Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | Magyar | Deutsch | Česky | Polski | Español | English
Virus Total

VirusTotal 是一款可疑文件分析服务, 通过各种知名反病毒引擎, 对您所上传的文件进行检测, 以判断文件是否被病毒, 蠕虫, 木马, 以及各类恶意软件感染. 查看详细信息...

文件 report-8977-exe.txt 接收于 2009.06.17 17:22:07 (UTC)
当前状态: 完成
结果: 6/41 (14.63%)
反病毒引擎 版本 最后更新 扫描结果
a-squared 4.5.0.18 2009.06.17 Win32.SuspectCrc!IK
AhnLab-V3 5.0.0.2 2009.06.17 -
AntiVir 7.9.0.187 2009.06.17 -
Antiy-AVL 2.0.3.1 2009.06.17 -
Authentium 5.1.2.4 2009.06.17 -
Avast 4.8.1335.0 2009.06.16 -
AVG 8.5.0.339 2009.06.17 -
BitDefender 7.2 2009.06.17 -
CAT-QuickHeal 10.00 2009.06.17 -
ClamAV 0.94.1 2009.06.17 -
Comodo 1352 2009.06.17 -
DrWeb 5.0.0.12182 2009.06.17 -
eSafe 7.0.17.0 2009.06.17 -
eTrust-Vet 31.6.6564 2009.06.17 -
F-Prot 4.4.4.56 2009.06.16 -
F-Secure 8.0.14470.0 2009.06.17 -
Fortinet 3.117.0.0 2009.06.17 -
GData 19 2009.06.17 -
Ikarus T3.1.1.59.0 2009.06.17 Win32.SuspectCrc
Jiangmin 11.0.706 2009.06.17 -
K7AntiVirus 7.10.766 2009.06.17 -
Kaspersky 7.0.0.125 2009.06.17 -
McAfee 5649 2009.06.17 -
McAfee+Artemis 5649 2009.06.17 -
McAfee-GW-Edition 6.7.6 2009.06.17 -
Microsoft 1.4701 2009.06.17 -
NOD32 4163 2009.06.17 -
Norman 6.01.09 2009.06.17 -
nProtect 2009.1.8.0 2009.06.17 -
Panda 10.0.0.14 2009.06.16 Suspicious file
PCTools 4.4.2.0 2009.06.17 -
Prevx 3.0 2009.06.17 Medium Risk Malware
Rising 21.34.24.00 2009.06.17 -
Sophos 4.42.0 2009.06.17 Troj/Agent-KFA
Sunbelt 3.2.1858.2 2009.06.17 -
Symantec 1.4.4.12 2009.06.17 Infostealer.Bancos.C
TheHacker 6.3.4.3.348 2009.06.17 -
TrendMicro 8.950.0.1094 2009.06.17 -
VBA32 3.12.10.7 2009.06.17 -
ViRobot 2009.6.17.1792 2009.06.17 -
VirusBuster 4.6.5.0 2009.06.17 -
附加信息
File size: 81920 bytes
MD5   : d4e6069285270e41ef470d897cf26e36
SHA1  : 854bf8ff8933cd30797eb1d2e134a4895f574af6
SHA256: 8e6cfb980d4a6a364ce714244f761d2c056c57688908e3d8e263d4fd119043ba
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x6E3E
timedatestamp.....: 0x48400198 (Fri May 30 15:31:04 2008)
machinetype.......: 0x14C (Intel I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x11557 0x11600 7.30 f14357b2860cf8116eb9cb7c5b39ed26
.rdata 0x13000 0x2268 0x2400 5.45 223f5966cc500ab7f2146562fa4c655b
.data 0x16000 0x504E 0x200 0.12 f46625fb607f845f461f36cc586481a1

( 5 imports )

