S PC to vypadá dobře...
C:\Windows\SysWOW64\CTXFISPI.EXE
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.03.07 -
AhnLab-V3 5.0.0.2 2010.03.07 -
AntiVir 8.2.1.180 2010.03.05 -
Antiy-AVL 2.0.3.7 2010.03.05 -
Authentium 5.2.0.5 2010.03.06 -
Avast 4.8.1351.0 2010.03.07 -
Avast5 5.0.332.0 2010.03.07 -
AVG 9.0.0.787 2010.03.07 -
BitDefender 7.2 2010.03.07 -
CAT-QuickHeal 10.00 2010.03.06 -
ClamAV 0.96.0.0-git 2010.03.06 -
Comodo 4091 2010.02.28 -
DrWeb 5.0.1.12222 2010.03.07 -
eSafe 7.0.17.0 2010.03.04 -
eTrust-Vet 35.2.7342 2010.03.05 -
F-Prot 4.5.1.85 2010.03.06 -
F-Secure 9.0.15370.0 2010.03.07 -
Fortinet 4.0.14.0 2010.03.07 -
GData 19 2010.03.07 -
Ikarus T3.1.1.80.0 2010.03.07 -
Jiangmin 13.0.900 2010.03.07 -
K7AntiVirus 7.10.990 2010.03.04 -
Kaspersky 7.0.0.125 2010.03.07 -
McAfee 5912 2010.03.06 -
McAfee+Artemis 5912 2010.03.06 -
McAfee-GW-Edition 6.8.5 2010.03.07 -
Microsoft 1.5502 2010.03.07 -
NOD32 4922 2010.03.07 -
Norman 6.04.08 2010.03.07 -
nProtect 2009.1.8.0 2010.03.07 -
Panda 10.0.2.2 2010.03.07 -
PCTools 7.0.3.5 2010.03.04 -
Prevx 3.0 2010.03.09 -
Rising 22.37.06.04 2010.03.07 -
Sophos 4.51.0 2010.03.07 -
Sunbelt 5780 2010.03.07 -
Symantec 20091.2.0.41 2010.03.07 -
TheHacker 6.5.1.9.223 2010.03.07 -
TrendMicro 9.120.0.1004 2010.03.07 -
VBA32 3.12.12.2 2010.03.05 -
ViRobot 2010.3.5.2214 2010.03.05 -
VirusBuster 5.0.27.0 2010.03.06 -
Rozšiřující informace
File size: 1213440 bytes
MD5...: d22b70cfdb85dd96b551efd30281ffa3
SHA1..: 53321e9843a35db33f04a4c79baf06a2d8525d8d
SHA256: 853fc77b93ed7d1434ef43357c8da6fdd1d88ace40fdd5aaade9380939c012e6
ssdeep: 24576:cExfZV9VuRuVJVgRgl+9AqqqbH3W1P90nM+4u+oub0sRhInFyvJHm1j8BL
pQikMa:cExfZV9VuRuVJVgRgl+9AqqqbH3W1P9S
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0xcb708
timedatestamp.....: 0x4a26a9ae (Wed Jun 03 16:49:50 2009)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xdc928 0xdca00 6.38 069510ff79c357b9ed58199bfcac67e7
.data 0xde000 0xefd0 0xe200 5.14 2daf567299974ba038dc81f6baab7bf1
.rsrc 0xed000 0x3d3c8 0x3d400 5.39 5aaaedf32467bc1cd189fef72a70e858
( 12 imports )
> ADVAPI32.dll: RegDeleteKeyA, RegDeleteValueA, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA, RegSetValueExA, RegQueryInfoKeyA, RegQueryValueExA, RegCreateKeyA, RegEnumKeyExA, RegOpenKeyA, SetNamedSecurityInfoA, RegEnumValueA
> KERNEL32.dll: InterlockedExchange, MultiByteToWideChar, WideCharToMultiByte, GetLastError, GetVersion, lstrlenW, lstrcmpiA, lstrlenA, GetEnvironmentVariableA, RaiseException, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, SizeofResource, LockResource, LoadResource, FindResourceA, FindResourceExA, FlushInstructionCache, GetCurrentProcess, CloseHandle, WaitForSingleObject, VerifyVersionInfoA, VerSetConditionMask, Sleep, GetModuleFileNameA, GetCurrentThreadId, GetModuleHandleA, CreateThread, CreateEventA, IsDBCSLeadByte, InterlockedIncrement, InterlockedDecrement, LocalFree, SetEvent, LocalAlloc, FormatMessageA, SetLastError, FreeLibrary, LoadLibraryExA, GetCommandLineA, CreateFileA, SetProcessShutdownParameters, lstrcmpA, WritePrivateProfileStringA, GetPrivateProfileStringA, GetPrivateProfileIntA, OutputDebugStringA, lstrcpyA, DeleteFileA, ReadFile, WriteFile, GetSystemDirectoryA, GetCurrentProcessId, GetVersionExA, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, GetProcAddress, LoadLibraryA, VirtualFree, VirtualAlloc, InterlockedCompareExchange, GetStartupInfoA, RtlUnwind, SetUnhandledExceptionFilter, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter
> USER32.dll: LoadCursorA, GetClassInfoExA, IsWindow, PostThreadMessageA, SetWindowLongA, CharNextA, CharUpperA, wsprintfA, DestroyWindow, GetMessageA, UnregisterClassA, UnregisterDeviceNotification, DefWindowProcA, RegisterClassExA, GetWindowLongA, SetParent, SendNotifyMessageA, PostQuitMessage, DispatchMessageA, TranslateMessage, RegisterDeviceNotificationA, CreateWindowExA, CallWindowProcA, MessageBoxA, PostMessageA
> MFC42.dll: -, -
