文件 smona125130298687556678834 接收于 2009.08.26 16:18:58 (UTC)
当前状态: 完成
结果: 19/41 (46.34%)
格式化文本 打印结果
反病毒引擎 版本 最后更新 扫描结果
a-squared 4.5.0.24 2009.08.26 -
AhnLab-V3 5.0.0.2 2009.08.26 -
AntiVir 7.9.1.7 2009.08.26 TR/Crypt.XPACK.Gen
Antiy-AVL 2.0.3.7 2009.08.24 -
Authentium 5.1.2.4 2009.08.26 -
Avast 4.8.1335.0 2009.08.26 Win32:Trojan-gen {Other}
AVG 8.5.0.406 2009.08.25 Win32/NSAnti
BitDefender 7.2 2009.08.26 -
CAT-QuickHeal 10.00 2009.08.25 -
ClamAV 0.94.1 2009.08.26 -
Comodo 2100 2009.08.26 UnclassifiedMalware
DrWeb 5.0.0.12182 2009.08.26 Trojan.MulDrop.12903
eSafe 7.0.17.0 2009.08.26 Suspicious File
eTrust-Vet 31.6.6702 2009.08.26 -
F-Prot 4.5.1.85 2009.08.25 -
F-Secure 8.0.14470.0 2009.08.26 Trojan.Win32.Agent.cvff
Fortinet 3.120.0.0 2009.08.26 -
GData 19 2009.08.26 Win32:Trojan-gen {Other}
Ikarus T3.1.1.68.0 2009.08.26 Trojan.Win32.Agent
Jiangmin 11.0.800 2009.08.26 Trojan/PSW.OnLineGames.bcjj
K7AntiVirus 7.10.828 2009.08.26 Trojan.Win32.Malware.1
Kaspersky 7.0.0.125 2009.08.26 Trojan.Win32.Agent.cvff
McAfee 5720 2009.08.25 New Malware.bj
McAfee+Artemis 5720 2009.08.25 New Malware.bj
McAfee-GW-Edition 6.8.5 2009.08.26 Trojan.Crypt.XPACK.Gen
Microsoft 1.4903 2009.08.26 PWS:Win32/Frethog.AF
NOD32 4369 2009.08.26 -
Norman 2009.08.26 -
nProtect 2009.1.8.0 2009.08.26 -
Panda 10.0.2.2 2009.08.26 Suspicious file
PCTools 4.4.2.0 2009.08.26 -
Prevx 3.0 2009.08.26 -
Rising 21.44.11.00 2009.08.25 -
Sophos 4.44.0 2009.08.26 Mal/Behav-321
Sunbelt 3.2.1858.2 2009.08.25 -
Symantec 1.4.4.12 2009.08.26 -
TheHacker 6.3.4.3.388 2009.08.25 -
TrendMicro 8.950.0.1094 2009.08.26 -
VBA32 3.12.10.10 2009.08.26 suspected of Embedded.Malware-Dropper.Win32.Inject.gen
ViRobot 2009.8.26.1903 2009.08.26 -
VirusBuster 4.6.5.0 2009.08.26 -
附加信息
File size: 5552319 bytes
MD5 : 815837802a5df982826b8728ad533f38
SHA1 : a0d578276d7db4567de9be4b5679dbf48636455e
SHA256: 36ed06dacd5f2d1a0f18500bc44d136a1490829a63cfac2afed779f68b417e5f
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x1000
timedatestamp.....: 0x42A32314 (Sun Jun 5 18:06:44 2005)
machinetype.......: 0x14C (Intel I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x13000 0x12600 6.46 0948df5551ded25964af8f9baab5eca4
.data 0x14000 0x7000 0xA00 4.73 795fd6af1e53adee4eb75a5212cae805
.idata 0x1B000 0x1000 0x1000 5.02 7f9440e32acb299f3bda96288136b63a
.rsrc 0x1C000 0x4000 0x3C00 4.48 785a0d398cfcc0874716efc1d2461954
( 8 imports )
> advapi32.dll: AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA, SetFileSecurityA, SetFileSecurityW
> comctl32.dll: -
> comdlg32.dll: CommDlgExtendedError, GetOpenFileNameA