> advapi32.dll: OpenEventLogW, CloseServiceHandle, CryptExportKey, RevertToSelf, GetMultipleTrusteeA, EnumDependentServicesW, SetEntriesInAccessListA, ImpersonateSelf, RegisterServiceCtrlHandlerA, AdjustTokenPrivileges, AddAuditAccessAce, RegQueryMultipleValuesW, GetNamedSecurityInfoExW, GetAccessPermissionsForObjectA, BuildTrusteeWithSidA, GetMultipleTrusteeW, GetMultipleTrusteeOperationA, SetSecurityInfoExW, CryptReleaseContext, CryptGenKey, RegCloseKey, RegFlushKey, MakeAbsoluteSD, SetSecurityDescriptorDacl, RegSetKeySecurity, BuildTrusteeWithNameA, OpenBackupEventLogA, GetFileSecurityW, CryptGetHashParam, BuildTrusteeWithSidW, SetEntriesInAccessListW, RegCreateKeyExA, GetSecurityDescriptorSacl, CryptVerifySignatureW, GetServiceKeyNameW, ObjectOpenAuditAlarmW, RegOpenKeyExW, SetNamedSecurityInfoA, GetSecurityDescriptorGroup, OpenBackupEventLogW, RegReplaceKeyW, CryptGenRandom, CryptDestroyKey, GetSidSubAuthority, SetKernelObjectSecurity, CryptDuplicateHash, LookupPrivilegeNameA
> kernel32.dll: MapViewOfFileEx, ReadConsoleInputA, IsBadWritePtr, VirtualProtectEx, Heap32First, ReleaseSemaphore, GetNumberFormatA, Heap32ListNext, GetStringTypeExA, GetStartupInfoA, MapViewOfFile, IsProcessorFeaturePresent, GetCurrencyFormatW, TerminateProcess, GetConsoleMode, WritePrivateProfileStringW, GetCommConfig, FindNextFileW, LoadModule, SetSystemPowerState, CreateMutexA, ConvertThreadToFiber, VirtualProtect, SetupComm, SetDefaultCommConfigW, DefineDosDeviceA, GetVersionExA, EnumCalendarInfoW, WaitForDebugEvent, LockFileEx, MulDiv, GlobalFix, GetModuleHandleA, Thread32First, GetVersionExW, BeginUpdateResourceA, GetFileAttributesW, lstrcpyn, ResumeThread, GetConsoleCursorInfo, GetVolumeInformationA, FindResourceA, SetVolumeLabelA, GetFullPathNameW, PrepareTape, HeapLock, GetProcessShutdownParameters, WritePrivateProfileStructA, GetCommandLineW, ReadConsoleOutputAttribute, SetFilePointer, SetVolumeLabelW, GetOEMCP, VirtualAlloc, GetLogicalDriveStringsA, WriteConsoleOutputA, UpdateResourceA, WriteTapemark, PurgeComm, SetWaitableTimer, GetProcessHeap, SetCommTimeouts, RequestWakeupLatency
> ole32.dll: OleCreateFromDataEx, OleLockRunning, CoInitializeSecurity, BindMoniker, CoSwitchCallContext, StgCreateDocfileOnILockBytes, IsEqualGUID, OleRegGetUserType, CoFreeAllLibraries, CoIsHandlerConnected, PropVariantClear, StgOpenAsyncDocfileOnIFillLockBytes, ReadFmtUserTypeStg, OleCreate, StgIsStorageFile, WriteOleStg, OleTranslateAccelerator, CoDisconnectObject, OleGetIconOfClass, OleCreateLinkFromDataEx, CoRevertToSelf, OleCreateFromFile, CoQueryClientBlanket, ReadClassStm, CreateOleAdviseHolder, OleInitialize, OleConvertIStorageToOLESTREAMEx, DllDebugObjectRPCHook, CoGetTreatAsClass, CoFileTimeNow, OleGetClipboard, CoUnmarshalHresult, ReadClassStg, GetRunningObjectTable, CoImpersonateClient, CoMarshalInterface, CoFreeUnusedLibraries, CLSIDFromProgID, CreateDataAdviseHolder, CoGetCurrentLogicalThreadId, OleCreateLink, ProgIDFromCLSID, CoMarshalHresult, CoGetMarshalSizeMax, CoGetPSClsid, StgGetIFillLockBytesOnFile, CoFileTimeToDosDateTime, CoAddRefServerProcess, OpenOrCreateStream, SetConvertStg, StgIsStorageILockBytes, CoTaskMemFree, OleNoteObjectVisible, CoTaskMemAlloc, CreateItemMoniker, StgOpenStorage, OleIsCurrentClipboard
