CIMG_002851.scr
ZitatAlles anzeigenDatei CIMG_002851.scr empfangen 2008.12.18 21:37:02 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.12.19.0 2008.12.18 Win-Trojan/Inject.626688.B
AntiVir 7.9.0.45 2008.12.18 PCK/Armadillo
Authentium 5.1.0.4 2008.12.18 W32/Trojan3.IA
Avast 4.8.1281.0 2008.12.18 Win32:IRCBot-BSX
AVG 8.0.0.199 2008.12.18 -
BitDefender 7.2 2008.12.18 MemScan:Backdoor.IRCBot.ACNF
CAT-QuickHeal 10.00 2008.12.18 Backdoor.SdBot.iwa
ClamAV 0.94.1 2008.12.18 -
Comodo 771 2008.12.17 Backdoor.Win32.SdBot.~FV
DrWeb 4.44.0.09170 2008.12.18 -
eSafe 7.0.17.0 2008.12.18 -
eTrust-Vet 31.6.6267 2008.12.18 -
Ewido 4.0 2008.12.18 -
F-Prot 4.4.4.56 2008.12.18 W32/Trojan3.IA
F-Secure 8.0.14332.0 2008.12.18 -
Fortinet 3.117.0.0 2008.12.18 -
GData 19 2008.12.18 MemScan:Backdoor.IRCBot.ACNF
Ikarus T3.1.1.45.0 2008.12.18 -
K7AntiVirus 7.10.557 2008.12.18 -
Kaspersky 7.0.0.125 2008.12.18 -
McAfee 5468 2008.12.18 -
McAfee+Artemis 5468 2008.12.18 -
Microsoft 1.4205 2008.12.18 -
NOD32 3703 2008.12.18 -
Norman 5.80.02 2008.12.18 -
Panda 9.0.0.4 2008.12.18 Suspicious file
PCTools 4.4.2.0 2008.12.18 -
Prevx1 V2 2008.12.18 -
Rising 21.08.32.00 2008.12.18 -
SecureWeb-Gateway 6.7.6 2008.12.18 Packer.Armadillo
Sophos 4.37.0 2008.12.18 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.18 -
TheHacker 6.3.1.4.191 2008.12.17 -
TrendMicro 8.700.0.1004 2008.12.18 -
VBA32 3.12.8.10 2008.12.18 Trojan.Win32.Inject.jux
ViRobot 2008.12.18.1525 2008.12.18 -
VirusBuster 4.5.11.0 2008.12.18 -
weitere Informationen
File size: 634880 bytes
MD5...: 3a062aa1bf17a7478750f8558312814c
SHA1..: b7dc0235bd7f65a4b8119359435e5d23f13d6b28
SHA256: 6a314f5ca749c2d21b6cac5594644804b6df49c2c85c65ee939d76cb4441db85
SHA512: f9a5bf1f59b62ea42e832fbf18118a267af0974d096702379afe2724737cdce3<br>216bdf686a3ab55d3cb3aeb623d6078457d04a040fadbf0188095246587d8068<br>
ssdeep: 12288:eiWaUgfDhOPo0VdfG1mIn0sSelRnlUZrHQs:eiWDgfAJH6m0hl9lUtws<br>
PEiD..: -
TrID..: File type identification<br>Generic Win/DOS Executable (49.9%)<br>DOS Executable Generic (49.8%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x484dd2<br>timedatestamp.....: 0x494c037c (Fri Dec 19 20:26:36 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 8 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x40a8 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>.rdata 0x6000 0xc10 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>.data 0x7000 0x451bc 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>.text1 0x4d000 0x50000 0x42000 6.44 b1078f14803056b4994f6cec9c7bb064<br>.adata 0x9d000 0x10000 0xd000 0.00 938d6d97628275a512e07c66be5ccecf<br>.data1 0xad000 0x20000 0xb000 3.71 5218d16d1d3bcc546a001421587d4a30<br>.pdata 0xcd000 0x40000 0x3e000 8.00 3ff179ce321348fbe2b30bb63db131eb<br>.rsrc 0x10d000 0x2000 0x2000 3.04 3fc091a06cac948526c44567fca7f8aa<br><br>( 3 imports ) <br>> KERNEL32.dll: CreateThread, GlobalUnlock, GlobalLock, GlobalAlloc, GetTickCount, WideCharToMultiByte, IsBadReadPtr, GlobalAddAtomA, GlobalAddAtomW, GetModuleHandleA, GlobalFree, GlobalGetAtomNameA, GlobalDeleteAtom, GlobalGetAtomNameW, FreeConsole, GetEnvironmentVariableA, VirtualProtect, VirtualAlloc, GetProcAddress, GetLastError, LoadLibraryA, SetLastError, SetThreadPriority, GetCurrentThread, CreateProcessA, GetCommandLineA, GetStartupInfoA, SetEnvironmentVariableA, ReleaseMutex, WaitForSingleObject, CreateMutexA, OpenMutexA, GetCurrentThreadId, CreateFileA, FindClose, FindFirstFileA, FindFirstFileW, VirtualQueryEx, GetExitCodeProcess, ReadProcessMemory, UnmapViewOfFile, ContinueDebugEvent, SetThreadContext, GetThreadContext, WaitForDebugEvent, SuspendThread, DebugActiveProcess, ResumeThread, CreateProcessW, GetCommandLineW, GetStartupInfoW, CloseHandle, DuplicateHandle, GetCurrentProcess, CreateFileMappingA, VirtualProtectEx, WriteProcessMemory, ExitProcess, FlushFileBuffers, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetConsoleMode, GetConsoleCP, SetFilePointer, GetLocaleInfoA, GetStringTypeW, GetStringTypeA, LCMapStringW, MultiByteToWideChar, LCMapStringA, HeapSize, HeapReAlloc, QueryPerformanceCounter, VirtualFree, HeapCreate, HeapDestroy, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, RtlUnwind, DeleteCriticalSection, GetStdHandle, WriteFile, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, Sleep, EnterCriticalSection, LeaveCriticalSection, GetVersionExA, InitializeCriticalSection, GetCurrentProcessId, GetModuleFileNameW, GetShortPathNameW, GetModuleFileNameA, MapViewOfFile, GetShortPathNameA, GetSystemTimeAsFileTime, HeapFree, HeapAlloc, GetProcessHeap, RaiseException, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage<br>> USER32.dll: GetDesktopWindow, MoveWindow, SetPropA, EnumThreadWindows, GetPropA, GetMessageA, GetSystemMetrics, SetTimer, GetAsyncKeyState, KillTimer, BeginPaint, EndPaint, SetWindowTextA, GetDlgItem, CreateDialogIndirectParamA, ShowWindow, UpdateWindow, LoadStringA, LoadStringW, FindWindowA, WaitForInputIdle, MessageBoxA, InSendMessage, UnpackDDElParam, FreeDDElParam, DefWindowProcA, LoadCursorA, RegisterClassW, CreateWindowExW, RegisterClassA, CreateWindowExA, GetWindowThreadProcessId, SendMessageW, SendMessageA, PeekMessageA, TranslateMessage, DispatchMessageA, EnumWindows, IsWindowUnicode, PackDDElParam, PostMessageW, PostMessageA, IsWindow, DestroyWindow<br>> GDI32.dll: CreateDCA, CreateDIBitmap, CreateCompatibleDC, SelectObject, SelectPalette, RealizePalette, BitBlt, DeleteDC, DeleteObject, CreatePalette<br><br>( 0 exports ) <br>
packers (Kaspersky): Armadillo
packers (Avast): ArmadilloAntivirus;Version;letzte aktualisierung;Ergebnis
AhnLab-V3;2008.12.19.0;2008.12.18;Win-Trojan/Inject.626688.B
AntiVir;7.9.0.45;2008.12.18;PCK/Armadillo
Authentium;5.1.0.4;2008.12.18;W32/Trojan3.IA
Avast;4.8.1281.0;2008.12.18;Win32:IRCBot-BSX
AVG;8.0.0.199;2008.12.18;-
BitDefender;7.2;2008.12.18;MemScan:Backdoor.IRCBot.ACNF
CAT-QuickHeal;10.00;2008.12.18;Backdoor.SdBot.iwa
ClamAV;0.94.1;2008.12.18;-
Comodo;771;2008.12.17;Backdoor.Win32.SdBot.~FV
DrWeb;4.44.0.09170;2008.12.18;-
eSafe;7.0.17.0;2008.12.18;-
eTrust-Vet;31.6.6267;2008.12.18;-
Ewido;4.0;2008.12.18;-
F-Prot;4.4.4.56;2008.12.18;W32/Trojan3.IA
F-Secure;8.0.14332.0;2008.12.18;-
Fortinet;3.117.0.0;2008.12.18;-
GData;19;2008.12.18;MemScan:Backdoor.IRCBot.ACNF
Ikarus;T3.1.1.45.0;2008.12.18;-
K7AntiVirus;7.10.557;2008.12.18;-
Kaspersky;7.0.0.125;2008.12.18;-
McAfee;5468;2008.12.18;-
McAfee+Artemis;5468;2008.12.18;-
Microsoft;1.4205;2008.12.18;-
NOD32;3703;2008.12.18;-
Norman;5.80.02;2008.12.18;-
Panda;9.0.0.4;2008.12.18;Suspicious file
PCTools;4.4.2.0;2008.12.18;-
Prevx1;V2;2008.12.18;-
Rising;21.08.32.00;2008.12.18;-
SecureWeb-Gateway;6.7.6;2008.12.18;Packer.Armadillo
Sophos;4.37.0;2008.12.18;-
Sunbelt;3.2.1801.2;2008.12.11;-
Symantec;10;2008.12.18;-
TheHacker;6.3.1.4.191;2008.12.17;-
TrendMicro;8.700.0.1004;2008.12.18;-
VBA32;3.12.8.10;2008.12.18;Trojan.Win32.Inject.jux
ViRobot;2008.12.18.1525;2008.12.18;-
VirusBuster;4.5.11.0;2008.12.18;-weitere Informationen
File size: 634880 bytes
MD5...: 3a062aa1bf17a7478750f8558312814c
SHA1..: b7dc0235bd7f65a4b8119359435e5d23f13d6b28
SHA256: 6a314f5ca749c2d21b6cac5594644804b6df49c2c85c65ee939d76cb4441db85
SHA512: f9a5bf1f59b62ea42e832fbf18118a267af0974d096702379afe2724737cdce3<br>216bdf686a3ab55d3cb3aeb623d6078457d04a040fadbf0188095246587d8068<br>
