW.Win32.QQFish.cw
McAfee57682009.10.11New Malware.ac
McAfee+Artemis57682009.10.11Artemis!558DF6494D25
McAfee-GW-Edition6.8.52009.10.12Heuristic.LooksLike.Win32.Suspicious.A
Microsoft1.51012009.10.12Trojan:Win32/VB.OJ
NOD3245002009.10.12a variant of Win32/TrojanDropper.VB.NJG
Norman6.01.092009.10.11-
nProtect2009.1.8.02009.10.12-
Panda10.0.2.22009.10.12-
PCTools4.4.2.02009.10.11-
Prevx3.02009.10.12-
Rising21.51.03.002009.10.12-
Sophos4.45.02009.10.12Mal/Generic-A
Sunbelt3.2.1858.22009.10.11-
Symantec1.4.4.122009.10.12-
TheHacker6.5.0.2.0392009.10.12-
TrendMicro8.950.0.10942009.10.12-
VBA323.12.10.112009.10.11-
ViRobot2009.10.12.19802009.10.12-
VirusBuster4.6.5.02009.10.11-

附加信息
File size: 65260 bytes
MD5...: 558df6494d2571f9154b54f01759f0ab
SHA1..: d98d336b64c632ab92a371b00bde9e63fa8846ee
SHA256: 9f3aa51019c3858db34322a46ef6cb20d789947067222081f770f1f09d0339ba
ssdeep: 1536:UZoJcXVoXqvtOJP5Lgdacn+p11TWZF95Jpo4:iy8Si0P5L/c+pUH5Jp9<BR>
PEiD..: -
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x26130<BR>timedatestamp.....: 0x4acfdfa7 (Sat Oct 10 01:13:11 2009)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>UPX0 0x1000 0x18000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR>UPX1 0x19000 0xe000 0xd400 7.91 7a6d81c7551c88fc41e69512c2b2f0d0<BR>.rsrc 0x27000 0x1000 0x800 3.24 857a39dd33037a38f58b83187a469e2d<BR><BR>( 2 imports ) <BR>> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess<BR>> MSVBVM60.DLL: -<BR><BR>( 0 exports ) <BR>
RDS...: NSRL Reference Data Set<BR>-
pdfid.: -
trid..: UPX compressed Win32 Executable (39.5%)<BR>Win32 EXE Yoda's Crypter (34.3%)<BR>Win32 Executable Generic (11.0%)<BR>Win32 Dynamic Link Library (generic) (9.8%)<BR>Generic Win/DOS Executable (2.5%)
sigcheck:<BR>publisher....: dfdf<BR>copyright....: n/a<BR>product......: dfdf<BR>description..: n/a<BR>original name: Mode8.exe<BR>internal name: Mode8<BR>file version.: 4.05.0005<BR>comments.....: n/a<BR>signers......: -<BR>signing date.: -<BR>verified.....: Unsigned<BR>
packers (Kaspersky): PE_Patch.UPX, UPX
packers (Authentium): UPX
packers (F-Prot): UPX


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler 4.0; MAXTHON 2.0)
瑞星工程师19 - 2009-10-12 21:10:00
文件名:xx1[1].exe  病毒名:Trojan.DL.Win32.VBcode.ta

您所上报的病毒文件将在瑞星2009的21.51.21版本中处理解决。
1
查看完整版本: xx1.exe.rar