Re: Prosím o preventivní kontrolu logu
Napsal: 31 led 2010 00:01
Soubor 932B60D780432FF0A0DD1B44B4D83100226610E2.sys přijatý 2010.01.23 07:53:41 (UTC)
Současný stav: Dokončeno
Výsledek: 0/40 (0.00%)
Formátované Formátované
Vytisknout výsledky Vytisknout výsledky
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.01.23 -
AhnLab-V3 5.0.0.2 2010.01.22 -
AntiVir 7.9.1.146 2010.01.22 -
Antiy-AVL 2.0.3.7 2010.01.22 -
Authentium 5.2.0.5 2010.01.23 -
Avast 4.8.1351.0 2010.01.22 -
AVG 9.0.0.730 2010.01.22 -
BitDefender 7.2 2010.01.23 -
CAT-QuickHeal 10.00 2010.01.22 -
ClamAV 0.94.1 2010.01.22 -
Comodo 3677 2010.01.23 -
DrWeb 5.0.1.12222 2010.01.23 -
eSafe 7.0.17.0 2010.01.21 -
eTrust-Vet 35.2.7255 2010.01.22 -
F-Prot 4.5.1.85 2010.01.22 -
F-Secure 9.0.15370.0 2010.01.23 -
Fortinet 4.0.14.0 2010.01.23 -
GData 19 2010.01.23 -
Ikarus T3.1.1.80.0 2010.01.23 -
Jiangmin 13.0.900 2010.01.23 -
K7AntiVirus 7.10.952 2010.01.22 -
Kaspersky 7.0.0.125 2010.01.23 -
McAfee 5869 2010.01.22 -
McAfee+Artemis 5869 2010.01.22 -
McAfee-GW-Edition 6.8.5 2010.01.23 -
Microsoft 1.5405 2010.01.22 -
NOD32 4798 2010.01.22 -
Norman 6.04.03 2010.01.22 -
nProtect 2009.1.8.0 2010.01.22 -
Panda 10.0.2.2 2010.01.22 -
PCTools 7.0.3.5 2010.01.23 -
Rising 22.31.04.04 2010.01.22 -
Sophos 4.50.0 2010.01.23 -
Sunbelt 3.2.1858.2 2010.01.23 -
Symantec 20091.2.0.41 2010.01.23 -
TheHacker 6.5.0.9.160 2010.01.23 -
TrendMicro 9.120.0.1004 2010.01.23 -
VBA32 3.12.12.1 2010.01.21 -
ViRobot 2010.1.22.2151 2010.01.22 -
VirusBuster 5.0.21.0 2010.01.22 -
Rozšiřující informace
File size: 1810560 bytes
MD5 : 31d64f244916bb367c158218d47dfadf
SHA1 : 0d8568512a8538665523a8946d6ec94b19a1b394
SHA256: 78ad72aa93f763f2a85698891f87c99260dd0f3420b7d6ef3dcbb835a869ba8c
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0xD3440
timedatestamp.....: 0x4A532A76 (Tue Jul 7 12:59:02 2009)
machinetype.......: 0x14C (Intel I386)
( 10 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x500 0x9F286 0x9F300 6.57 daa41aae14a949cab15d5f33a025c43f
page 0x9F800 0x33B7C 0x33B80 6.45 3970fed1eb14cd57803f08e359ddf883
init 0xD3380 0x340 0x380 5.64 3ccc79d6f4454285d3d778f0b83e6b87
.rdata 0xD3700 0x1DF14 0x1DF80 5.93 3c75b96f79ace59aa81617d972db4153
.data 0xF1680 0x631E0 0x63200 4.34 515a74918d8fe8833f9b63ca904a54bc
init 0x154880 0x8C 0x100 2.64 b8c68280a60540773b195edf7ffe1357
_PDATA 0x154980 0x54A08 0x54A80 6.51 9cb1e627c2a3290ec3e5b97578456089
INIT 0x1A9400 0x796 0x800 5.37 608fb06c30542444a4e3d81dfa37dda0
.rsrc 0x1A9C00 0x2B8 0x300 3.01 50c957b25cff28412c47621971f94762
.reloc 0x1A9F00 0x10128 0x10180 6.42 251029e53174246fe7c4ad6ee8d41355
( 3 imports )
> hal.dll: KeQueryPerformanceCounter
> ks.sys: KsCreatePin