> msvcrt.dll: __p__fmode, __set_app_type, __1type_info@@UAE@XZ, realloc, _terminate@@YAXXZ, _unlock, __dllonexit, _lock, _onexit, memmove, _controlfp, isleadbyte, _iob, _snprintf, _itoa, wctomb, __badioinfo, __pioinfo, _fileno, _lseeki64, __p__commode, _isatty, atof, malloc, free, _CxxThrowException, calloc, _resetstkoflw, ___V@YAXPAX@Z, _mbsstr, _vscprintf, memset, _purecall, ___U@YAPAXI@Z, _mbsupr, _errno, __CxxFrameHandler, strncmp, atoi, atol, strtoul, _mbscmp, _CIlog10, _adjust_fdiv, __setusermatherr, _amsg_exit, _initterm, _acmdln, exit, _ismbblead, _XcptFilter, _exit, _cexit, __getmainargs, _write, memcpy, sprintf, _strdate, _strtime, strncpy, fopen, fputs, fflush, fclose
> SETUPAPI.dll: SetupDiGetClassDevsA, SetupDiGetDeviceInterfaceDetailA, SetupDiDestroyDeviceInfoList, SetupDiEnumDeviceInterfaces
> SHELL32.dll: SHGetFolderPathA, SHCreateDirectoryExA
> ole32.dll: PropVariantClear, CoFreeUnusedLibraries, StringFromGUID2, CoUninitialize, CoInitialize, CoCreateInstance, CoTaskMemFree, CoRegisterClassObject, CoRevokeClassObject, CoTaskMemRealloc, CoTaskMemAlloc
> OLEAUT32.dll: -, -, -, -, -, -, -
> SHLWAPI.dll: PathFileExistsA
> WINMM.dll: mixerGetDevCapsA, mixerSetControlDetails, mixerGetControlDetailsA, mixerGetNumDevs, mixerOpen, mixerClose, mixerGetLineInfoA, mixerGetLineControlsA
> ctosuser.dll: -, -, -
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
sigcheck:
publisher....: Creative Technology Ltd
copyright....: Copyright(c) 1999-2007 Creative Technology Ltd. All rights reserved.
product......: Creative Audio Product
description..: SPI (Creative X-Fi Module)
original name: CTXFISpi.exe
internal name: CTXFISpi.exe
file version.: 6.00.01.1373
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
trid..: Windows Screen Saver (51.1%)
Win32 Executable Generic (33.2%)
Generic Win/DOS Executable (7.8%)
DOS Executable Generic (7.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
C:\Windows\SysWOW64\Ctxfihlp.exe
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.03.07 -
AhnLab-V3 5.0.0.2 2010.03.07 -
AntiVir 8.2.1.180 2010.03.05 -
Antiy-AVL 2.0.3.7 2010.03.05 -
Authentium 5.2.0.5 2010.03.06 -
Avast 4.8.1351.0 2010.03.07 -
Avast5 5.0.332.0 2010.03.07 -
AVG 9.0.0.787 2010.03.07 -
BitDefender 7.2 2010.03.07 -
CAT-QuickHeal 10.00 2010.03.06 -
ClamAV 0.96.0.0-git 2010.03.06 -
Comodo 4091 2010.02.28 -
DrWeb 5.0.1.12222 2010.03.07 -
eSafe 7.0.17.0 2010.03.04 -
eTrust-Vet 35.2.7342 2010.03.05 -
F-Prot 4.5.1.85 2010.03.06 -
F-Secure 9.0.15370.0 2010.03.07 -
Fortinet 4.0.14.0 2010.03.07 -
GData 19 2010.03.07 -
Ikarus T3.1.1.80.0 2010.03.07 -
Jiangmin 13.0.900 2010.03.07 -
K7AntiVirus 7.10.990 2010.03.04 -
Kaspersky 7.0.0.125 2010.03.07 -
McAfee 5912 2010.03.06 -
McAfee+Artemis 5912 2010.03.06 -
McAfee-GW-Edition 6.8.5 2010.03.07 -
Microsoft 1.5502 2010.03.07 -
NOD32 4922 2010.03.07 -
Norman 6.04.08 2010.03.07 -
nProtect 2009.1.8.0 2010.03.07 -
Panda 10.0.2.2 2010.03.07 -
PCTools 7.0.3.5 2010.03.04 -
Prevx 3.0 2010.03.09 -
Rising 22.37.06.04 2010.03.07 -
Sophos 4.51.0 2010.03.07 -
Sunbelt 5780 2010.03.07 -
Symantec 20091.2.0.41 2010.03.07 -
TheHacker 6.5.1.9.223 2010.03.07 -
TrendMicro 9.120.0.1004 2010.03.07 -
VBA32 3.12.12.2 2010.03.05 -
ViRobot 2010.3.5.2214 2010.03.05 -
VirusBuster 5.0.27.0 2010.03.06 -
Rozšiřující informace
File size: 25600 bytes
MD5...: 73e6594a8fb258051369c28147437301
SHA1..: fb215d433441dbb4cf9c41c08ac2ef9418775ce2
SHA256: a64ce9502abf5a6725449cbd67ee8ac3a120279b238427176da377318016320b
ssdeep: 384:32Uj//JielFeN3F+hWQm6NmhXlbjC50I9e3t2ChGf64wwToCVBoCekoL2shW
ohGx:37jcOFe9FjNk2CIKf64H1oCy1QQGYhW
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x47ca
timedatestamp.....: 0x4a26aaf3 (Wed Jun 03 16:55:15 2009)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x4ed2 0x5000 6.47 b2d728eb06bb7ef01a600a1a24ceda70
.data 0x6000 0x884 0x600 5.19 1343fb41bb4815e25791d64151fadb75
.rsrc 0x7000 0x9d8 0xa00 3.38 569a2ff1e647670208589b585da5c112
( 8 imports )
> ADVAPI32.dll: RegSetValueExA, RegCreateKeyExA, RegEnumValueA, RegOpenKeyA, RegCloseKey
> KERNEL32.dll: GetLastError, CreateSemaphoreA, CloseHandle, FreeLibrary, GetProcAddress, LoadLibraryA, GetModuleHandleA, Sleep, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, SetUnhandledExceptionFilter, InterlockedCompareExchange, GetStartupInfoA, RtlUnwind, InterlockedExchange
> USER32.dll: EnableWindow, UnregisterDeviceNotification, RegisterDeviceNotificationA, LoadIconA, GetClientRect, IsIconic, PostMessageA, SendMessageA, DrawIcon, GetSystemMetrics
