Danke. Wieso muss ich mir dafür die versteckten Dateien anzeigen lassen (hab es gemacht, verstehe es aber nicht)?
Hier die Virustotalscanauswertungen (Reihenfolge wie bei undoreal): Code:
Antivirus Version Last Update Result
AhnLab-V3 2008.12.16.2 2008.12.16 -
AntiVir 7.9.0.45 2008.12.16 -
Authentium 5.1.0.4 2008.12.16 -
Avast 4.8.1281.0 2008.12.15 -
AVG 8.0.0.199 2008.12.15 -
BitDefender 7.2 2008.12.16 -
CAT-QuickHeal 10.00 2008.12.16 -
ClamAV 0.94.1 2008.12.16 -
Comodo 760 2008.12.15 -
DrWeb 4.44.0.09170 2008.12.16 -
eSafe 7.0.17.0 2008.12.15 -
eTrust-Vet 31.6.6263 2008.12.16 -
Ewido 4.0 2008.12.15 -
F-Prot 4.4.4.56 2008.12.15 -
F-Secure 8.0.14332.0 2008.12.16 -
Fortinet 3.117.0.0 2008.12.16 -
GData 19 2008.12.16 -
Ikarus T3.1.1.45.0 2008.12.16 -
K7AntiVirus 7.10.554 2008.12.15 -
Kaspersky 7.0.0.125 2008.12.16 -
McAfee 5465 2008.12.15 -
McAfee+Artemis 5465 2008.12.15 -
Microsoft 1.4205 2008.12.16 -
NOD32 3694 2008.12.15 -
Norman 5.80.02 2008.12.15 -
Panda 9.0.0.4 2008.12.15 -
PCTools 4.4.2.0 2008.12.15 -
Prevx1 V2 2008.12.16 -
Rising 21.08.11.00 2008.12.16 -
SecureWeb-Gateway 6.7.6 2008.12.16 -
Sophos 4.36.0 2008.12.16 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.16 -
TheHacker 6.3.1.4.189 2008.12.16 -
TrendMicro 8.700.0.1004 2008.12.16 -
VBA32 3.12.8.10 2008.12.15 -
ViRobot 2008.12.16.1520 2008.12.16 -
VirusBuster 4.5.11.0 2008.12.15 -
Additional information
File size: 161096 bytes
MD5...: 8ffe3209c1a4b4d80fb70e666c4d287a
SHA1..: 8f825de3cefa30e87d5688c24a92f2140efa8bdf
SHA256: 1396943d3a4366756a9f7aaf67ea1f1f0d3af2df82688bb4730603da3f9f1730
SHA512: e29102d540dee97d08cb272829a52560486b2ea3e2fdbb531e98c5b84fea3979
7e17748e39cff8a95c9112f133623e643cf50872a269900db6552a7113e932f7
ssdeep: 3072:Er8ckWP2Qwa68kuX1l5kTL79tGSz5zi3EvmfV2:APSvj7WSz5er
PEiD..: -
TrID..: File type identification
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x40810c
timedatestamp.....: 0x48935b1f (Fri Aug 01 18:51:11 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x178da 0x18000 6.62 2e4e386f5ed0ac5f00096079f4e3ba70
.rdata 0x19000 0x422e 0x5000 4.50 77415fe1119b1f59de653bd271dc5a5b
.data 0x1e000 0x3860 0x2000 2.36 df1a1000e3366afbc16d523c5e1668f5
.rsrc 0x22000 0x5350 0x6000 5.08 653a9e7720ddffa05fc1e3ab9e511c58
( 5 imports )