> shlwapi.dll: StrCmpNIW, StrRChrIA, wnsprintfA, PathRemoveBlanksW, PathIsDirectoryA, SHRegQueryUSValueW, UrlEscapeW, StrIsIntlEqualA, PathIsURLA, PathCombineW, UrlHashW, UrlApplySchemeA, StrCSpnA, ChrCmpIA, StrCatBuffA, UrlCombineW, PathFindOnPathW, HashData, PathCompactPathExA, StrChrW, SHRegCreateUSKeyW, SHStrDupW, IntlStrEqWorkerA, IntlStrEqWorkerW, UrlEscapeA, AssocQueryKeyA, PathUnmakeSystemFolderA, SHRegQueryInfoUSKeyA, StrChrIA, PathGetDriveNumberW, PathIsDirectoryW, SHGetInverseCMAP, PathStripToRootA, SHRegDeleteEmptyUSKeyA, PathCreateFromUrlW, SHOpenRegStream2W, SHStrDupA, PathRenameExtensionA, PathCreateFromUrlA, UrlGetPartA, PathBuildRootA, StrCatBuffW, SHAutoComplete, StrToIntExW, PathSkipRootA, GetMenuPosFromID, PathBuildRootW, PathRemoveArgsA, PathIsUNCServerShareA, UrlCanonicalizeW, StrToIntW
> user32.dll: WindowFromDC, GetClipCursor, CallMsgFilterA, GetCursorInfo, DrawTextW, GetUserObjectInformationW, SwitchDesktop, DrawTextExW, SetTimer, DefWindowProcW, LoadIconW, GetDialogBaseUnits, GetTabbedTextExtentA, RegisterWindowMessageA, OemKeyScan, GetKeyboardLayoutList, EnumDisplayDevicesA, BroadcastSystemMessageA, GetProcessDefaultLayout, DlgDirSelectComboBoxExW, GetWindow, GetKeyboardLayoutNameA, ToUnicode, IsZoomed, GetClassInfoExA, UnregisterClassA, LoadImageW, EnumPropsW, SetUserObjectInformationA, GetInputState, GetTitleBarInfo, LoadMenuA, DialogBoxIndirectParamW, DdeAddData, GetUserObjectSecurity, GetKBCodePage, InvertRect, EditWndProc, FrameRect, MsgWaitForMultipleObjects, TrackMouseEvent, SetScrollInfo, GetMessageW, GetPropA, ReplyMessage, ChangeDisplaySettingsW, GetScrollInfo, SetWindowWord, EnumClipboardFormats, SendMessageTimeoutA, WindowFromPoint, DlgDirListComboBoxW, DrawIconEx, ChildWindowFromPointEx, SetMenu, GetMessageTime, FindWindowW, PaintDesktop, CharLowerBuffA, EnumDesktopsA, ChangeMenuA, CreateCaret, IntersectRect, GetMonitorInfoA, GetWindowModuleFileNameA, DlgDirListComboBoxA, SetDoubleClickTime, EnumPropsA, OpenWindowStationW, DrawStateA, GetMessageA, SetMenuItemInfoW, RegisterHotKey, CallMsgFilterW, GetDlgItemTextA, GetWindowContextHelpId, CopyAcceleratorTableA, DrawFocusRect, IsChild, GetDesktopWindow, DefDlgProcW, HiliteMenuItem, IsWindowVisible, LoadKeyboardLayoutW, SetWindowLongA, IsCharAlphaNumericA, DdeConnectList, CharToOemA, VkKeyScanW, CharUpperW, RegisterClassA, CreateMDIWindowW, HideCaret, GetWindowTextA, InflateRect

( 0 exports )
TrID  : File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=d4e6069285270e41ef470d897cf26e36
ssdeep: 1536:Kr4+/vEu6O12KHVBoqEmGkmdLeJmGqEDF/cnVeW4HZBCdHDb9yH9hdBlJ:oT1BaO2LeJ99ZcVwHZBi8hdBl
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=53CFF7250014C51640AA0190BB6C1700E8CE91E7
PEiD  : -
RDS   : NSRL Reference Data Set
-

注意 注意: VirusTotal 是 Hispasec Sistemas 提供的免费服务. 我们不保证任何该服务的可用性和持续性. 尽管使用多种反病毒引擎所提供的检测率优于使用单一产品, 但这些结果并不保证文件无害. 目前来说, 没有任何一种解决方案可以提供 100% 的病毒和恶意软件检测率. 如果您购买了一款声称具有此能力的产品, 那么您可能已经成为受害者.

扫描其它文件