> MFC42.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> msvcrt.dll: _unlock, __dllonexit, _lock, _onexit, _terminate@@YAXXZ, _controlfp, __1type_info@@UAE@XZ, _itoa, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _amsg_exit, _initterm, _acmdln, exit, _ismbblead, _XcptFilter, _exit, _cexit, __getmainargs, ___U@YAPAXI@Z, sprintf, ___V@YAXPAX@Z, malloc, free, memset, __CxxFrameHandler, _setmbcp
> ole32.dll: CoInitializeSecurity, CoCreateInstance, CoUninitialize, CoInitialize
> OLEAUT32.dll: -, -, -, -, -, -, -, -
> SETUPAPI.dll: SetupDiEnumDeviceInterfaces, SetupDiDestroyDeviceInfoList, SetupDiGetDeviceInterfaceDetailA, SetupDiGetClassDevsA, SetupDiOpenDeviceInterfaceA, SetupDiGetDeviceRegistryPropertyA
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
sigcheck:
publisher....: Creative Technology Ltd
copyright....: Copyright (C) 2004-2007
product......: CTXfiHlp Application
description..: CTXfiHlp MFC Application
original name: CTXfiHlp.exe
internal name: CTXfiHlp
file version.: 6.00.01.1373-2.18.4580
comments.....: DriverHelper Module Loader
signers......: -
signing date.: -
verified.....: Unsigned
trid..: Win32 Executable MS Visual C++ (generic) (75.0%)
Win32 Executable Generic (16.9%)
Generic Win/DOS Executable (3.9%)
DOS Executable Generic (3.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
C:\Program Files (x86)\Zynga\tbZyng.dll
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.03.07 -
AhnLab-V3 5.0.0.2 2010.03.07 -
AntiVir 8.2.1.180 2010.03.05 -
Antiy-AVL 2.0.3.7 2010.03.05 -
Authentium 5.2.0.5 2010.03.06 -
Avast 4.8.1351.0 2010.03.07 -
Avast5 5.0.332.0 2010.03.07 -
AVG 9.0.0.787 2010.03.07 -
BitDefender 7.2 2010.03.07 -
CAT-QuickHeal 10.00 2010.03.06 -
ClamAV 0.96.0.0-git 2010.03.06 -
Comodo 4091 2010.02.28 -
DrWeb 5.0.1.12222 2010.03.07 -
eSafe 7.0.17.0 2010.03.04 -
eTrust-Vet 35.2.7342 2010.03.05 -
F-Prot 4.5.1.85 2010.03.06 -
F-Secure 9.0.15370.0 2010.03.07 -
Fortinet 4.0.14.0 2010.03.07 -
GData 19 2010.03.07 -
Ikarus T3.1.1.80.0 2010.03.07 -
Jiangmin 13.0.900 2010.03.07 -
K7AntiVirus 7.10.990 2010.03.04 -
Kaspersky 7.0.0.125 2010.03.07 -
McAfee 5912 2010.03.06 -
McAfee+Artemis 5912 2010.03.06 -
McAfee-GW-Edition 6.8.5 2010.03.07 -
Microsoft 1.5502 2010.03.07 -
NOD32 4922 2010.03.07 -
Norman 6.04.08 2010.03.07 -
nProtect 2009.1.8.0 2010.03.07 -
Panda 10.0.2.2 2010.03.07 -
PCTools 7.0.3.5 2010.03.04 -
Prevx 3.0 2010.03.09 -
Rising 22.37.06.04 2010.03.07 -
Sophos 4.51.0 2010.03.07 -
Sunbelt 5780 2010.03.07 -
Symantec 20091.2.0.41 2010.03.07 -
TheHacker 6.5.1.9.223 2010.03.07 -
TrendMicro 9.120.0.1004 2010.03.07 -
VBA32 3.12.12.2 2010.03.05 -
ViRobot 2010.3.5.2214 2010.03.05 -
VirusBuster 5.0.27.0 2010.03.06 -
Rozšiřující informace
File size: 2353176 bytes
MD5...: 1fecf655218fdf7329bea67f519c8642
SHA1..: 4fcc97779d94929758888a954e0806ce5f71afbd
SHA256: 0a008ab53e38a5bd5a5947e380e503480cebb686ce957f6f06ecbdb4df8524d9
ssdeep: 49152:OXbKYvZowp1yeVGOPgKcvNoqTrsRa32R952mxiZRkvzVQv21YXtFCYQ:OX
e90gOoFTrsU32R3/p
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x117cb0
timedatestamp.....: 0x4b8256cb (Mon Feb 22 10:04:59 2010)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x147f01 0x148000 6.60 a302ceb764a12a16795967eca7fe1442
.rdata 0x149000 0x74d67 0x74e00 4.53 6a2109ecbbd12d716c4e810e4e864169
.data 0x1be000 0x8584 0x6400 4.96 a63d07e68b55f8fb3ee16e1e1ebe6af2
.rsrc 0x1c7000 0x5d258 0x5d400 5.97 90ef0b48ac317eff2680b78e64f5e639
.reloc 0x225000 0x1d04c 0x1d200 5.94 db0c92aa8a1253bc3059acb788243b2d
( 20 imports )
> COMCTL32.dll: ImageList_Create, InitCommonControlsEx, CreateToolbarEx, PropertySheetW, CreatePropertySheetPageW, ImageList_ReplaceIcon, _TrackMouseEvent, -
> WININET.dll: DeleteUrlCacheEntry, FindNextUrlCacheEntryA, FindFirstUrlCacheEntryA, InternetCanonicalizeUrlW, InternetCrackUrlW, InternetCloseHandle, InternetSetOptionA, HttpOpenRequestA, FindCloseUrlCache, InternetConnectA, InternetGetLastResponseInfoA, HttpSendRequestA, HttpQueryInfoA, InternetOpenA, InternetCrackUrlA, InternetOpenW, InternetSetOptionW, InternetOpenUrlW, InternetReadFile, InternetSetOptionExA, InternetQueryOptionA, GetUrlCacheEntryInfoW, InternetCanonicalizeUrlA, InternetGetConnectedState