> ntoskrnl.exe: RtlStringFromGUID, KeReleaseSemaphore, ObfDereferenceObject, KeSetEvent, ObReferenceObjectByHandle, ExEventObjectType, InterlockedIncrement, InterlockedDecrement, _purecall, RtlCompareUnicodeString, RtlCompareMemory, KeInitializeMutex, KeGetCurrentThread, KeWaitForSingleObject, KeReleaseMutex, ZwClose, IofCallDriver, IoBuildDeviceIoControlRequest, KeInitializeEvent, ZwCreateFile, KeResetEvent, InterlockedExchange, KeCancelTimer, KeClearEvent, InterlockedCompareExchange, KeSetTimer, PsTerminateSystemThread, RtlFreeUnicodeString, KeWaitForMultipleObjects, KeSetPriorityThread, PsCreateSystemThread, MmBuildMdlForNonPagedPool, IoAllocateMdl, ExFreePool, IoFreeIrp, IoFreeMdl, MmUnlockPages, MmMapLockedPages, MmProbeAndLockPages, _except_handler3, IoGetDeviceProperty, IofCompleteRequest, IoReleaseCancelSpinLock, IoDeleteDevice, IoDetachDevice, PoCallDriver, PoStartNextPowerIrp, IoAttachDeviceToDeviceStack, IoCreateDevice, IoWMIRegistrationControl, KeQuerySystemTime, _allmul, _aulldiv, MmMapLockedPagesSpecifyCache, KeInitializeTimer, RtlEqualUnicodeString, _vsnwprintf, wcslen, RtlInitUnicodeString, IoGetDeviceInterfaces, swprintf, ZwQueryValueKey, ZwSetValueKey, ZwDeleteValueKey, ZwCreateKey, ZwOpenKey, IoIsWdmVersionAvailable, KeDelayExecutionThread, IoAllocateIrp, ExAllocatePoolWithTag, RtlRaiseException, KeBugCheckEx, sprintf, memmove, strncpy
( 0 exports )
TrID : File type identification
Clipper DOS Executable (33.3%)
Generic Win/DOS Executable (33.0%)
DOS Executable Generic (33.0%)
VXD Driver (0.5%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
ssdeep: 24576:+JHRCU/liAQeXwaE4eYqL/7Lkev6Ho+ZqUgzARQS3wN6XeO+Nuqp:8HRCOlibeXwHnLjLkeCHpgkQWYGeu
PEiD : -
RDS : NSRL Reference Data Set
-
Současný stav: Dokončeno
Výsledek: 0/40 (0.00%)
Formátované Formátované
Vytisknout výsledky Vytisknout výsledky
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.01.23 -
AhnLab-V3 5.0.0.2 2010.01.22 -
AntiVir 7.9.1.146 2010.01.22 -
Antiy-AVL 2.0.3.7 2010.01.22 -
Authentium 5.2.0.5 2010.01.23 -
Avast 4.8.1351.0 2010.01.22 -
AVG 9.0.0.730 2010.01.22 -
BitDefender 7.2 2010.01.23 -
CAT-QuickHeal 10.00 2010.01.22 -
ClamAV 0.94.1 2010.01.22 -
Comodo 3677 2010.01.23 -
DrWeb 5.0.1.12222 2010.01.23 -
eSafe 7.0.17.0 2010.01.21 -
eTrust-Vet 35.2.7255 2010.01.22 -
F-Prot 4.5.1.85 2010.01.22 -
F-Secure 9.0.15370.0 2010.01.23 -
Fortinet 4.0.14.0 2010.01.23 -
GData 19 2010.01.23 -
Ikarus T3.1.1.80.0 2010.01.23 -
Jiangmin 13.0.900 2010.01.23 -
K7AntiVirus 7.10.952 2010.01.22 -
Kaspersky 7.0.0.125 2010.01.23 -
McAfee 5869 2010.01.22 -
McAfee+Artemis 5869 2010.01.22 -
McAfee-GW-Edition 6.8.5 2010.01.23 -
Microsoft 1.5405 2010.01.22 -
NOD32 4798 2010.01.22 -
Norman 6.04.03 2010.01.22 -
nProtect 2009.1.8.0 2010.01.22 -
Panda 10.0.2.2 2010.01.22 -
PCTools 7.0.3.5 2010.01.23 -
Rising 22.31.04.04 2010.01.22 -
Sophos 4.50.0 2010.01.23 -
Sunbelt 3.2.1858.2 2010.01.23 -
Symantec 20091.2.0.41 2010.01.23 -
TheHacker 6.5.0.9.160 2010.01.23 -
TrendMicro 9.120.0.1004 2010.01.23 -
VBA32 3.12.12.1 2010.01.21 -
ViRobot 2010.1.22.2151 2010.01.22 -
VirusBuster 5.0.21.0 2010.01.22 -
