Sir Hawk | 17.01.2009 15:26 | Hi Andreas :)
G:\WINDOWS\system32\svchost.exe:ext.exe
Diese habe ich nicht finden können, statt dessen habe ich diese gescannt:
G:\WINDOWS\system32\svchost.exe
Ergebnis: Code:
Complete scanning result of "svchost.exe", processed in VirusTotal at 01/17/2009 15:08:37 (CET).
[ file data ]
* name..: svchost.exe
* size..: 14336
* md5...: 65a819b121eb6fdab4400ea42bdffe64
* sha1..: 0dfdee2871427e9c40ec82541156884ff9b4bfa3
* peid..: -
[ scan result ]
a-squared 4.0.0.73/20090117 found nothing
AhnLab-V3 2009.1.15.0/20090117 found nothing
AntiVir 7.9.0.55/20090116 found nothing
Authentium 5.1.0.4/20090116 found nothing
Avast 4.8.1281.0/20090116 found nothing
AVG 8.0.0.229/20090116 found nothing
BitDefender 7.2/20090117 found nothing
CAT-QuickHeal 10.00/20090117 found nothing
ClamAV 0.94.1/20090117 found nothing
Comodo 934/20090117 found nothing
DrWeb 4.44.0.09170/20090117 found nothing
eSafe 7.0.17.0/20090115 found nothing
eTrust-Vet 31.6.6312/20090117 found nothing
F-Prot 4.4.4.56/20090116 found nothing
F-Secure 8.0.14470.0/20090117 found nothing
Fortinet 3.117.0.0/20090115 found nothing
GData 19/20090117 found nothing
Ikarus T3.1.1.45.0/20090117 found nothing
K7AntiVirus 7.10.594/20090117 found nothing
Kaspersky 7.0.0.125/20090117 found nothing
McAfee 5497/20090116 found nothing
McAfee+Artemis 5497/20090116 found nothing
Microsoft 1.4205/20090117 found nothing
NOD32 3773/20090117 found nothing
Norman 5.93.01/20090116 found nothing
nProtect 2009.1.8.0/20090116 found nothing
Panda 9.5.1.2/20090117 found nothing
PCTools 4.4.2.0/20090117 found nothing
Prevx1 V2/20090117 found nothing
Rising 21.12.52.00/20090117 found nothing
SecureWeb-Gateway 6.7.6/20090116 found nothing
Sophos 4.37.0/20090117 found nothing
Sunbelt 3.2.1835.2/20090116 found nothing
Symantec 10/20090117 found nothing
TheHacker 6.3.1.5.221/20090117 found nothing
TrendMicro 8.700.0.1004/20090116 found nothing
VBA32 3.12.8.10/20090116 found nothing
ViRobot 2009.1.17.1563/20090117 found nothing
VirusBuster 4.5.11.0/20090117 found nothing
[ notes ]
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=65a819b121eb6fdab4400ea42bdffe64
CWSandbox info: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=65a819b121eb6fdab4400ea42bdffe64 G:\WINDOWS\SYSTEM32\zkdxgr32.dll
Ergebnis: Code:
Complete scanning result of "zkdxgr32.dll", processed in VirusTotal at 01/17/2009 15:09:33 (CET).