> SHLWAPI.dll: SHDeleteKeyA, PathFileExistsW
> WSOCK32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -
> VERSION.dll: GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
> MSIMG32.dll: GradientFill
> RPCRT4.dll: UuidToStringW
> urlmon.dll: ObtainUserAgentString, URLDownloadToFileW
> CRYPT32.dll: CryptProtectData, CryptUnprotectData, CryptQueryObject, CryptMsgGetParam, CertFindCertificateInStore, CertGetNameStringA, CertGetNameStringW, CertFreeCertificateContext, CertCloseStore, CryptMsgClose
> WINMM.dll: sndPlaySoundW, PlaySoundW, PlaySoundA, timeGetTime
> KERNEL32.dll: OutputDebugStringW, GetTickCount, GetModuleHandleW, GetShortPathNameW, GetLongPathNameW, LocalFree, GetCurrentThreadId, GetCurrentProcessId, CloseHandle, ReleaseMutex, InterlockedDecrement, SetEndOfFile, CreateFileA, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetLocaleInfoA, InterlockedExchange, InitializeCriticalSectionAndSpinCount, SetFilePointer, FlushFileBuffers, GetConsoleMode, GetConsoleCP, LCMapStringA, GetStringTypeW, GetStringTypeA, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, GetFileType, SetHandleCount, HeapSize, LCMapStringW, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, GetStdHandle, WriteFile, ExitProcess, VirtualAlloc, VirtualFree, HeapDestroy, HeapCreate, InterlockedIncrement, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, MoveFileW, GetCommandLineA, ResumeThread, ExitThread, RaiseException, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, HeapReAlloc, HeapAlloc, RtlUnwind, GetProcessHeap, HeapFree, MapViewOfFile, UnmapViewOfFile, OpenFileMappingW, CreateFileMappingW, ReleaseSemaphore, CreateSemaphoreW, SetEvent, GetCurrentThread, SetThreadPriority, TerminateProcess, CreateToolhelp32Snapshot, Thread32First, Thread32Next, OpenProcess, LocalAlloc, lstrcpyA, GetComputerNameW, GetSystemTimeAsFileTime, RemoveDirectoryW, GetFileTime, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, SizeofResource, CreateFileW, GetFileSize, GlobalAlloc, GlobalLock, ReadFile, MulDiv, LoadLibraryA, GlobalUnlock, GlobalFree, GetLastError, GetProcAddress, GetModuleHandleA, GetModuleFileNameW, WaitForSingleObject, CreateEventW, lstrlenW, MoveFileExW, GetModuleFileNameA, WideCharToMultiByte, FreeLibrary, LoadLibraryW, lstrcpyW, CopyFileW, FindClose, FindNextFileW, DeleteFileW, FindFirstFileW, CreateThread, SetLastError, OpenMutexW, GetCurrentProcess, FlushInstructionCache, VirtualProtect, Sleep, ExpandEnvironmentStringsW, CreateProcessW, GetLocaleInfoW, CreateMutexW, Beep, MultiByteToWideChar, GetLocalTime, GetDateFormatW, GetTimeFormatW, FindResourceW, LoadResource, LockResource, FreeResource, GetFileAttributesW, GetVersionExA
> USER32.dll: SetCursor, GetWindowLongW, GetParent, SetDlgItemTextW, ClientToScreen, SetWindowTextA, SetWindowTextW, GetClientRect, GetDlgCtrlID, CallWindowProcA, InvalidateRect, IsWindow, GetWindowRgn, MessageBeep, LoadCursorA, SendMessageA, wsprintfW, PostMessageA, ShowWindow, SetWindowLongW, ReleaseDC, GetWindow, UpdateWindow, GetClassInfoExW, RegisterClassExW, CopyRect, InflateRect, DrawFocusRect, CharUpperW, SetRect, GetLastInputInfo, IsIconic, LoadImageW, SystemParametersInfoW, MoveWindow, DrawTextW, GetDC, GetWindowRect, RegisterWindowMessageW, GetActiveWindow, IsDialogMessageA, IsDialogMessageW, MessageBoxA, DialogBoxParamW, DialogBoxParamA, CreateDialogParamA, CreateDialogParamW, SetRectEmpty, GetKeyState, SetDlgItemInt, GetDlgItemTextA, FrameRect, DrawFrameControl, AllowSetForegroundWindow, CharLowerBuffA, DrawEdge, MsgWaitForMultipleObjects, PostThreadMessageA, SetParent, GetDlgItemTextW, GetScrollInfo, GetMenuItemRect, InsertMenuItemA, InsertMenuItemW, IsMenu, GetMenuInfo, SetMenuInfo, GetMenuItemID, GetMenuState, SetMenuItemInfoW, CheckMenuItem, EnableMenuItem, DeleteMenu, TrackPopupMenu, PostMessageW, GetMonitorInfoW, GetMenuItemCount, GetMenuItemInfoW, CreatePopupMenu, DestroyMenu, SetClassLongA, SetLayeredWindowAttributes, SetForegroundWindow, EnableWindow, IsDlgButtonChecked, CheckDlgButton, SetActiveWindow, TranslateMessage, GetMessageA, ReleaseCapture, GetCapture, DispatchMessageW, DispatchMessageA, SetCapture, GetUpdateRect, BeginPaint, EndPaint, SetWindowRgn, GetDlgItem, OffsetRect, DrawIconEx, GetIconInfo, DestroyIcon, GetSystemMetrics, FillRect, GetSysColor, PeekMessageA, MessageBoxW, DefWindowProcW, GetAsyncKeyState, SendMessageW, GetWindowTextLengthW, EndDialog, GetWindowTextW, FindWindowW, GetMenuItemInfoA, SetWindowsHookExA, UnhookWindowsHookEx, CallNextHookEx, CreateWindowExW, UnregisterClassA, GetClassNameW, DefWindowProcA, GetWindowLongA, SetWindowLongA, GetFocus, IsChild, KillTimer, IsWindowUnicode, CallWindowProcW, FindWindowExW, GetWindowThreadProcessId, SetWindowPos, MonitorFromRect, GetMonitorInfoA, GetClassInfoW, RegisterClassW, DestroyWindow, SetTimer, GetDesktopWindow, SetFocus, GetCursorPos, ScreenToClient, PtInRect, IsWindowVisible
> GDI32.dll: GetDeviceCaps, RealizePalette, SelectPalette, PlgBlt, SetLayout, PtInRegion, GetTextColor, GetBkColor, GetBkMode, ExcludeClipRect, SetRectRgn, OffsetRgn, FrameRgn, SetTextAlign, TextOutW, RoundRect, CombineRgn, GetPixel, CreateCompatibleBitmap, BitBlt, CreateRectRgn, Polygon, GdiFlush, SetPixel, GetObjectA, GetTextAlign, GetTextExtentPoint32W, GetLayout, Rectangle, SetBkColor, CreateCompatibleDC, DeleteDC, CreateSolidBrush, CreateFontIndirectW, CreatePen, SelectObject, MoveToEx, LineTo, DeleteObject, GetWindowOrgEx, SetWindowOrgEx, SetBkMode, SetTextColor, GetStockObject
> COMDLG32.dll: GetOpenFileNameW
> ADVAPI32.dll: OpenProcessToken, RegCreateKeyExA, RegSetValueExA, RegCreateKeyExW, RegSetValueExW, RegDeleteKeyW, CryptCreateHash, CryptHashData, CryptGetHashParam, CryptDestroyHash, CryptAcquireContextA, CryptReleaseContext, RegEnumValueW, RegEnumKeyExW, RegDeleteValueW, RegOpenKeyW, RegEnumKeyW, RegCreateKeyW, RegQueryInfoKeyW, RegOpenKeyExW, RegQueryValueExW, RegOpenKeyExA, GetTokenInformation, GetSidSubAuthorityCount, GetSidSubAuthority, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl, SetSecurityDescriptorSacl, RegCloseKey, RegDeleteKeyA
> SHELL32.dll: SHCreateDirectoryExW, ShellExecuteW, ShellExecuteExW, SHGetFolderPathW
> ole32.dll: IIDFromString, CoCreateInstance, CoCreateGuid, StringFromGUID2, CLSIDFromString, CoUninitialize, CoInitialize, CreateStreamOnHGlobal, CoGetMalloc, StringFromIID
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> PSAPI.DLL: EnumProcessModules, GetModuleFileNameExW, EnumProcesses, GetModuleBaseNameW, GetProcessMemoryInfo
> DNSAPI.dll: DnsQuery_A
( 14 exports )
DllCanUnloadNow, DllConnectToIE, DllConnectionProc, DllGetClassObject, DllGetInstallFileNameExt, DllOnUninstall, DllOnUpdateFinish, DllOpenUninstallPage, DllRegisterServer, DllShowTB, DllShowToolbar, DllShowToolbarWithIE, DllUnregisterServer, DllUpdate
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Windows OCX File (71.0%)
Win32 Executable MS Visual C++ (generic) (21.6%)
Win32 Executable Generic (4.9%)
Generic Win/DOS Executable (1.1%)
DOS Executable Generic (1.1%)
sigcheck:
publisher....: Conduit Ltd.
copyright....: Copyright (c) Conduit Ltd. 2008
product......: Conduit Toolbar
description..: Conduit Toolbar
original name: n/a
internal name: Conduit Toolbar
file version.: 5, 3, 5, 4
comments.....: Conduit Toolbar ver 1.0
signers......: Conduit Ltd.
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 8:24 AM 3/9/2010
verified.....: -
C:\Windows\system32\SrchSTS.exe
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.03.09 -
AhnLab-V3 5.0.0.2 2010.03.08 -
AntiVir 8.2.1.180 2010.03.08 -
Antiy-AVL 2.0.3.7 2010.03.09 -
Authentium 5.2.0.5 2010.03.09 -
Avast 4.8.1351.0 2010.03.07 -
Avast5 5.0.332.0 2010.03.07 -
AVG 9.0.0.787 2010.03.08 -
BitDefender 7.2 2010.03.09 -
CAT-QuickHeal 10.00 2010.03.08 -
ClamAV 0.96.0.0-git 2010.03.09 -
Comodo 4091 2010.02.28 -
DrWeb 5.0.1.12222 2010.03.09 -
eSafe 7.0.17.0 2010.03.08 -
eTrust-Vet 35.2.7348 2010.03.09 -
F-Prot 4.5.1.85 2010.03.08 -
F-Secure 9.0.15370.0 2010.03.09 -
Fortinet 4.0.14.0 2010.03.07 -
GData 19 2010.03.09 -
Ikarus T3.1.1.80.0 2010.03.09 -
Jiangmin 13.0.900 2010.03.09 -
K7AntiVirus 7.10.992 2010.03.08 -
Kaspersky 7.0.0.125 2010.03.09 -
McAfee 5914 2010.03.08 -
McAfee+Artemis 5914 2010.03.08 -
McAfee-GW-Edition 6.8.5 2010.03.09 -
Microsoft 1.5502 2010.03.09 -
NOD32 4927 2010.03.09 -
Norman 6.04.08 2010.03.08 -
nProtect 2009.1.8.0 2010.03.08 -
