Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.7.9.2 2008.07.09 -
AntiVir 7.8.0.64 2008.07.09 -
Authentium 5.1.0.4 2008.07.08 -
Avast 4.8.1195.0 2008.07.09 Win32:Rootkit-gen
AVG 7.5.0.516 2008.07.09 -
BitDefender 7.2 2008.07.09 -
CAT-QuickHeal 9.50 2008.07.09 -
ClamAV 0.93.1 2008.07.09 -
DrWeb 4.44.0.09170 2008.07.09 -
eSafe 7.0.17.0 2008.07.08 -
eTrust-Vet 31.6.5939 2008.07.09 -
Ewido 4.0 2008.07.09 -
F-Prot 4.4.4.56 2008.07.08 -
F-Secure 7.60.13501.0 2008.07.08 -
Fortinet 3.14.0.0 2008.07.09 -
GData 2.0.7306.1023 2008.07.09 Win32:Rootkit-gen
Ikarus T3.1.1.26.0 2008.07.09 -
Kaspersky 7.0.0.125 2008.07.09 -
McAfee 5334 2008.07.08 -
Microsoft 1.3704 2008.07.09 -
NOD32v2 3255 2008.07.09 -
Norman 5.80.02 2008.07.08 -
Panda 9.0.0.4 2008.07.08 -
Prevx1 V2 2008.07.09 -
Rising 20.52.22.00 2008.07.09 -
Sophos 4.31.0 2008.07.09 -
Sunbelt 3.1.1509.1 2008.07.04 -
Symantec 10 2008.07.09 -
TheHacker 6.2.96.374 2008.07.07 -
TrendMicro 8.700.0.1004 2008.07.09 -
VBA32 3.12.6.8 2008.07.08 -
VirusBuster 4.5.11.0 2008.07.08 -
Webwasher-Gateway 6.6.2 2008.07.09 Win32.Malware.gen!92 (suspicious)
weitere Informationen
File size: 136888 bytes
MD5...: e2bf955fe43c7a79d6cddcf2c100ed78
SHA1..: 5e4c6b2f6999599310dbeed02977168fff0d5c3e
SHA256: 459d87fd6789edec3c39769b638f50b886fb483b470f21111e0034e7842929d2
SHA512: b00b30510e42ca58549e8c19c5237384d0ddf95943afd792a7847aca88335f4b
af0ba851829ddc2a7d9c6fec033876e1ff369b17555715008b8db193e0c88841
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x10003320
timedatestamp.....: 0x48699a10 (Tue Jul 01 02:44:32 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x6400 0x6400 7.34 34d6b0c4159a766202ef7c79b1772c66
.rdata 0x8000 0x2fa 0x400 4.16 f60c82d71fb821fea0439bc1b4b4ae41
.data 0x9000 0x1680 0xa00 1.68 84869ab031f1d047090c367228fafbab
.reloc 0xb000 0x18b7c 0x18b7c 7.86 7a8126e9a029d9de07d18c8503a2aa1e
( 1 imports )
> ntoskrnl.exe: RtlFreeAnsiString, RtlFreeUnicodeString, RtlUnicodeStringToAnsiString, RtlQueryRegistryValues, memset, IoGetCurrentProcess, strncmp, memcpy, ObfDereferenceObject, ObReferenceObjectByHandle, strlen, KeTickCount, MmGetSystemRoutineAddress, RtlInitUnicodeString, PsGetCurrentProcessId, _except_handler3, ExFreePoolWithTag, ExAllocatePoolWithTag, IofCompleteRequest, IoDeleteSymbolicLink, IoDeleteDevice, IoCreateSymbolicLink, IoCreateDevice
( 0 exports )