> WS2_32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> KERNEL32.dll: RtlUnwind, GetConsoleMode, GetConsoleCP, SetFilePointer, GetLocaleInfoA, GetStringTypeW, GetLocaleInfoW, GetVersionExW, GetModuleHandleW, WriteFile, LockResource, GetTempFileNameW, FindResourceExW, CreateFileW, LoadResource, MultiByteToWideChar, CloseHandle, MoveFileExW, GetTempPathW, DeleteFileW, CreateDirectoryW, GetProcAddress, FreeLibrary, LoadLibraryA, WideCharToMultiByte, CreateMutexW, GetLastError, GetStringTypeA, HeapSize, Sleep, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, LCMapStringW, LCMapStringA, InitializeCriticalSection, GetModuleFileNameA, GetStdHandle, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, ReadFile, CreateFileA, FlushFileBuffers, GetSystemDirectoryA, TerminateProcess, HeapReAlloc, VirtualAlloc, EnterCriticalSection, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, HeapFree, HeapAlloc, GetModuleHandleA, ExitProcess, GetCommandLineA, GetVersionExA, GetProcessHeap, GetStartupInfoA, RaiseException, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, HeapDestroy, HeapCreate, VirtualFree, DeleteCriticalSection, LeaveCriticalSection
> USER32.dll: DestroyWindow, wsprintfW, TranslateMessage, IsDialogMessageW, CloseWindow, SetDlgItemTextW, LoadIconW, SendMessageW, CreateDialogIndirectParamW, SetWindowTextW, LoadImageW, PeekMessageW, GetDlgItem, DispatchMessageW, DialogBoxIndirectParamW, EndDialog, GetDesktopWindow, ShowWindow
> ADVAPI32.dll: RegQueryValueExA, RegSetValueExA, RegOpenKeyExA, CheckTokenMembership, RegOpenKeyExW, FreeSid, AllocateAndInitializeSid, RegQueryValueExW, RegCloseKey, RegCreateKeyExA
> SHELL32.dll: SHGetFolderPathA, ShellExecuteW
( 0 exports ) Code:
Antivirus Version Last Update Result
AhnLab-V3 2008.12.16.2 2008.12.16 -
AntiVir 7.9.0.45 2008.12.16 -
Authentium 5.1.0.4 2008.12.16 -
Avast 4.8.1281.0 2008.12.15 -
AVG 8.0.0.199 2008.12.15 -
BitDefender 7.2 2008.12.16 -
CAT-QuickHeal 10.00 2008.12.16 -
ClamAV 0.94.1 2008.12.16 -
Comodo 760 2008.12.15 -
DrWeb 4.44.0.09170 2008.12.16 -
eSafe 7.0.17.0 2008.12.15 -
eTrust-Vet 31.6.6263 2008.12.16 -
Ewido 4.0 2008.12.15 -
F-Prot 4.4.4.56 2008.12.15 -
F-Secure 8.0.14332.0 2008.12.16 -
Fortinet 3.117.0.0 2008.12.16 -
GData 19 2008.12.16 -
Ikarus T3.1.1.45.0 2008.12.16 -
K7AntiVirus 7.10.554 2008.12.15 -
Kaspersky 7.0.0.125 2008.12.16 -
McAfee 5465 2008.12.15 -
McAfee+Artemis 5465 2008.12.15 -
Microsoft 1.4205 2008.12.16 -
NOD32 3694 2008.12.15 -
Norman 5.80.02 2008.12.15 -
Panda 9.0.0.4 2008.12.15 -
PCTools 4.4.2.0 2008.12.15 -
Prevx1 V2 2008.12.16 -
Rising 21.08.11.00 2008.12.16 -
SecureWeb-Gateway 6.7.6 2008.12.16 -
Sophos 4.36.0 2008.12.16 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.16 -
TheHacker 6.3.1.4.189 2008.12.16 -
TrendMicro 8.700.0.1004 2008.12.16 -
VBA32 3.12.8.10 2008.12.15 -