[ file data ]
* name..: zkdxgr32.dll
* size..: 16896
* md5...: 84750408763db66975e8c72d4e8623a0
* sha1..: a4495b38258b2b606b911af8c3ac9f35fca3587a
* peid..: -
[ scan result ]
a-squared 4.0.0.73/20090117 found nothing
AhnLab-V3 2009.1.15.0/20090117 found nothing
AntiVir 7.9.0.55/20090116 found [TR/Hijacker.Gen]
Authentium 5.1.0.4/20090116 found nothing
Avast 4.8.1281.0/20090116 found nothing
AVG 8.0.0.229/20090116 found nothing
BitDefender 7.2/20090117 found [Trojan.FakeAlert.ABZ]
CAT-QuickHeal 10.00/20090117 found nothing
ClamAV 0.94.1/20090117 found [Trojan.Fakealert-532]
Comodo 934/20090117 found nothing
DrWeb 4.44.0.09170/20090117 found nothing
eSafe 7.0.17.0/20090115 found nothing
eTrust-Vet 31.6.6312/20090117 found nothing
F-Prot 4.4.4.56/20090116 found nothing
F-Secure 8.0.14470.0/20090117 found nothing
Fortinet 3.117.0.0/20090115 found nothing
GData 19/20090117 found [Trojan.FakeAlert.ABZ]
Ikarus T3.1.1.45.0/20090117 found nothing
K7AntiVirus 7.10.594/20090117 found nothing
Kaspersky 7.0.0.125/20090117 found nothing
McAfee 5497/20090116 found [Cutwail.dll]
McAfee+Artemis 5497/20090116 found [Cutwail.dll]
Microsoft 1.4205/20090117 found [TrojanDownloader:Win32/Renos.AW]
NOD32 3773/20090117 found [a variant of Win32/Injector.CT]
Norman 5.93.01/20090116 found nothing
nProtect 2009.1.8.0/20090116 found [Trojan.FakeAlert.ABZ]
Panda 9.5.1.2/20090117 found nothing
PCTools 4.4.2.0/20090117 found nothing
Prevx1 V2/20090117 found [Cloaked Malware]
Rising 21.12.52.00/20090117 found nothing
SecureWeb-Gateway 6.7.6/20090116 found [Trojan.Hijacker.Gen]
Sophos 4.37.0/20090117 found [Troj/Agent-HNY]
Sunbelt 3.2.1835.2/20090116 found nothing
Symantec 10/20090117 found nothing
TheHacker 6.3.1.5.221/20090117 found nothing
TrendMicro 8.700.0.1004/20090116 found nothing
VBA32 3.12.8.10/20090116 found nothing
ViRobot 2009.1.17.1563/20090117 found nothing
VirusBuster 4.5.11.0/20090117 found [Trojan.FakeAlert.Gen!Pac]
[ notes ]
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=6A40529B008D3BF6424100F597A641002AAB454D G:\Dokumente und Einstellungen\***\reader_s.exe
War nicht vorhanden.
G:\WINDOWS\System32\reader_s.exe
Ergebnis: Code:
Ergebnis:
Datei reader_s.exe empfangen 2009.01.17 15:13:24 (CET)
Status: Beendet
Ergebnis: 36/39 (92.31%)
Filter
Drucken der Ergebnisse Antivirus Version letzte aktualisierung Ergebnis
a-squared 4.0.0.73 2009.01.17 Virus.Win32.Cheburgen.a!IK
AhnLab-V3 2009.1.15.0 2009.01.17 Win32/Virut.D
AntiVir 7.9.0.55 2009.01.16 W32/Virut.Gen
Authentium 5.1.0.4 2009.01.16 W32/Virut.9264
Avast 4.8.1281.0 2009.01.16 Win32:Virut
