2010年6月23日 星期三

免費線上41套防毒軟體掃描網站 VirusTotal


對於在 Windows環境開發工具的人而言,這個網站的好處是,可以在Release前透過41套防毒軟體的掃描,確認自己是否有用到被特定軟體視為惡意行為的操作機制.
或是,當使用者有安全疑慮懷疑的執行檔時,也可以透過該網站的41套防毒軟體進行掃描 (應該沒有人會自己安裝41套防毒軟體吧….),確認沒有漏網之魚.
該網站中文介紹如下
關於 VirusTotal
VirusTotal 是一款可疑檔案分析服務, 通過各種知名反病毒引擎, 對您所上傳的檔案進行偵測, 以判斷檔案是否被病毒, 蠕蟲, 木馬, 以及各類惡意軟體感染.
特點:
免費, 獨立的服務
使用多種反病毒引擎
實時自動更新病毒特徵庫
每款反病毒引擎都將顯示詳細的結果
實時全球統計資料
操作範例流程如下.
選擇一個檔案上傳進行掃描











上傳中,











進行41套防毒軟體的掃描.














如下為這次掃描的掃描結果- 文字內容
反病毒引擎版本最後更新掃瞄結果
a-squared4.5.0.502010.05.10-
AhnLab-V32010.05.11.002010.05.10-
AntiVir8.2.1.2362010.05.10-
Antiy-AVL2.0.3.72010.05.10-
Authentium5.2.0.52010.05.11-
Avast4.8.1351.02010.05.10-
Avast55.0.332.02010.05.10-
AVG9.0.0.7872010.05.11-
BitDefender7.22010.05.11-
CAT-QuickHeal10.002010.05.11-
ClamAV0.96.0.3-git2010.05.11-
Comodo48212010.05.11-
DrWeb5.0.2.033002010.05.11-
eSafe7.0.17.02010.05.10-
eTrust-Vet35.2.74782010.05.10-
F-Prot4.5.1.852010.05.10-
F-Secure9.0.15370.02010.05.11-
Fortinet4.1.133.02010.05.10-
GData212010.05.11-
IkarusT3.1.1.84.02010.05.11-
Jiangmin13.0.9002010.05.10-
Kaspersky7.0.0.1252010.05.11-
McAfee5.400.0.11582010.05.11-
McAfee-GW-Edition2010.12010.05.10-
Microsoft1.57032010.05.11-
NOD3251032010.05.10-
Norman6.04.122010.05.10-
nProtect2010-05-10.012010.05.10-
Panda10.0.2.72010.05.10-
PCTools7.0.3.52010.05.11-
Prevx3.02010.05.11-
Rising22.47.01.012010.05.11-
Sophos4.53.02010.05.11-
Sunbelt62892010.05.11-
Symantec20101.1.0.892010.05.11-
TheHacker6.5.2.0.2772010.05.10-
TrendMicro9.120.0.10042010.05.10-
TrendMicro-HouseCall9.120.0.10042010.05.11-
VBA323.12.12.42010.05.06-
ViRobot2010.5.10.23082010.05.10-
VirusBuster5.0.27.02010.05.10-
附加訊息
File size: 208944 bytes
MD5   : 54cdf523534a508e30d52bb0b8ad9242
SHA1  : cd1eaa03dd65b41e66f0266c382de1370c5fab3a
SHA256: df3ff0dbf803c6b62aeb9640cdbe945d059a8a006d589c838052f273f475180e
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0×5820
timedatestamp…..: 0x4B964183 (Tue Mar 9 13:39:31 2010)
machinetype…….: 0x14C (Intel I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0×1000 0x25F00 0×26000 3.89 f35d8f9b5d1b86fa3bbd918ecde6c34d
.rdata 0×27000 0x185F 0×2000 3.96 7cf866c92f7ca0d52f1ed4ae68d864a5
.data 0×29000 0x27F9C8 0×4000 3.14 9c7d52b9515945e34c0e2cddcbbb9c68
.idata 0x2A9000 0xF42 0×1000 4.24 9122a7dc375f906f450a03911fca224b
.rsrc 0x2AA000 0x16C3 0×2000 2.20 2c5332ec2474f0bff2a946763d58e02f
.reloc 0x2AC000 0x2E2D 0×3000 3.02 07607e3ff3614a885c58c2081e00b3f5
( 6 imports )
> advapi32.dll: SetSecurityDescriptorDacl, GetSecurityDescriptorSacl, InitializeSecurityDescriptor, SetNamedSecurityInfoA, SetSecurityDescriptorSacl, ConvertStringSecurityDescriptorToSecurityDescriptorA
> comctl32.dll: InitCommonControlsEx, -
> kernel32.dll: CreateMutexA, Sleep, CreateThread, CompareStringW, CompareStringA, LCMapStringW, LCMapStringA, ReadFile, SetEndOfFile, GetStringTypeW, GetStringTypeA, MultiByteToWideChar, GetOEMCP, GetACP, GetCPInfo, CreateFileA, SetFilePointer, FlushFileBuffers, SetStdHandle, GetLastError, HeapReAlloc, HeapAlloc, GetCurrentProcessId, CreateFileMappingA, MapViewOfFile, ExitProcess, IsBadReadPtr, LocalFree, GetVersionExA, SetConsoleCtrlHandler, RtlUnwind, VirtualFree, HeapFree, HeapCreate, HeapDestroy, GetFileType, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, WideCharToMultiByte, CloseHandle, GetCurrentProcess, TerminateProcess, HeapValidate, SetEnvironmentVariableA, GetTickCount, VirtualAlloc, GetModuleFileNameA, GetTimeZoneInformation, GetSystemTime, GetLocalTime, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersion, DebugBreak, GetStdHandle, WriteFile, InterlockedDecrement, OutputDebugStringA, GetProcAddress, LoadLibraryA, InterlockedIncrement, IsBadWritePtr
> shell32.dll: Shell_NotifyIconW
> user32.dll: SendMessageW, MessageBoxA, SendMessageA, GetClientRect, DialogBoxParamW, EndDialog, SetWindowPos, GetWindowRect, DestroyIcon, KillTimer, LoadImageA, SetTimer, GetDlgItem, SetClassLongA, SetForegroundWindow, GetSystemMetrics, LoadIconA, CreateWindowExA
> ws2_32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
( 0 exports )
TrID  : File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
Symantec reputation: Suspicious.Insight http://www.symantec.com/security_response/writeup.jsp?docid=2010-021223-0550-99
ssdeep: 1536:jZSFY6l3HDe4cYc9Yv9ddYnDBaPUtkUj3Y/lGpqsba:gYWjjcxwXEDBZtkIXpqs+
sigcheck: publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
PEiD  : -
RDS   : NSRL Reference Data Set
-

沒有留言:

張貼留言