Rozšiřující informace
File size: 1810560 bytes
MD5 : 31d64f244916bb367c158218d47dfadf
SHA1 : 0d8568512a8538665523a8946d6ec94b19a1b394
SHA256: 78ad72aa93f763f2a85698891f87c99260dd0f3420b7d6ef3dcbb835a869ba8c
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0xD3440
timedatestamp.....: 0x4A532A76 (Tue Jul 7 12:59:02 2009)
machinetype.......: 0x14C (Intel I386)
( 10 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x500 0x9F286 0x9F300 6.57 daa41aae14a949cab15d5f33a025c43f
page 0x9F800 0x33B7C 0x33B80 6.45 3970fed1eb14cd57803f08e359ddf883
init 0xD3380 0x340 0x380 5.64 3ccc79d6f4454285d3d778f0b83e6b87
.rdata 0xD3700 0x1DF14 0x1DF80 5.93 3c75b96f79ace59aa81617d972db4153
.data 0xF1680 0x631E0 0x63200 4.34 515a74918d8fe8833f9b63ca904a54bc
init 0x154880 0x8C 0x100 2.64 b8c68280a60540773b195edf7ffe1357
_PDATA 0x154980 0x54A08 0x54A80 6.51 9cb1e627c2a3290ec3e5b97578456089
INIT 0x1A9400 0x796 0x800 5.37 608fb06c30542444a4e3d81dfa37dda0
.rsrc 0x1A9C00 0x2B8 0x300 3.01 50c957b25cff28412c47621971f94762
.reloc 0x1A9F00 0x10128 0x10180 6.42 251029e53174246fe7c4ad6ee8d41355
( 3 imports )
> hal.dll: KeQueryPerformanceCounter
> ks.sys: KsCreatePin
> ntoskrnl.exe: RtlStringFromGUID, KeReleaseSemaphore, ObfDereferenceObject, KeSetEvent, ObReferenceObjectByHandle, ExEventObjectType, InterlockedIncrement, InterlockedDecrement, _purecall, RtlCompareUnicodeString, RtlCompareMemory, KeInitializeMutex, KeGetCurrentThread, KeWaitForSingleObject, KeReleaseMutex, ZwClose, IofCallDriver, IoBuildDeviceIoControlRequest, KeInitializeEvent, ZwCreateFile, KeResetEvent, InterlockedExchange, KeCancelTimer, KeClearEvent, InterlockedCompareExchange, KeSetTimer, PsTerminateSystemThread, RtlFreeUnicodeString, KeWaitForMultipleObjects, KeSetPriorityThread, PsCreateSystemThread, MmBuildMdlForNonPagedPool, IoAllocateMdl, ExFreePool, IoFreeIrp, IoFreeMdl, MmUnlockPages, MmMapLockedPages, MmProbeAndLockPages, _except_handler3, IoGetDeviceProperty, IofCompleteRequest, IoReleaseCancelSpinLock, IoDeleteDevice, IoDetachDevice, PoCallDriver, PoStartNextPowerIrp, IoAttachDeviceToDeviceStack, IoCreateDevice, IoWMIRegistrationControl, KeQuerySystemTime, _allmul, _aulldiv, MmMapLockedPagesSpecifyCache, KeInitializeTimer, RtlEqualUnicodeString, _vsnwprintf, wcslen, RtlInitUnicodeString, IoGetDeviceInterfaces, swprintf, ZwQueryValueKey, ZwSetValueKey, ZwDeleteValueKey, ZwCreateKey, ZwOpenKey, IoIsWdmVersionAvailable, KeDelayExecutionThread, IoAllocateIrp, ExAllocatePoolWithTag, RtlRaiseException, KeBugCheckEx, sprintf, memmove, strncpy
( 0 exports )
TrID : File type identification
Clipper DOS Executable (33.3%)
Generic Win/DOS Executable (33.0%)
DOS Executable Generic (33.0%)
VXD Driver (0.5%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
ssdeep: 24576:+JHRCU/liAQeXwaE4eYqL/7Lkev6Ho+ZqUgzARQS3wN6XeO+Nuqp:8HRCOlibeXwHnLjLkeCHpgkQWYGeu
PEiD : -
RDS : NSRL Reference Data Set
-