AVG 8.0.0.229 2009.01.16 Win32/Virut
BitDefender 7.2 2009.01.17 Win32.Virtob.Gen.9
CAT-QuickHeal 10.00 2009.01.17 W32.Virut.D
ClamAV 0.94.1 2009.01.17 W32.Virut.si
Comodo 934 2009.01.17 -
DrWeb 4.44.0.09170 2009.01.17 Win32.Virut.5
eSafe 7.0.17.0 2009.01.15 -
eTrust-Vet 31.6.6312 2009.01.17 Win32/Virut.9276
F-Prot 4.4.4.56 2009.01.16 W32/Virut.9264
F-Secure 8.0.14470.0 2009.01.17 Virus.Win32.Virut.n
Fortinet 3.117.0.0 2009.01.15 W32/MetaCrypt.7
GData 19 2009.01.17 Win32.Virtob.Gen.9
Ikarus T3.1.1.45.0 2009.01.17 Virus.Win32.Cheburgen.a
K7AntiVirus 7.10.594 2009.01.17 Virus.Win32.Virut.Generic
Kaspersky 7.0.0.125 2009.01.17 Virus.Win32.Virut.n
McAfee 5497 2009.01.16 W32/Virut.gen
McAfee+Artemis 5497 2009.01.16 W32/Virut.gen
Microsoft 1.4205 2009.01.17 Virus:Win32/Virut.AK
NOD32 3773 2009.01.17 Win32/Virut.E
Norman 5.93.01 2009.01.16 W32/Virut.D2
nProtect 2009.1.8.0 2009.01.16 Virus/W32.Virut.D
Panda 9.5.1.2 2009.01.17 W32/Virutas.gen
PCTools 4.4.2.0 2009.01.17 Win32.Virut.Gen
Prevx1 V2 2009.01.17 -
Rising 21.12.52.00 2009.01.17 Win32.Virut.aw
SecureWeb-Gateway 6.7.6 2009.01.16 Win32.Virut.Gen
Sophos 4.37.0 2009.01.17 W32/Vetor-A
Sunbelt 3.2.1835.2 2009.01.16 Trojan.Win32.Packed.gen (v)
Symantec 10 2009.01.17 W32.Virut.B
TheHacker 6.3.1.5.221 2009.01.17 W32/Virut.f
TrendMicro 8.700.0.1004 2009.01.16 PE_VIRUT.D-1
VBA32 3.12.8.10 2009.01.16 Virus.Win32.Virut.3
ViRobot 2009.1.17.1563 2009.01.17 Trojan.Win32.Downloader.28672.BPF
VirusBuster 4.5.11.0 2009.01.17 Win32.Virut.Gen
weitere Informationen
File size: 38400 bytes
MD5...: e4c8094f0188d48bc17a149f0ca05a28
SHA1..: 60436e4acb3c4a25cf1464508600ab9b7b745821
SHA256: 19251d997c0aa8c250cac880bdf06fe937a7560763fbabebf062e7d7dd419d9a
SHA512: 8966c4c4d4c4360c3ce33afed587260be15630fc8be547dbdf3ef8066c9ae06c
cbda6d8f34a23a1802136b39de1d5e867a5b95673d5a62dfe9733701163bf68e
ssdeep: 768:YF5fjfg7/GfnBgcyhCavJzjd75Bkd5XD3ULFwKxF:I5LKefnWYCzjFkduLSe
PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x409200
timedatestamp.....: 0x4600490f (Tue Mar 20 20:50:23 2007)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x36a 0x400 5.50 e67a94a914647a9e5e77c896b0ac5391
.rsrc 0x2000 0x646c 0x6600 7.98 b11b7748b45b838d2fb32b2ad2f775ba
.reloc 0x9000 0x7200 0x2800 7.70 fd2b2add36ae7c06d2ed48cf9842c4ec
( 2 imports )
> KERNEL32.dll: VirtualAllocEx
> ADVAPI32.dll: RegCreateKeyW
( 0 exports ) G:\WINDOWS\TEMP\TMPE.tmp
Nicht vorhanden
G:\Dokumente und Einstellungen\***\B.tmp
Nicht vorhanden
G:\WINDOWS\TEMP\jlv7.tmp
Ergebnis: Code:
Complete scanning result of "jlv7.tmp", processed in VirusTotal at 01/17/2009 15:12:14 (CET).