ViRobot 2008.12.16.1520 2008.12.16 -
VirusBuster 4.5.11.0 2008.12.15 -
Additional information
File size: 12288 bytes
MD5...: 85f907acd7befe530502a0924376ba6a
SHA1..: a99118d885728ad0b4b13317da29f522a926b9aa
SHA256: 1621805b7cefa91103a4820cffc53dbe8678d2a437605184487d8cc7642ddfd9
SHA512: d1947452b38302daf4de78ab001f0d9bb754dd67477daf6db90d0ecda07bc6b1
77cdaf5cdd1d4f8c3c26eeef7f30623582571780a86bb17730ed527a4b60d560
ssdeep: 6:idq2Vg3F+X32kQxQQD5y/Yy+QWdsf750X4t:e9GSGZxH1QUc7i
PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x10000000
timedatestamp.....: 0x43d19f58 (Sat Jan 21 02:41:28 2006)
machinetype.......: 0x14c (I386)
( 2 sections )
name viradd virsiz rawdsiz ntrpy md5
.rsrc 0x1000 0xa0 0x1000 0.10 a4744c73cbd620ff85e3e8ebe377cefa
.reloc 0x2000 0xc 0x1000 0.00 3808644f11ba1ee3cb2b6326fcd2e01a
( 0 imports )
( 0 exports )
ThreatExpert info: <a href='h**p://www.threatexpert.com/report.aspx?md5=85f907acd7befe530502a0924376ba6a' target='_blank'>h**p://www.threatexpert.com/report.aspx?md5=85f907acd7befe530502a0924376ba6a</a> Code:
Antivirus Version Last Update Result
AhnLab-V3 2008.12.16.2 2008.12.16 -
AntiVir 7.9.0.45 2008.12.16 -
Authentium 5.1.0.4 2008.12.16 -
Avast 4.8.1281.0 2008.12.15 -
AVG 8.0.0.199 2008.12.15 -
BitDefender 7.2 2008.12.16 -
CAT-QuickHeal 10.00 2008.12.16 -
ClamAV 0.94.1 2008.12.16 -
Comodo 760 2008.12.15 -
DrWeb 4.44.0.09170 2008.12.16 -
eSafe 7.0.17.0 2008.12.15 -
eTrust-Vet 31.6.6263 2008.12.16 -
Ewido 4.0 2008.12.15 -
F-Prot 4.4.4.56 2008.12.15 -
F-Secure 8.0.14332.0 2008.12.16 -
Fortinet 3.117.0.0 2008.12.16 -
GData 19 2008.12.16 -
Ikarus T3.1.1.45.0 2008.12.16 -
K7AntiVirus 7.10.554 2008.12.15 -
Kaspersky 7.0.0.125 2008.12.16 -
McAfee 5465 2008.12.15 -
McAfee+Artemis 5465 2008.12.15 -
Microsoft 1.4205 2008.12.16 -
NOD32 3694 2008.12.15 -
Norman 5.80.02 2008.12.15 -
Panda 9.0.0.4 2008.12.15 -
PCTools 4.4.2.0 2008.12.15 -
Prevx1 V2 2008.12.16 -
Rising 21.08.11.00 2008.12.16 -
SecureWeb-Gateway 6.7.6 2008.12.16 -
Sophos 4.36.0 2008.12.16 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.16 -
TheHacker 6.3.1.4.189 2008.12.16 -
TrendMicro 8.700.0.1004 2008.12.16 -
VBA32 3.12.8.10 2008.12.15 -
ViRobot 2008.12.16.1520 2008.12.16 -
VirusBuster 4.5.11.0 2008.12.15 -
Additional information
File size: 200704 bytes
MD5...: eed2ce7bd9e43b8500d906d944460d22
SHA1..: c34261a2b1e30fa5c80fe304683b6568d12eb978
SHA256: 94d8edba9c4509483fdd5deb3a9aac51506b56d80f1a138bf2493eefc49f78ab
SHA512: 24e024a61d74c8f8976ea5cd52cb7479437756cd2734d5b8ce1245ee23756bf8
