QUOTE(RadarpSP @ 20.05.2007 21:02)
Puedes mandarme el virus, comprimido con password por mensaje personal??
Saludos
Hola perdon por no aberlo mensinado antes pero al entrar ala pagina ala cual te envia el mensaje del msn www.xxxxxxxxx.land.ru/festa2007.jpg automaticamente se descarga el siguiente archivo
llamado flash_instal supoestamente es una actualisacion del flash requerido para ver imagenes ene sa pagina el cual e enviado a virustotal y a arojado lo siguiente
lo malo es que kis no detecta este archivo como danino te dejo el reporte del virus total y de paso te lo envio en privado si lo deceas saludos .
..................................................
....................................................
VirusTotalVirusTotal is a free file analisys service that works using several antivirus engines.
Select file : DistributeSSL
Enter your email, choose the file to be scanned with multiple antivirus engines and click Send.Menu:
News Hot news in the virus/antivirus sector.
Estadisticas Statistics of VirusTotal procesing.
Virustotal More info about Virustotal.
STATUS: FINISHEDComplete scanning result of "flash_instal.zip", received in VirusTotal at 05.20.2007, 20:04:15 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.5.16.1 05.18.2007 no virus found
AntiVir 7.4.0.23 05.20.2007 TR/Delphi.Downloader.Gen
Authentium 4.93.8 05.18.2007 no virus found
Avast 4.7.997.0 05.18.2007 Win32:Banload-BHD
AVG 7.5.0.467 05.20.2007 no virus found
BitDefender 7.2 05.20.2007 BehavesLike:Trojan.Downloader
CAT-QuickHeal 9.00 05.18.2007 no virus found
ClamAV devel-20070416 05.20.2007 no virus found
DrWeb 4.33 05.20.2007 DLOADER.Trojan
eSafe 7.0.15.0 05.20.2007 suspicious Trojan/Worm
eTrust-Vet 30.7.3644 05.19.2007 no virus found
Ewido 4.0 05.20.2007 no virus found
FileAdvisor 1 05.20.2007 no virus found
Fortinet 2.85.0.0 05.20.2007 no virus found
F-Prot 4.3.2.48 05.18.2007 no virus found
F-Secure 6.70.13030.0 05.20.2007 W32/Downloader
Ikarus T3.1.1.7 05.20.2007 no virus found
Kaspersky 4.0.2.24 05.20.2007 no virus found
McAfee 5034 05.18.2007 no virus found
Microsoft 1.2503 05.20.2007 no virus found
NOD32v2 2278 05.20.2007 no virus found
Norman 5.80.02 05.18.2007 W32/Downloader
Panda 9.0.0.4 05.20.2007 Suspicious file
Prevx1 V2 05.20.2007 no virus found
Sophos 4.17.0 05.20.2007 no virus found
Sunbelt 2.2.907.0 05.17.2007 no virus found
Symantec 10 05.20.2007 no virus found
TheHacker 6.1.6.118 05.18.2007 no virus found
VBA32 3.12.0 05.20.2007 no virus found
VirusBuster 4.3.7:9 05.20.2007 no virus found
Webwasher-Gateway 6.0.1 05.20.2007 Trojan.Delphi.Downloader.Gen
Aditional Information
File size: 165468 bytes
MD5: 19ef097b6f118bccedefac31ce6fe0a1
SHA1: fbdfb0fec9feade9b1f7576653353c4f32140ee6
packers: UPX
packers: UPX
packers: UPX
packers: UPX
norman sandbox: [ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Decompressing UPX.
* File length: 195584 bytes.
[ Changes to filesystem ]
* Creates file C:WINDOWSdgwkl.exe.
* Creates file C:Documents and SettingsAll UsersMenu IniciarProgramasInicializar qupdate.exe.
[ Network services ]
* Downloads file from [http://www.xxxxxxx/ie.exe[/url] as C:WINDOWSdgwkl.exe.
* Connects to "www.xxxxxx" on port 80 (TCP).
* Opens URL: www.xxxxxx.
Editado porque enlazaba a un virus[ Security issues ]
* Starting downloaded file - potential security problem.
[ Process/window information ]
* Creates a mutex sxswtt.
* Attemps to open C:Documents and SettingsAll UsersMenu IniciarProgramasInicializar qupdate.exe .
VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
> Go to: Home Contactar En Español
--------------------------------------------------------------------------------
www.virustotal.com :: ©Hispasec Sistemas 2004-07:: e-mail info@virustotal.com