Panda 10.0.2.2 2010.03.08 -
PCTools 7.0.3.5 2010.03.09 -
Prevx 3.0 2010.03.09 -
Rising 22.38.01.03 2010.03.09 -
Sophos 4.51.0 2010.03.09 -
Sunbelt 5797 2010.03.09 -
Symantec 20091.2.0.41 2010.03.09 -
TheHacker 6.5.2.0.226 2010.03.09 -
TrendMicro 9.120.0.1004 2010.03.09 -
VBA32 3.12.12.2 2010.03.05 -
ViRobot 2010.3.9.2217 2010.03.09 -
VirusBuster 5.0.27.0 2010.03.08 -
Rozšiřující informace
File size: 288417 bytes
MD5...: fc041f7d1341eee456f1fa1a256cd24f
SHA1..: 79bf4b742b8decaa516c2a29145facb83796f1d6
SHA256: 562c5f4a7674c9eeeda4b8e99324b3f78a266e7f42048b5a27b8f917af8a3dba
ssdeep: 6144:07mdwRp3eo8I1ZtLvqFf1DAWgIdssH2o6Pr1fvIKEdTzuhOChC38usHfJY6
En6Ty:JJeZtr4RAW25cEiP/3IWVJ/ux7cmih
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4c5d0
timedatestamp.....: 0x4450e808 (Thu Apr 27 15:49:28 2006)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x39000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x3a000 0x13000 0x12800 7.90 8026838d191497773df997895b2dd5b3
.rsrc 0x4d000 0x1000 0x400 3.27 99e1dc84aa59b5cff80611d9b1f98563
( 3 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> ADVAPI32.DLL: RegCloseKey
> msvcrt.dll: _iob
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
sigcheck:
publisher....: S_Ri
copyright....:
product......: SrchSTS
description..: Search SharedTaskScheduler
original name:
internal name:
file version.:
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
packers (Kaspersky): UPX
C:\Windows\system32\Process.exe
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.03.07 -
AhnLab-V3 5.0.0.2 2010.03.07 -
AntiVir 8.2.1.180 2010.03.05 -
Antiy-AVL 2.0.3.7 2010.03.05 -
Authentium 5.2.0.5 2010.03.06 -
Avast 4.8.1351.0 2010.03.07 -
Avast5 5.0.332.0 2010.03.07 -
AVG 9.0.0.787 2010.03.07 -
BitDefender 7.2 2010.03.07 -
CAT-QuickHeal 10.00 2010.03.06 -
ClamAV 0.96.0.0-git 2010.03.06 -
Comodo 4091 2010.02.28 -
DrWeb 5.0.1.12222 2010.03.07 Tool.Prockill
eSafe 7.0.17.0 2010.03.04 -
eTrust-Vet 35.2.7342 2010.03.05 -
F-Prot 4.5.1.85 2010.03.06 -
F-Secure 9.0.15370.0 2010.03.07 -
Fortinet 4.0.14.0 2010.03.07 -
GData 19 2010.03.07 -
Ikarus T3.1.1.80.0 2010.03.07 -
Jiangmin 13.0.900 2010.03.07 -
K7AntiVirus 7.10.990 2010.03.04 -
Kaspersky 7.0.0.125 2010.03.07 -
McAfee 5912 2010.03.06 potentially unwanted program PrcViewer
McAfee+Artemis 5912 2010.03.06 potentially unwanted program PrcViewer
McAfee-GW-Edition 6.8.5 2010.03.07 Heuristic.BehavesLike.Win32.Dropper.L
Microsoft 1.5502 2010.03.07 -
NOD32 4922 2010.03.07 Win32/PrcView
Norman 6.04.08 2010.03.07 -
nProtect 2009.1.8.0 2010.03.07 -
Panda 10.0.2.2 2010.03.07 -
PCTools 7.0.3.5 2010.03.04 -
Prevx 3.0 2010.03.09 -
Rising 22.37.06.04 2010.03.07 -
Sophos 4.51.0 2010.03.07 -
Sunbelt 5780 2010.03.07 -
Symantec 20091.2.0.41 2010.03.07 -
TheHacker 6.5.1.9.223 2010.03.07 Aplicacion/Processor.20
TrendMicro 9.120.0.1004 2010.03.07 -
VBA32 3.12.12.2 2010.03.05 -
ViRobot 2010.3.5.2214 2010.03.05 -
VirusBuster 5.0.27.0 2010.03.06 Trojan.PrcView.B
Rozšiřující informace
File size: 53248 bytes
MD5...: 7397f6ee4a9601a123b645c0cd428017
SHA1..: 890368473ecbc404dcd42ff0c6c38397102f59c0
SHA256: 5aaf73ef89f0efab963abb170bc9b7cd7d4d5bd7a691cd83137b4cc39cd120de
ssdeep: 768:ORWMA68kDGXcK1JP9COApZsLUFDeLHAwu0aB0wWYS/a/x9GYDM0+0O:OkMKH
9fApDFPgiKMM0I
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x2b42
timedatestamp.....: 0x3edf2cf1 (Thu Jun 05 11:43:45 2003)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x7bea 0x8000 6.52 c01fadec01aae81015745dad0ecda107
.rdata 0x9000 0x1dfc 0x2000 5.10 e5217bccc8786d801b7a78bb7cce029c
.data 0xb000 0x1fc8 0x1000 2.67 5ba738a705a45c4209cbffe7469d458a
.rsrc 0xd000 0x3c0 0x1000 0.99 0967ff97890b79a40016a44e82666655
( 3 imports )
> KERNEL32.dll: GetLastError, GetProcessAffinityMask, OpenProcess, Sleep, TerminateProcess, WaitForSingleObject, SetPriorityClass, lstrcmpiA, HeapFree, ResumeThread, SuspendThread, GetVersionExA, WideCharToMultiByte, HeapAlloc, CloseHandle, GlobalFree, GlobalAlloc, FileTimeToSystemTime, SystemTimeToFileTime, GetSystemTime, LocalFree, FormatMessageA, HeapSize, RtlUnwind, LCMapStringW, LCMapStringA, VirtualQuery, GetSystemInfo, SetProcessAffinityMask, LoadLibraryA, GetProcAddress, FreeLibrary, GetProcessHeap, GetCurrentProcess, ExitProcess, GetModuleHandleA, GetCommandLineA, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, GetModuleFileNameA, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, WriteFile, GetStdHandle, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, GetStartupInfoA, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, GetACP, GetOEMCP, GetCPInfo, FlushFileBuffers, SetFilePointer, GetLocaleInfoA, VirtualProtect, SetStdHandle