ce04f19f89356121e49c4c9b077e0c9ecdadb1b088b8ca24f2eee0cd425c0fe6
ssdeep: 3072:SBQm5WGVHOyabSdm1LosvlJ9X+ikuDNIICE9krDb1UV5NXZDm17uDEa3cgX
4QyT:SB0GVPabsm1Psikw+0Sb1USc3H
PEiD..: Armadillo v1.xx - v2.xx
TrID..: File type identification
Win64 Executable Generic (80.9%)
Win32 Executable Generic (8.0%)
Win32 Dynamic Link Library (generic) (7.1%)
Generic Win/DOS Executable (1.8%)
DOS Executable Generic (1.8%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x1002239a
timedatestamp.....: 0x44691d42 (Tue May 16 00:30:58 2006)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x2145e 0x22000 6.25 73037a107b70a1cc30883247a0feb9fd
.rdata 0x23000 0x73ea 0x8000 5.13 8030a96377a813f37863453bff029028
.data 0x2b000 0x24c4 0x3000 3.89 338ae97b86a868e2111bb9ec09bfec4a
.rsrc 0x2e000 0x440 0x1000 1.16 a6458ae5e5c5267a59d7463dbd63b254
.reloc 0x2f000 0x1ba2 0x2000 6.03 1acebc5b05861141e863de7cb89648fb
( 3 imports )
> libdivx.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> MSVCRT.dll: _adjust_fdiv, malloc, _initterm, free, _errno, _iob, fprintf, strncmp, memmove, time
> KERNEL32.dll: GetLastError, SetLastError, DisableThreadLibraryCalls
( 206 exports )
BIO_f_ssl, BIO_new_buffer_ssl_connect, BIO_new_ssl, BIO_new_ssl_connect, BIO_ssl_copy_session_id, BIO_ssl_shutdown, DTLSv1_client_method, DTLSv1_method, DTLSv1_server_method, ERR_load_SSL_strings, SSL_CIPHER_description, SSL_CIPHER_get_bits, SSL_CIPHER_get_name, SSL_CIPHER_get_version, SSL_COMP_add_compression_method, SSL_COMP_get_compression_methods, SSL_COMP_get_name, SSL_CTX_add_client_CA, SSL_CTX_add_session, SSL_CTX_callback_ctrl, SSL_CTX_check_private_key, SSL_CTX_ctrl, SSL_CTX_flush_sessions, SSL_CTX_free, SSL_CTX_get_cert_store, SSL_CTX_get_client_CA_list, SSL_CTX_get_ex_data, SSL_CTX_get_ex_new_index, SSL_CTX_get_quiet_shutdown, SSL_CTX_get_timeout, SSL_CTX_get_verify_callback, SSL_CTX_get_verify_depth, SSL_CTX_get_verify_mode, SSL_CTX_load_verify_locations, SSL_CTX_new, SSL_CTX_remove_session, SSL_CTX_sessions, SSL_CTX_set_cert_store, SSL_CTX_set_cert_verify_callback, SSL_CTX_set_cipher_list, SSL_CTX_set_client_CA_list, SSL_CTX_set_default_passwd_cb, SSL_CTX_set_default_passwd_cb_userdata, SSL_CTX_set_default_verify_paths, SSL_CTX_set_ex_data, SSL_CTX_set_generate_session_id, SSL_CTX_set_msg_callback, SSL_CTX_set_purpose, SSL_CTX_set_quiet_shutdown, SSL_CTX_set_session_id_context, SSL_CTX_set_ssl_version, SSL_CTX_set_timeout, SSL_CTX_set_tmp_dh_callback, SSL_CTX_set_tmp_ecdh_callback, SSL_CTX_set_tmp_rsa_callback, SSL_CTX_set_trust, SSL_CTX_set_verify, SSL_CTX_set_verify_depth, SSL_CTX_use_PrivateKey, SSL_CTX_use_PrivateKey_ASN1, SSL_CTX_use_PrivateKey_file, SSL_CTX_use_RSAPrivateKey, SSL_CTX_use_RSAPrivateKey_ASN1, SSL_CTX_use_RSAPrivateKey_file, SSL_CTX_use_certificate, SSL_CTX_use_certificate_ASN1, SSL_CTX_use_certificate_chain_file, SSL_CTX_use_certificate_file, SSL_SESSION_cmp, SSL_SESSION_free, SSL_SESSION_get_ex_data, SSL_SESSION_get_ex_new_index, SSL_SESSION_get_id, SSL_SESSION_get_time, SSL_SESSION_get_timeout, SSL_SESSION_hash, SSL_SESSION_new, SSL_SESSION_print, SSL_SESSION_print_fp, SSL_SESSION_set_ex_data, SSL_SESSION_set_time, SSL_SESSION_set_timeout, SSL_accept, SSL_add_client_CA, SSL_add_dir_cert_subjects_to_stack, SSL_add_file_cert_subjects_to_stack, SSL_alert_desc_string, SSL_alert_desc_string_long, SSL_alert_type_string, SSL_alert_type_string_long, SSL_callback_ctrl, SSL_check_private_key, SSL_clear, SSL_connect, SSL_copy_session_id, SSL_ctrl, SSL_do_handshake, SSL_dup, SSL_dup_CA_list, SSL_free, SSL_get1_session, SSL_get_SSL_CTX, SSL_get_certificate, SSL_get_cipher_list, SSL_get_ciphers, SSL_get_client_CA_list, SSL_get_current_cipher, SSL_get_current_compression, SSL_get_current_expansion, SSL_get_default_timeout, SSL_get_error, SSL_get_ex_data, SSL_get_ex_data_X509_STORE_CTX_idx, SSL_get_ex_new_index, SSL_get_fd, SSL_get_finished, SSL_get_info_callback, SSL_get_peer_cert_chain, SSL_get_peer_certificate, SSL_get_peer_finished, SSL_get_privatekey, SSL_get_quiet_shutdown, SSL_get_rbio, SSL_get_read_ahead, SSL_get_rfd, SSL_get_session, SSL_get_shared_ciphers, SSL_get_shutdown, SSL_get_ssl_method, SSL_get_verify_callback, SSL_get_verify_depth, SSL_get_verify_mode, SSL_get_verify_result, SSL_get_version, SSL_get_wbio, SSL_get_wfd, SSL_has_matching_session_id, SSL_library_init, SSL_load_client_CA_file, SSL_load_error_strings, SSL_new, SSL_peek, SSL_pending, SSL_read, SSL_renegotiate, SSL_renegotiate_pending, SSL_rstate_string, SSL_rstate_string_long, SSL_set_accept_state, SSL_set_bio, SSL_set_cipher_list, SSL_set_client_CA_list, SSL_set_connect_state, SSL_set_ex_data, SSL_set_fd, SSL_set_generate_session_id, SSL_set_info_callback, SSL_set_msg_callback, SSL_set_purpose, SSL_set_quiet_shutdown, SSL_set_read_ahead, SSL_set_rfd, SSL_set_session, SSL_set_session_id_context, SSL_set_shutdown, SSL_set_ssl_method, SSL_set_tmp_dh_callback, SSL_set_tmp_ecdh_callback, SSL_set_tmp_rsa_callback, SSL_set_trust, SSL_set_verify, SSL_set_verify_depth, SSL_set_verify_result, SSL_set_wfd, SSL_shutdown, SSL_state, SSL_state_string, SSL_state_string