Tak to mam. Je to síla. Kopíroval jsem celou tu tabulku, omlouvám se, jestli jsou ty spodní části zbytečné.
Každopádně ten C:\windows\system32\drivers\izsmuyy.sys nejde otestovat. Neodpovídají stránky. Dával jsem několikrát počkat, ale pořád nic, restartoval jsem a pořád nic, nevím, co s tím. Ostatní proběhly v pořádku, jenom škoda, že jsou vadný... :
C:/dinu.exe:
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.01.18 -
AhnLab-V3 5.0.0.2 2010.01.18 -
AntiVir 7.9.1.142 2010.01.18 -
Antiy-AVL 2.0.3.7 2010.01.18 -
Authentium 5.2.0.5 2010.01.16 -
Avast 4.8.1351.0 2010.01.18 -
AVG 9.0.0.730 2010.01.18 -
BitDefender 7.2 2010.01.18 -
CAT-QuickHeal 10.00 2010.01.18 -
ClamAV 0.94.1 2010.01.18 -
Comodo 3624 2010.01.18 -
DrWeb 5.0.1.12222 2010.01.18 -
eSafe 7.0.17.0 2010.01.17 -
eTrust-Vet 35.2.7243 2010.01.18 -
F-Prot 4.5.1.85 2010.01.17 -
F-Secure 9.0.15370.0 2010.01.18 -
Fortinet 4.0.14.0 2010.01.18 -
GData 19 2010.01.18 -
Ikarus T3.1.1.80.0 2010.01.18 -
Jiangmin 13.0.900 2010.01.18 -
K7AntiVirus 7.10.949 2010.01.16 -
Kaspersky 7.0.0.125 2010.01.18 -
McAfee 5864 2010.01.17 -
McAfee+Artemis 5864 2010.01.17 -
McAfee-GW-Edition 6.8.5 2010.01.18 -
Microsoft 1.5302 2010.01.18 -
NOD32 4782 2010.01.18 -
Norman 6.04.03 2010.01.18 -
nProtect 2009.1.8.0 2010.01.18 -
Panda 10.0.2.2 2010.01.17 -
PCTools 7.0.3.5 2010.01.18 -
Prevx 3.0 2010.01.18 -
Rising 22.31.00.04 2010.01.18 -
Sophos 4.49.0 2010.01.18 -
Sunbelt 3.2.1858.2 2010.01.17 -
Symantec 20091.2.0.41 2010.01.18 -
TheHacker 6.5.0.6.154 2010.01.18 -
TrendMicro 9.120.0.1004 2010.01.18 -
VBA32 3.12.12.1 2010.01.17 -
ViRobot 2010.1.18.2142 2010.01.18 -
VirusBuster 5.0.21.0 2010.01.17 -
Rozšiřující informace
File size: 2329 bytes
MD5...: a5718e53661a49dd59bffa4fb4ef60f8
SHA1..: a2153b036f67068c116ada37de1ccfe1b9a69dd1
SHA256: b375655c496ea593b5e92eced6c976808ef1d5fe118a6102ee5e01329d76ca32
ssdeep: 48:pNpZT+P5mA0/QvBYIutDQFK/UiuNArQvYDZTVa8W5lLosidJndlcH58iddYnd
XDY:pYUAbBstUizmOaYdJdlUdGdzdHbK
PEiD..: -
PEInfo: -
RDS...: NSRL Reference Data Set
-
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
trid..: HyperText Markup Language (100.0%)
pdfid.: -
C:/wuovki.exe:
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.01.18 -
AhnLab-V3 5.0.0.2 2010.01.18 -
AntiVir 7.9.1.142 2010.01.18 -
Antiy-AVL 2.0.3.7 2010.01.18 -
Authentium 5.2.0.5 2010.01.16 W32/Damaged_File.gen!Eldorado
Avast 4.8.1351.0 2010.01.18 Win32:Rootkit-gen
AVG 9.0.0.730 2010.01.18 -
BitDefender 7.2 2010.01.18 -
CAT-QuickHeal 10.00 2010.01.18 -
ClamAV 0.94.1 2010.01.18 PUA.Packed.ASPack212
Comodo 3624 2010.01.18 -
DrWeb 5.0.1.12222 2010.01.18 -
eSafe 7.0.17.0 2010.01.17 -
eTrust-Vet 35.2.7243 2010.01.18 -
F-Prot 4.5.1.85 2010.01.17 W32/Damaged_File.gen!Eldorado
F-Secure 9.0.15370.0 2010.01.18 -
Fortinet 4.0.14.0 2010.01.18 -
GData 19 2010.01.18 Win32:Rootkit-gen
Ikarus T3.1.1.80.0 2010.01.18 -
Jiangmin 13.0.900 2010.01.18 Packed.Katusha.cxc
K7AntiVirus 7.10.949 2010.01.16 -
Kaspersky 7.0.0.125 2010.01.18 -
McAfee 5864 2010.01.17 -
McAfee+Artemis 5864 2010.01.17 -
McAfee-GW-Edition 6.8.5 2010.01.18 Heuristic.LooksLike.Win32.Suspicious.A
Microsoft 1.5302 2010.01.18 -
NOD32 4782 2010.01.18 -
Norman 6.04.03 2010.01.18 -
nProtect 2009.1.8.0 2010.01.18 -
Panda 10.0.2.2 2010.01.17 -
PCTools 7.0.3.5 2010.01.18 -
Prevx 3.0 2010.01.18 Medium Risk Malware
Rising 22.31.00.04 2010.01.18 -