> USER32.dll: CloseDesktop, EnumDesktopWindows, GetWindowThreadProcessId, PostMessageA, OpenDesktopA
> ADVAPI32.dll: LookupAccountSidA, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges, GetTokenInformation
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
sigcheck:
publisher....:
http://www.beyondlogic.org
copyright....: Copyright 2003
Craig.Peacock@beyondlogic.org
product......: Command Line Process Utility
description..: Command Line Process Utility
original name: Process.exe
internal name: Process.exe
file version.: 2, 0, 0, 0
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
C:\Windows\system32\o4Patch.exe
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.03.09 -
AhnLab-V3 5.0.0.2 2010.03.08 -
AntiVir 8.2.1.180 2010.03.08 -
Antiy-AVL 2.0.3.7 2010.03.09 -
Authentium 5.2.0.5 2010.03.09 -
Avast 4.8.1351.0 2010.03.07 -
Avast5 5.0.332.0 2010.03.07 -
AVG 9.0.0.787 2010.03.08 -
BitDefender 7.2 2010.03.09 -
CAT-QuickHeal 10.00 2010.03.08 -
ClamAV 0.96.0.0-git 2010.03.09 -
Comodo 4091 2010.02.28 -
DrWeb 5.0.1.12222 2010.03.09 -
eSafe 7.0.17.0 2010.03.08 Win32.Banker
eTrust-Vet 35.2.7348 2010.03.09 -
F-Prot 4.5.1.85 2010.03.08 -
F-Secure 9.0.15370.0 2010.03.09 -
Fortinet 4.0.14.0 2010.03.07 -
GData 19 2010.03.09 -
Ikarus T3.1.1.80.0 2010.03.09 -
Jiangmin 13.0.900 2010.03.09 -
K7AntiVirus 7.10.992 2010.03.08 -
Kaspersky 7.0.0.125 2010.03.09 -
McAfee 5914 2010.03.08 -
McAfee+Artemis 5914 2010.03.08 -
McAfee-GW-Edition 6.8.5 2010.03.09 -
Microsoft 1.5502 2010.03.09 -
NOD32 4927 2010.03.09 -
Norman 6.04.08 2010.03.08 -
nProtect 2009.1.8.0 2010.03.08 -
Panda 10.0.2.2 2010.03.08 -
PCTools 7.0.3.5 2010.03.09 -
Prevx 3.0 2010.03.09 -
Rising 22.38.01.03 2010.03.09 -
Sophos 4.51.0 2010.03.09 -
Sunbelt 5797 2010.03.09 -
Symantec 20091.2.0.41 2010.03.09 -
TheHacker 6.5.2.0.226 2010.03.09 -
TrendMicro 9.120.0.1004 2010.03.09 -
VBA32 3.12.12.2 2010.03.05 -
ViRobot 2010.3.9.2217 2010.03.09 -
VirusBuster 5.0.27.0 2010.03.08 -
Rozšiřující informace
File size: 80384 bytes
MD5...: cebef7e3612a75d15c73e8ca71d012ae
SHA1..: 2dc82528d99da40a976c8ae3101144a77305baa3
SHA256: bbd52071facb6fb9e6c9376070fb1881457eeeefcda41e9482ce1add4ad4ef04
ssdeep: 1536:MNIgZ5LgQNvea0hWl/ZBViMvW/JfGKkJUatKdY9rkbJmOz:Jg7LN0huZBVt
6fCKdYp2mOz
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4d100
timedatestamp.....: 0x48d4d443 (Sat Sep 20 10:45:23 2008)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x39000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x3a000 0x14000 0x13400 7.91 d0ebb260afc4c5afc6c783a12b2a6072
.rsrc 0x4e000 0x1000 0x400 3.56 f73d0c5ec087eb5260ffe2508cd7aeb3
( 3 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> ADVAPI32.DLL: RegCloseKey
> msvcrt.dll: _iob
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
sigcheck:
publisher....: S_Ri.URZ
copyright....:
product......: o4Patch
description..: o4Patch
original name: o4Patch.exe
internal name: o4Patch
file version.:
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
packers (Kaspersky): PE_Patch.UPX, UPX
C:\Windows\system32\IEDFix.C.exe
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.03.07 -
AhnLab-V3 5.0.0.2 2010.03.07 -
AntiVir 8.2.1.180 2010.03.05 -
Antiy-AVL 2.0.3.7 2010.03.05 -
Authentium 5.2.0.5 2010.03.06 -
Avast 4.8.1351.0 2010.03.07 -
Avast5 5.0.332.0 2010.03.07 -
AVG 9.0.0.787 2010.03.07 -
BitDefender 7.2 2010.03.07 -
CAT-QuickHeal 10.00 2010.03.06 -
ClamAV 0.96.0.0-git 2010.03.06 -
Comodo 4091 2010.02.28 -
DrWeb 5.0.1.12222 2010.03.07 -
eSafe 7.0.17.0 2010.03.04 Win32.Banker
eTrust-Vet 35.2.7342 2010.03.05 -
F-Prot 4.5.1.85 2010.03.06 -
F-Secure 9.0.15370.0 2010.03.07 -
Fortinet 4.0.14.0 2010.03.07 -
GData 19 2010.03.07 -
Ikarus T3.1.1.80.0 2010.03.07 -
Jiangmin 13.0.900 2010.03.07 -