_long, SSL_use_PrivateKey, SSL_use_PrivateKey_ASN1, SSL_use_PrivateKey_file, SSL_use_RSAPrivateKey, SSL_use_RSAPrivateKey_ASN1, SSL_use_RSAPrivateKey_file, SSL_use_certificate, SSL_use_certificate_ASN1, SSL_use_certificate_file, SSL_version, SSL_want, SSL_write, SSLv23_client_method, SSLv23_method, SSLv23_server_method, SSLv2_client_method, SSLv2_method, SSLv2_server_method, SSLv3_client_method, SSLv3_method, SSLv3_server_method, TLSv1_client_method, TLSv1_method, TLSv1_server_method, d2i_SSL_SESSION, i2d_SSL_SESSION, ssl2_ciphers, ssl3_ciphers Code:
Antivirus Version Last Update Result
AhnLab-V3 2008.12.16.2 2008.12.16 -
AntiVir 7.9.0.45 2008.12.16 -
Authentium 5.1.0.4 2008.12.16 -
Avast 4.8.1281.0 2008.12.15 -
AVG 8.0.0.199 2008.12.15 -
BitDefender 7.2 2008.12.16 -
CAT-QuickHeal 10.00 2008.12.16 -
ClamAV 0.94.1 2008.12.16 -
Comodo 760 2008.12.15 -
DrWeb 4.44.0.09170 2008.12.16 -
eSafe 7.0.17.0 2008.12.15 -
eTrust-Vet 31.6.6263 2008.12.16 -
Ewido 4.0 2008.12.15 -
F-Prot 4.4.4.56 2008.12.15 -
F-Secure 8.0.14332.0 2008.12.16 -
Fortinet 3.117.0.0 2008.12.16 -
GData 19 2008.12.16 -
Ikarus T3.1.1.45.0 2008.12.16 -
K7AntiVirus 7.10.554 2008.12.15 -
Kaspersky 7.0.0.125 2008.12.16 -
McAfee 5465 2008.12.15 -
McAfee+Artemis 5465 2008.12.15 -
Microsoft 1.4205 2008.12.16 -
NOD32 3694 2008.12.15 -
Norman 5.80.02 2008.12.15 -
Panda 9.0.0.4 2008.12.15 -
PCTools 4.4.2.0 2008.12.15 -
Prevx1 V2 2008.12.16 -
Rising 21.08.12.00 2008.12.16 -
SecureWeb-Gateway 6.7.6 2008.12.16 -
Sophos 4.36.0 2008.12.16 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.16 -
TheHacker 6.3.1.4.189 2008.12.16 -
TrendMicro 8.700.0.1004 2008.12.16 -
VBA32 3.12.8.10 2008.12.15 -
ViRobot 2008.12.16.1520 2008.12.16 -
VirusBuster 4.5.11.0 2008.12.15 -
Additional information
File size: 4816 bytes
MD5...: 160421403ba5090d775356f3513df403
SHA1..: cab5758fec3c2a73dc95efd8f69580e9049c1493
SHA256: 6fe1edc4176e668f4b669585099d00190c82ee7cc87a93647dcea12e82cd7c37
SHA512: b25086603080417c8cddc19271fada36c389acffb0c7ee7aeafa8c5253feecac
f5aae56def8c4f927ec2457e7a476b059b0bae74635b6b4a03bc1358c0a30ff4
ssdeep: 96:ztGnqJ8KSZ40cPrG2jihG4saB9JpO9J/WtLLr/r:FSOPrjjQpL9JpmyTD
PEiD..: -
TrID..: File type identification
Type Library (100.0%)
PEInfo: - Code:
Antivirus Version Last Update Result
AhnLab-V3 2008.12.16.2 2008.12.16 -
AntiVir 7.9.0.45 2008.12.16 -
Authentium 5.1.0.4 2008.12.16 -
Avast 4.8.1281.0 2008.12.15 -
AVG 8.0.0.199 2008.12.15 -
BitDefender 7.2 2008.12.16 -
CAT-QuickHeal 10.00 2008.12.16 -
ClamAV 0.94.1 2008.12.16 -
Comodo 760 2008.12.15 -
