Hallo,
dankeschön für deine Bemühen
Habe leider keinen Link zum Ergebnis von der Auswertung von Virustotal gefunden, daher poste ich die Ergebnisse eben so, hoffe es ist kein Problem.
Zitat:
Antivirus Version letzte aktualisierung Ergebnis
a-squared 4.5.0.50 2010.01.25 -
AhnLab-V3 5.0.0.2 2010.01.25 -
AntiVir 7.9.1.150 2010.01.25 -
Antiy-AVL 2.0.3.7 2010.01.22 -
Authentium 5.2.0.5 2010.01.25 -
Avast 4.8.1351.0 2010.01.25 -
AVG 9.0.0.730 2010.01.25 -
BitDefender 7.2 2010.01.25 -
CAT-QuickHeal 10.00 2010.01.25 -
ClamAV 0.94.1 2010.01.25 -
Comodo 3708 2010.01.25 -
DrWeb 5.0.1.12222 2010.01.25 -
eSafe 7.0.17.0 2010.01.25 -
eTrust-Vet 35.2.7259 2010.01.25 -
F-Prot 4.5.1.85 2010.01.25 -
F-Secure 9.0.15370.0 2010.01.25 -
Fortinet 4.0.14.0 2010.01.25 -
GData 19 2010.01.25 -
Ikarus T3.1.1.80.0 2010.01.25 -
Jiangmin 13.0.900 2010.01.24 -
K7AntiVirus 7.10.952 2010.01.22 -
McAfee 5872 2010.01.25 -
McAfee+Artemis 5872 2010.01.25 -
McAfee-GW-Edition 6.8.5 2010.01.25 -
Microsoft 1.5405 2010.01.25 -
NOD32 4805 2010.01.25 -
Norman 6.04.03 2010.01.25 -
nProtect 2009.1.8.0 2010.01.25 -
Panda 10.0.2.2 2010.01.25 -
PCTools 7.0.3.5 2010.01.25 -
Prevx 3.0 2010.01.25 -
Rising 22.32.00.04 2010.01.25 -
Sophos 4.50.0 2010.01.25 -
Sunbelt 3.2.1858.2 2010.01.24 -
Symantec 20091.2.0.41 2010.01.25 -
TheHacker 6.5.0.9.162 2010.01.25 -
TrendMicro 9.120.0.1004 2010.01.25 -
VBA32 3.12.12.1 2010.01.25 -
ViRobot 2010.1.25.2154 2010.01.25 -
VirusBuster 5.0.21.0 2010.01.25 -
weitere Informationen
File size: 11032 bytes
MD5...: 001b4278407f4303efc902a2b16f2453
SHA1..: ea06eafcbf0a2dc7b99596057313b1d424b50867
SHA256: 92a95b0efaae7adc6380d5207c86cb45beeae6974417a13669484a9d179e69ac
ssdeep: 192:kLMUB3XEOQP410kvnKL/CldolMzMjGwP7kuMh40+ebMyVzMXW:kMQHlrKLCc
gLp4qbHEW
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0xcc6
timedatestamp.....: 0x462393e9 (Mon Apr 16 15:19:05 2007)
machinetype.......: 0x14c (I386)
( 7 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x480 0x28 0x80 2.22 b17405997580b07e7c2c9bf30b57f04b
.rdata 0x500 0xd3 0x100 3.88 2d703f31d844475d9380fb88bd9facd1
.data 0x600 0x18 0x80 0.20 df7d8ecc5fe0c6c7f7c29703d865767a
PAGE 0x680 0x5fa 0x600 6.03 f5c902b63b9b1c592e9800e30bfc02f2
INIT 0xc80 0x31a 0x380 5.16 833998b5a1024cc165e8e6aa7219f1cb
.rsrc 0x1000 0x3c8 0x400 3.09 62d0c3c18ac1affb5d600e92bf21d07f
.reloc 0x1400 0xb2 0x100 3.45 8e5bcecfd9956e42e4180855d198dde6
( 1 imports )
> ntoskrnl.exe: IofCompleteRequest, IoDeleteDevice, IoDeleteSymbolicLink, RtlInitUnicodeString, ZwClose, RtlRandom, KeQuerySystemTime, ObfDereferenceObject, ZwWriteFile, ZwReadFile, IoGetCurrentProcess, ZwCreateFile, ExFreePoolWithTag, ZwQueryValueKey, ExAllocatePoolWithTag, ZwOpenKey, ObfReferenceObject, IoRegisterShutdownNotification, IoCreateSymbolicLink, IoCreateDevice
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win16/32 Executable Delphi generic (25.4%)
Clipper DOS Executable (24.8%)
Generic Win/DOS Executable (24.6%)
DOS Executable Generic (24.6%)
VXD Driver (0.3%)
sigcheck:
publisher....: InterVideo
copyright....: Copyright (C) InterVideo Corp. 1997-2006
product......: InterVideo regi.sys
description..: regi driver
original name: regi.sys
internal name: regi.sys
file version.: 1.0.0.2
comments.....:
signers......: Intervideo, Inc.
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 3:05 AM 4/17/2007
verified.....: -
|
Ich muss grad noch etwas am Computer machen, Combofix führe ich dann aus, bevor ich ins Bett gehe und schreibe morgen die Ergebnisse.
Danke nochmals.