K7AntiVirus 7.10.990 2010.03.04 -
Kaspersky 7.0.0.125 2010.03.07 -
McAfee 5912 2010.03.06 -
McAfee+Artemis 5912 2010.03.06 -
McAfee-GW-Edition 6.8.5 2010.03.07 -
Microsoft 1.5502 2010.03.07 -
NOD32 4922 2010.03.07 -
Norman 6.04.08 2010.03.07 -
nProtect 2009.1.8.0 2010.03.07 -
Panda 10.0.2.2 2010.03.07 Application/IEDefender
PCTools 7.0.3.5 2010.03.04 -
Prevx 3.0 2010.03.09 -
Rising 22.37.06.04 2010.03.07 -
Sophos 4.51.0 2010.03.07 -
Sunbelt 5780 2010.03.07 -
Symantec 20091.2.0.41 2010.03.07 -
TheHacker 6.5.1.9.223 2010.03.07 -
TrendMicro 9.120.0.1004 2010.03.07 -
VBA32 3.12.12.2 2010.03.05 -
ViRobot 2010.3.5.2214 2010.03.05 -
VirusBuster 5.0.27.0 2010.03.06 -
Rozšiřující informace
File size: 82944 bytes
MD5...: 9769ab38cb77c9914c25b8141a2a3fbe
SHA1..: ca02a39e467582d40af16003dae1b64db038e79a
SHA256: 7237b3e0c9a5560d505e0aa8ae558f35b70bc34be08dfb17ff97480b3951622c
ssdeep: 1536:x2XbU/gOHJi72/3X3nYyj7vwAVVMbWY3pcyZYoP/Vg2TstwSY6USkaYY:x2
ISE3nD7vwuSWY3pHpG24twSY6U5aYY
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x509a0
timedatestamp.....: 0x493174ad (Sat Nov 29 16:58:21 2008)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x3c000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x3d000 0x14000 0x13c00 7.91 960bb7b2696ff501065477f9e56fbcc7
.rsrc 0x51000 0x1000 0x600 2.79 105d3eb19d82424dd0d20d0966609973
( 4 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> ADVAPI32.DLL: RegCloseKey
> msvcrt.dll: _iob
> SHELL32.DLL: ShellExecuteA
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
sigcheck:
publisher....: S_Ri.URZ
copyright....:
product......: IEDFix.C
description..: IEDFix.C
original name: IEDFix.C.exe
internal name: IEDFix.C
file version.:
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX
C:\Windows\system32\Agent.OMZ.Fix.exe
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.03.07 -
AhnLab-V3 5.0.0.2 2010.03.07 -
AntiVir 8.2.1.180 2010.03.05 -
Antiy-AVL 2.0.3.7 2010.03.05 -
Authentium 5.2.0.5 2010.03.06 -
Avast 4.8.1351.0 2010.03.07 -
Avast5 5.0.332.0 2010.03.07 -
AVG 9.0.0.787 2010.03.07 -
BitDefender 7.2 2010.03.07 -
CAT-QuickHeal 10.00 2010.03.06 -
ClamAV 0.96.0.0-git 2010.03.06 -
Comodo 4091 2010.02.28 -
eSafe 7.0.17.0 2010.03.04 Win32.Banker
eTrust-Vet 35.2.7342 2010.03.05 -
F-Prot 4.5.1.85 2010.03.06 -
F-Secure 9.0.15370.0 2010.03.07 -
Fortinet 4.0.14.0 2010.03.07 -
GData 19 2010.03.07 -
Ikarus T3.1.1.80.0 2010.03.07 -
Jiangmin 13.0.900 2010.03.07 -
K7AntiVirus 7.10.990 2010.03.04 -
Kaspersky 7.0.0.125 2010.03.07 -
McAfee 5912 2010.03.06 -
McAfee+Artemis 5912 2010.03.06 -
McAfee-GW-Edition 6.8.5 2010.03.07 -
Microsoft 1.5502 2010.03.07 -
NOD32 4922 2010.03.07 -
Norman 6.04.08 2010.03.07 -
nProtect 2009.1.8.0 2010.03.07 -
Panda 10.0.2.2 2010.03.07 -
PCTools 7.0.3.5 2010.03.04 -
Prevx 3.0 2010.03.09 -
Rising 22.37.06.04 2010.03.07 -
Sophos 4.51.0 2010.03.07 -
Sunbelt 5780 2010.03.07 -
Symantec 20091.2.0.41 2010.03.07 -
TheHacker 6.5.1.9.223 2010.03.07 -
TrendMicro 9.120.0.1004 2010.03.07 -
VBA32 3.12.12.2 2010.03.05 -
ViRobot 2010.3.5.2214 2010.03.05 -
VirusBuster 5.0.27.0 2010.03.06 -
Rozšiřující informace
File size: 78336 bytes
MD5...: c02562a732f0223082d4ccfc7d4f23df
SHA1..: f02f4a27823772c2ca04c01f5c390887a109d277
SHA256: 4d40d3826750344c4c6080d20f20ad47f694c972923a024edaae998ef23a6ae0
ssdeep: 1536:xtQ1IK3cY2Q/CAZIXKPPumZGkF57RtuIHd7b/pOVVH:xi9l/XPPFJHdIIHd
7FQVH
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4c690
timedatestamp.....: 0x4941a8f7 (Thu Dec 11 23:57:43 2008)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x39000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x3a000 0x13000 0x12a00 7.90 5bf4d8410d3c5848231e58a9108ced2f
.rsrc 0x4d000 0x1000 0x600 2.87 aeb2f4c788c343e5ccc1f080f1f65e5f
( 4 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> ADVAPI32.DLL: RegOpenKeyExA
> msvcrt.dll: _iob
> SHELL32.DLL: ShellExecuteA
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
packers (Kaspersky): PE_Patch.UPX, UPX
sigcheck:
publisher....: S_Ri.URZ
copyright....:
product......: Agent.OMZ.Fix
description..: Agent.OMZ.Fix
original name: Agent.OMZ.Fix.exe
internal name: Agent.OMZ.Fix
file version.:
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
packers (F-Prot): UPX