DrWeb 4.44.0.09170 2008.12.16 -
eSafe 7.0.17.0 2008.12.15 -
eTrust-Vet 31.6.6263 2008.12.16 -
Ewido 4.0 2008.12.15 -
F-Prot 4.4.4.56 2008.12.15 -
F-Secure 8.0.14332.0 2008.12.16 -
Fortinet 3.117.0.0 2008.12.16 -
GData 19 2008.12.16 -
Ikarus T3.1.1.45.0 2008.12.16 -
K7AntiVirus 7.10.554 2008.12.15 -
Kaspersky 7.0.0.125 2008.12.16 -
McAfee 5465 2008.12.15 -
McAfee+Artemis 5465 2008.12.15 -
Microsoft 1.4205 2008.12.16 -
NOD32 3694 2008.12.15 -
Norman 5.80.02 2008.12.15 -
Panda 9.0.0.4 2008.12.15 -
PCTools 4.4.2.0 2008.12.15 -
Prevx1 V2 2008.12.16 -
Rising 21.08.12.00 2008.12.16 -
SecureWeb-Gateway 6.7.6 2008.12.16 -
Sophos 4.36.0 2008.12.16 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.16 -
TheHacker 6.3.1.4.189 2008.12.16 -
TrendMicro 8.700.0.1004 2008.12.16 -
VBA32 3.12.8.10 2008.12.15 -
ViRobot 2008.12.16.1520 2008.12.16 -
VirusBuster 4.5.11.0 2008.12.15 -
Additional information
File size: 10152 bytes
MD5...: e463cafd6120d8e86c313b38f1de9447
SHA1..: 4cc84dd078763034fdc9a47b5f206c10f9e88e1d
SHA256: f770956dbde4aedcc1890a3340dda7bb0fca16e9bb32f19eefebeb8e67192dd1
SHA512: f46de96ba1edebcffb4ed62551d56809a8973bbf19617eb17579357623fd739b
2efdc0fb370f25df836928a637eedf5816ac268c984532a59ecf66aa89be9c7c
ssdeep: 192:wP7igQrl19RjPLUncGVt2eLnn8K7xbEUKzkiDzFmpNnEGHXm6I0ARW:ztRzL
UcGVAon8Q5hKze/nEGHXd0RW
PEiD..: -
TrID..: File type identification
Unknown!
PEInfo: - Code:
Antivirus Version Last Update Result
AhnLab-V3 2008.12.16.2 2008.12.16 -
AntiVir 7.9.0.45 2008.12.16 -
Authentium 5.1.0.4 2008.12.16 -
Avast 4.8.1281.0 2008.12.15 -
AVG 8.0.0.199 2008.12.15 -
BitDefender 7.2 2008.12.16 -
CAT-QuickHeal 10.00 2008.12.16 -
ClamAV 0.94.1 2008.12.16 -
Comodo 760 2008.12.15 -
DrWeb 4.44.0.09170 2008.12.16 -
eSafe 7.0.17.0 2008.12.15 -
eTrust-Vet 31.6.6263 2008.12.16 -
Ewido 4.0 2008.12.15 -
F-Prot 4.4.4.56 2008.12.15 -
F-Secure 8.0.14332.0 2008.12.16 -
Fortinet 3.117.0.0 2008.12.16 -
GData 19 2008.12.16 -
Ikarus T3.1.1.45.0 2008.12.16 -
K7AntiVirus 7.10.554 2008.12.15 -
Kaspersky 7.0.0.125 2008.12.16 -
McAfee 5465 2008.12.15 -
McAfee+Artemis 5465 2008.12.15 -
Microsoft 1.4205 2008.12.16 -
NOD32 3694 2008.12.15 -
Norman 5.80.02 2008.12.15 -
Panda 9.0.0.4 2008.12.15 -
PCTools 4.4.2.0 2008.12.15 -
Prevx1 V2 2008.12.16 -
Rising 21.08.12.00 2008.12.16 -
SecureWeb-Gateway 6.7.6 2008.12.16 -
Sophos 4.36.0 2008.12.16 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.16 -
TheHacker 6.3.1.4.189 2008.12.16 -
TrendMicro 8.700.0.1004 2008.12.16 -
VBA32 3.12.8.10 2008.12.15 -
ViRobot 2008.12.16.1520 2008.12.16 -