[ file data ]
* name..: jlv7.tmp
* size..: 23040
* md5...: 30dd0e96b116d9364882aa034e9b3b3d
* sha1..: c10734d7f841da499f965d805cb08c7bd78a35d1
* peid..: -
[ scan result ]
a-squared 4.0.0.73/20090117 found [Trojan-Downloader.Win32.Renos!IK]
AhnLab-V3 2009.1.15.0/20090117 found nothing
AntiVir 7.9.0.55/20090116 found [TR/Dropper.Gen]
Authentium 5.1.0.4/20090116 found nothing
Avast 4.8.1281.0/20090116 found [Win32:Trojan-gen {Other}]
AVG 8.0.0.229/20090116 found [Generic12.AONJ]
BitDefender 7.2/20090117 found [Dropped:Trojan.FakeAlert.ABZ]
CAT-QuickHeal 10.00/20090117 found nothing
ClamAV 0.94.1/20090117 found [Trojan.Fakealert-532]
Comodo 934/20090117 found nothing
DrWeb 4.44.0.09170/20090117 found [Trojan.Inject.5416]
eSafe 7.0.17.0/20090115 found nothing
eTrust-Vet 31.6.6312/20090117 found nothing
F-Prot 4.4.4.56/20090116 found nothing
F-Secure 8.0.14470.0/20090117 found [W32/Malware]
Fortinet 3.117.0.0/20090115 found [PossibleThreat]
GData 19/20090117 found [Dropped:Trojan.FakeAlert.ABZ]
Ikarus T3.1.1.45.0/20090117 found [Trojan-Downloader.Win32.Renos]
K7AntiVirus 7.10.594/20090117 found [Trojan.Win32.Malware.1]
Kaspersky 7.0.0.125/20090117 found [Backdoor.Win32.Hijack.al]
McAfee 5497/20090116 found [Generic Downloader.x]
McAfee+Artemis 5497/20090116 found [Generic Downloader.x]
Microsoft 1.4205/20090117 found [TrojanDownloader:Win32/Renos.AW]
NOD32 3773/20090117 found [probably unknown NewHeur_PE]
Norman 5.93.01/20090116 found [W32/Malware.EZCH]
nProtect 2009.1.8.0/20090116 found [Dropped:Trojan.FakeAlert.ABZ]
Panda 9.5.1.2/20090117 found [Generic Trojan]
PCTools 4.4.2.0/20090117 found nothing
Prevx1 V2/20090117 found [Malicious Software]
Rising 21.12.52.00/20090117 found nothing
SecureWeb-Gateway 6.7.6/20090116 found [Trojan.Dropper.Gen]
Sophos 4.37.0/20090117 found [Troj/Agent-HNY]
Sunbelt 3.2.1835.2/20090116 found nothing
Symantec 10/20090117 found nothing
TheHacker 6.3.1.5.221/20090117 found [Trojan/Downloader.gen]
TrendMicro 8.700.0.1004/20090116 found [TROJ_DLOAD.CAA]
VBA32 3.12.8.10/20090116 found [suspected of Embedded.Backdoor.Win32.Hijack.ai]
ViRobot 2009.1.17.1563/20090117 found nothing
VirusBuster 4.5.11.0/20090117 found [Trojan.FakeAlert.Gen!Pac]
[ notes ]
packers (F-Prot): embedded
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=30dd0e96b116d9364882aa034e9b3b3d
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=4C8F7A1800F4FEEE5A860082CA3FCF00943E8753
CWSandbox info: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=30dd0e96b116d9364882aa034e9b3b3d G:\WINDOWS\system32\regwiz.exe
Ergebnis: Code:
Datei regwiz.exe empfangen 2009.01.17 15:21:44 (CET)
Status: Beendet
Ergebnis: 37/39 (94.88%)
Filter