ssdeep: 12288:eiWaUgfDhOPo0VdfG1mIn0sSelRnlUZrHQs:eiWDgfAJH6m0hl9lUtws<br>
PEiD..: -
TrID..: File type identification<br>Generic Win/DOS Executable (49.9%)<br>DOS Executable Generic (49.8%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x484dd2<br>timedatestamp.....: 0x494c037c (Fri Dec 19 20:26:36 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 8 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x40a8 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>.rdata 0x6000 0xc10 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>.data 0x7000 0x451bc 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>.text1 0x4d000 0x50000 0x42000 6.44 b1078f14803056b4994f6cec9c7bb064<br>.adata 0x9d000 0x10000 0xd000 0.00 938d6d97628275a512e07c66be5ccecf<br>.data1 0xad000 0x20000 0xb000 3.71 5218d16d1d3bcc546a001421587d4a30<br>.pdata 0xcd000 0x40000 0x3e000 8.00 3ff179ce321348fbe2b30bb63db131eb<br>.rsrc 0x10d000 0x2000 0x2000 3.04 3fc091a06cac948526c44567fca7f8aa<br><br>( 3 imports ) <br>> KERNEL32.dll: CreateThread, GlobalUnlock, GlobalLock, GlobalAlloc, GetTickCount, WideCharToMultiByte, IsBadReadPtr, GlobalAddAtomA, GlobalAddAtomW, GetModuleHandleA, GlobalFree, GlobalGetAtomNameA, GlobalDeleteAtom, GlobalGetAtomNameW, FreeConsole, GetEnvironmentVariableA, VirtualProtect, VirtualAlloc, GetProcAddress, GetLastError, LoadLibraryA, SetLastError, SetThreadPriority, GetCurrentThread, CreateProcessA, GetCommandLineA, GetStartupInfoA, SetEnvironmentVariableA, ReleaseMutex, WaitForSingleObject, CreateMutexA, OpenMutexA, GetCurrentThreadId, CreateFileA, FindClose, FindFirstFileA, FindFirstFileW, VirtualQueryEx, GetExitCodeProcess, ReadProcessMemory, UnmapViewOfFile, ContinueDebugEvent, SetThreadContext, GetThreadContext, WaitForDebugEvent, SuspendThread, DebugActiveProcess, ResumeThread, CreateProcessW, GetCommandLineW, GetStartupInfoW, CloseHandle, DuplicateHandle, GetCurrentProcess, CreateFileMappingA, VirtualProtectEx, WriteProcessMemory, ExitProcess, FlushFileBuffers, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetConsoleMode, GetConsoleCP, SetFilePointer, GetLocaleInfoA, GetStringTypeW, GetStringTypeA, LCMapStringW, MultiByteToWideChar, LCMapStringA, HeapSize, HeapReAlloc, QueryPerformanceCounter, VirtualFree, HeapCreate, HeapDestroy, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, RtlUnwind, DeleteCriticalSection, GetStdHandle, WriteFile, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, Sleep, EnterCriticalSection, LeaveCriticalSection, GetVersionExA, InitializeCriticalSection, GetCurrentProcessId, GetModuleFileNameW, GetShortPathNameW, GetModuleFileNameA, MapViewOfFile, GetShortPathNameA, GetSystemTimeAsFileTime, HeapFree, HeapAlloc, GetProcessHeap, RaiseException, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage<br>> USER32.dll: GetDesktopWindow, MoveWindow, SetPropA, EnumThreadWindows, GetPropA, GetMessageA, GetSystemMetrics, SetTimer, GetAsyncKeyState, KillTimer, BeginPaint, EndPaint, SetWindowTextA, GetDlgItem, CreateDialogIndirectParamA, ShowWindow, UpdateWindow, LoadStringA, LoadStringW, FindWindowA, WaitForInputIdle, MessageBoxA, InSendMessage, UnpackDDElParam, FreeDDElParam, DefWindowProcA, LoadCursorA, RegisterClassW, CreateWindowExW, RegisterClassA, CreateWindowExA, GetWindowThreadProcessId, SendMessageW, SendMessageA, PeekMessageA, TranslateMessage, DispatchMessageA, EnumWindows, IsWindowUnicode, PackDDElParam, PostMessageW, PostMessageA, IsWindow, DestroyWindow<br>> GDI32.dll: CreateDCA, CreateDIBitmap, CreateCompatibleDC, SelectObject, SelectPalette, RealizePalette, BitBlt, DeleteDC, DeleteObject, CreatePalette<br><br>( 0 exports ) <br>
packers (Kaspersky): Armadillo
packers (Avast): Armadillo