VirusBuster 4.5.11.0 2008.12.15 -
Additional information
File size: 17097 bytes
MD5...: 7a27b475768d2a7e725617a6bedf9c9a
SHA1..: cbd77b4aa396e509b26c0ea75cf7825e6982e68c
SHA256: 91c8e85f1ae1ebc69244a2a93253b2cd560c4a379703839ac28a3b7d844996e2
SHA512: 2786ada56ec01761956db5270eeed9f35625a4fc6238b8242a3ddeb3d24795f2
5bd04c21d0e16c730d9b1a8aab9930698e8098e09774a454ea70b6e94d9e415a
ssdeep: 192:z6I+1NlN/UiEDEvkTSfVAK0CJMFJdxYqJCfK73qokAfGXvCcjfo/EhwGD:+I
+1v6DEsOCbcMFOqT9HpckMhwq
PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x103bc
timedatestamp.....: 0x3f16d68f (Thu Jul 17 17:02:07 2003)
machinetype.......: 0x14c (I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x2c0 0x2abc 0x2ac0 6.43 7b8fdc5fed09542da2c0beb9afb74cfe
.rdata 0x2d80 0x18c 0x1a0 3.36 f196e33a1393d3432480b77e6ada7eba
.data 0x2f20 0x68 0x80 2.26 65403084ed05d7ffea78a6898a2cd203
INIT 0x2fa0 0x6d6 0x6e0 5.18 8092ab5b22248d2c275b74153706c0ac
.rsrc 0x3680 0x410 0x420 3.41 601f4e69a8f29545704481fc529a4886
.reloc 0x3aa0 0x2b4 0x2c0 5.57 65194addf2477361a920ea0108cd1cc1
( 3 imports )
> ntoskrnl.exe: RtlAnsiStringToUnicodeString, RtlFreeUnicodeString, KeInitializeEvent, KeWaitForSingleObject, KeResetEvent, RtlEqualUnicodeString, KeSetEvent, MmUnlockPages, IoAllocateMdl, MmProbeAndLockPages, IoFreeMdl, _except_handler3, DbgPrint, IoReleaseCancelSpinLock, ExInterlockedAddLargeStatistic, InterlockedExchange, MmMapLockedPagesSpecifyCache, IofCompleteRequest, IoDeleteDevice, IoIsWdmVersionAvailable, IoCreateDevice, ExAllocatePoolWithTag, RtlAppendUnicodeToString, IoCreateSymbolicLink, IoDeleteSymbolicLink, ExFreePool
> HAL.dll: KeQueryPerformanceCounter
> NDIS.SYS: NdisCloseAdapter, NdisResetEvent, NdisOpenAdapter, NdisWaitEvent, NdisCompleteBindAdapter, NdisSetEvent, NdisFreeSpinLock, NdisFreeBufferPool, NdisAllocatePacketPool, NdisAllocateBufferPool, NdisFreePacketPool, NdisAllocateSpinLock, NdisInitAnsiString, NdisFreeMemory, NdisAllocateMemory, NdisRequest, NdisUnicodeStringToAnsiString, NdisSend, NdisAcquireSpinLock, NdisInterlockedRemoveHeadList, NdisReleaseSpinLock, NdisGetCurrentSystemTime, NdisAllocatePacket, NdisAllocateBuffer, NdisTransferData, NdisInitializeEvent, NdisFreePacket, NdisInitUnicodeString, NdisRegisterProtocol, NdisDeregisterProtocol, NdisFreeBuffer, NdisUnchainBufferAtFront, NDIS_BUFFER_TO_SPAN_PAGES, NdisQueryBufferOffset, NdisInterlockedInsertTailList
( 0 exports ) Heißt das, dass die Files ok sind? Nochmal vielen Dank, undoreal, für alle schon getane Arbeit und Sucherei in diesen logfiles... |