> gdi32.dll: DeleteObject
> kernel32.dll: CloseHandle, CompareStringA, CreateDirectoryA, CreateDirectoryW, CreateFileA, CreateFileW, DeleteFileA, DeleteFileW, DosDateTimeToFileTime, ExitProcess, ExpandEnvironmentStringsA, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, FindFirstFileA, FindFirstFileW, FindNextFileA, FindNextFileW, FindResourceA, FreeLibrary, GetCPInfo, GetCommandLineA, GetCurrentDirectoryA, GetCurrentProcess, GetDateFormatA, GetFileAttributesA, GetFileAttributesW, GetFileType, GetFullPathNameA, GetLastError, GetLocaleInfoA, GetModuleFileNameA, GetModuleHandleA, GetNumberFormatA, GetProcAddress, GetProcessHeap, GetStdHandle, GetTempPathA, GetTickCount, GetTimeFormatA, GetVersionExA, GlobalAlloc, HeapAlloc, HeapFree, HeapReAlloc, IsDBCSLeadByte, LoadLibraryA, LocalFileTimeToFileTime, MoveFileA, MoveFileExA, MultiByteToWideChar, ReadFile, SetCurrentDirectoryA, SetEndOfFile, SetEnvironmentVariableA, SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFileTime, SetLastError, Sleep, SystemTimeToFileTime, WaitForSingleObject, WideCharToMultiByte, WriteFile, lstrcmpiA, lstrlenA
> ole32.dll: CLSIDFromString, CoCreateInstance, CreateStreamOnHGlobal, OleInitialize, OleUninitialize
> shell32.dll: SHBrowseForFolderA, SHChangeNotify, SHFileOperationA, SHGetFileInfoA, SHGetMalloc, SHGetSpecialFolderLocation, ShellExecuteExA, SHGetPathFromIDListA
> user32.dll: CharToOemBuffA, CharUpperA, CopyRect, CreateWindowExA, DefWindowProcA, DestroyIcon, DestroyWindow, DialogBoxParamA, DispatchMessageA, EnableWindow, EndDialog, FindWindowExA, GetClassNameA, GetClientRect, GetDlgItem, GetDlgItemTextA, GetMessageA, GetParent, GetSysColor, GetSystemMetrics, GetWindow, GetWindowLongA, GetWindowRect, GetWindowTextA, IsWindow, IsWindowVisible, LoadBitmapA, LoadCursorA, LoadIconA, LoadStringA, MapWindowPoints, MessageBoxA, OemToCharA, OemToCharBuffA, PeekMessageA, PostMessageA, RegisterClassExA, SendDlgItemMessageA, SendMessageA, SetDlgItemTextA, SetFocus, SetMenu, SetWindowLongA, SetWindowPos, SetWindowTextA, ShowWindow, TranslateMessage, UpdateWindow, WaitForInputIdle, wsprintfA, wvsprintfA
( 0 exports )
TrID : File type identification
WinRAR Self Extracting archive (88.7%)
InstallShield setup (7.3%)
Win32 Executable Generic (1.4%)
Win32 Dynamic Link Library (generic) (1.2%)
Win32 Executable Watcom C++ (generic) (0.4%)
ssdeep: 98304:TOpIcwTwr2A1P3gA3DX7+oVlH5r2qX0Ghvh/SuD5ixVX3SGVsPzOtmMtXzFQO:TOppwTwJ1TDyoVlH5rLE0NSkixR3SxOR
PEiD : -
packers (Kaspersky): PE_Patch
packers (F-Prot): RAR
RDS : NSRL Reference Data Set