Drucken der Ergebnisse Antivirus Version letzte aktualisierung Ergebnis
a-squared 4.0.0.73 2009.01.17 Email-Worm.Win32.Mydoom.bj!IK
AhnLab-V3 2009.1.15.0 2009.01.17 Win32/Mydoom.worm.46080
AntiVir 7.9.0.55 2009.01.16 W32/Virut.Gen
Authentium 5.1.0.4 2009.01.16 W32/Virut.9264
Avast 4.8.1281.0 2009.01.16 Win32:Virut
AVG 8.0.0.229 2009.01.16 Win32/Virut
BitDefender 7.2 2009.01.17 Win32.Virtob.Gen.9
CAT-QuickHeal 10.00 2009.01.17 W32.Virut.D
ClamAV 0.94.1 2009.01.17 W32.Virut.ia
Comodo 934 2009.01.17 -
DrWeb 4.44.0.09170 2009.01.17 Win32.Virut.5
eSafe 7.0.17.0 2009.01.15 Win32.Virut.gen
eTrust-Vet 31.6.6312 2009.01.17 Win32/Virut.9276
F-Prot 4.4.4.56 2009.01.16 W32/Virut.9264
F-Secure 8.0.14470.0 2009.01.17 Virus.Win32.Virut.n
Fortinet 3.117.0.0 2009.01.15 W32/Virut.fam
GData 19 2009.01.17 Win32.Virtob.Gen.9
Ikarus T3.1.1.45.0 2009.01.17 Email-Worm.Win32.Mydoom.bj
K7AntiVirus 7.10.594 2009.01.17 Virus.Win32.Virut.Generic
Kaspersky 7.0.0.125 2009.01.17 Virus.Win32.Virut.n
McAfee 5497 2009.01.16 W32/Virut.gen
McAfee+Artemis 5497 2009.01.16 W32/Virut.gen
Microsoft 1.4205 2009.01.17 Virus:Win32/Virut.AK
NOD32 3773 2009.01.17 Win32/Virut.E
Norman 5.93.01 2009.01.16 W32/Virut.D2
nProtect 2009.1.8.0 2009.01.16 Virus/W32.Virut.G
Panda 9.5.1.2 2009.01.17 W32/Virutas.gen
PCTools 4.4.2.0 2009.01.17 Trojan.Agent.DEL
Prevx1 V2 2009.01.17 -
Rising 21.12.52.00 2009.01.17 Win32.Virut.GEN
SecureWeb-Gateway 6.7.6 2009.01.16 Win32.Virut.Gen
Sophos 4.37.0 2009.01.17 W32/Virut-L
Sunbelt 3.2.1835.2 2009.01.16 Win32.Virut.o (v)
Symantec 10 2009.01.17 W32.Mytob@mm
TheHacker 6.3.1.5.221 2009.01.17 W32/Virut.gen
TrendMicro 8.700.0.1004 2009.01.16 PE_VIRUT.D-4
VBA32 3.12.8.10 2009.01.16 Virus.Win32.Virut.3
ViRobot 2009.1.17.1563 2009.01.17 Win32.Virut.D
VirusBuster 4.5.11.0 2009.01.17 Trojan.Agent.DEL
weitere Informationen
File size: 55808 bytes
MD5...: db42988fd95a19e4fbdf7c781ae6d6ec
SHA1..: 0df471815580c38d8d07a51103cdb8065c2bc4b3
SHA256: f4334e587ee4175ee611983b472fab6b4c33ac39198726345b937c153345375f
SHA512: 39b78fddfbf6c7573470d9d82628888efaa60a3ab6a9c272d47d48c31a0076b2
fcf970ee385be3a5c3d8c96d32f10472c12420fdc91c790365a3a565f34fcfe5
ssdeep: 1536:k+8oHDAbgO0gw/Z0HPAas5vG+dGvH3w/fGzG:kIUb3W0HYa72uwnF
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x41b070
timedatestamp.....: 0x46d6fefa (Thu Aug 30 17:31:38 2007)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x10000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x11000 0xb000 0xa400 7.89 10af9197e80fab3979a7535d69271f48
.rsrc 0x1c000 0x8000 0x3200 6.22 a9d52bbbe52dfe299d83f67d0096ca0b
( 4 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, ExitProcess
> ADVAPI32.dll: RegCloseKey
> USER32.dll: wsprintfA
> WS2_32.dll: -
( 0 exports ) |