Sophos 4.49.0 2010.01.18 -
Sunbelt 3.2.1858.2 2010.01.17 -
Symantec 20091.2.0.41 2010.01.18 -
TheHacker 6.5.0.6.154 2010.01.18 -
TrendMicro 9.120.0.1004 2010.01.18 -
VBA32 3.12.12.1 2010.01.17 -
ViRobot 2010.1.18.2142 2010.01.18 -
VirusBuster 5.0.21.0 2010.01.17 -
Rozšiřující informace
File size: 38912 bytes
MD5...: 9681fb0494c75c5315654d282d5196c3
SHA1..: f39cd3f4b39c7481fb2d52253f49ce3ba6c2f364
SHA256: 68995a30a1d2ca3724f3f01e1ff609d57b6d4d59bf52e4af0fa0f73af26cb453
ssdeep: 768:KAR0oeJoIABU1rt0ayZ5R7ETXqo0GHpCyKsNUZHv2tdQ0bJGDJx1c:92opP6
1ri90XppCyKsNUZHOti0bJx
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x17001
timedatestamp.....: 0x4b50ea6e (Fri Jan 15 22:21:34 2010)
machinetype.......: 0x14c (I386)
( 7 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xc000 0x7000 7.99 fe32b14a836239d13edfce109278a85a
.rdata 0xd000 0x3000 0x1200 7.73 5fe96e9593b76a906b3b0a3ee1914718
.data 0x10000 0x5000 0x400 7.59 218db55ef19e01db261205004516bcbb
.rsrc 0x15000 0x1000 0x200 1.33 1008a486f91b813b39b46455d9d03d14
.nznzn 0x16000 0x1000 0x200 2.78 ed9ebea3daa1e4a95d629ea9f2506f2e
.aspack 0x17000 0x2000 0x1200 6.22 a166e6550d3d6076c1b0ee00dbc23a6b
.adata 0x19000 0x1000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
( 0 imports )
( 0 exports )
RDS...: NSRL Reference Data Set
-
packers (Kaspersky): ASPack
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
pdfid.: -
<a href='
http://info.prevx.com/aboutprogramtext. ... 00843BA805' target='_blank'>
http://info.prevx.com/aboutprogramtext. ... 43BA805</a>
trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
c:\gbqitfm.exe :
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.01.18 P2P-Worm.Win32.Palevo!IK
AhnLab-V3 5.0.0.2 2010.01.18 -
AntiVir 7.9.1.142 2010.01.18 TR/Dldr.Genome.acra.8
Antiy-AVL 2.0.3.7 2010.01.18 Trojan/Win32.Genome.gen
Authentium 5.2.0.5 2010.01.16 -
Avast 4.8.1351.0 2010.01.18 Win32:Palevo-T
AVG 9.0.0.730 2010.01.18 Win32/Dlder.D
BitDefender 7.2 2010.01.18 Backdoor.Bot.111845
CAT-QuickHeal 10.00 2010.01.18 TrojanDownloader.Genome.acra
ClamAV 0.94.1 2010.01.18 -
Comodo 3624 2010.01.18 -
DrWeb 5.0.1.12222 2010.01.18 Win32.HLLW.Lime.8
eSafe 7.0.17.0 2010.01.17 -
eTrust-Vet 35.2.7243 2010.01.18 -
F-Prot 4.5.1.85 2010.01.17 -
F-Secure 9.0.15370.0 2010.01.18 Backdoor.Bot.111845
Fortinet 4.0.14.0 2010.01.18 W32/Genome.ACRA!tr.dldr
GData 19 2010.01.18 Backdoor.Bot.111845
Ikarus T3.1.1.80.0 2010.01.18 P2P-Worm.Win32.Palevo
Jiangmin 13.0.900 2010.01.18 TrojanDownloader.Genome.haj
K7AntiVirus 7.10.949 2010.01.16 -
Kaspersky 7.0.0.125 2010.01.18 Trojan-Downloader.Win32.Genome.acra
McAfee 5864 2010.01.17 -
McAfee+Artemis 5864 2010.01.17 Artemis!5805035FCBC7
McAfee-GW-Edition 6.8.5 2010.01.18 Heuristic.LooksLike.Worm.Palevo.H
Microsoft 1.5302 2010.01.18 -
NOD32 4783 2010.01.18 Win32/TrojanDownloader.Small.OUC
Norman 6.04.03 2010.01.18 W32/Downloader.ASMJ
nProtect 2009.1.8.0 2010.01.18 -
Panda 10.0.2.2 2010.01.17 Suspicious file
PCTools 7.0.3.5 2010.01.18 -
Prevx 3.0 2010.01.18 Medium Risk Malware Downloader
Rising 22.31.00.04 2010.01.18 Win32.Polipo.t
Sophos 4.49.0 2010.01.18 Mal/Generic-A
Sunbelt 3.2.1858.2 2010.01.17 -
Symantec 20091.2.0.41 2010.01.18 -
TheHacker 6.5.0.6.154 2010.01.18 Trojan/Downloader.Genome.gen
TrendMicro 9.120.0.1004 2010.01.18 -
VBA32 3.12.12.1 2010.01.17 Trojan-Downloader.Win32.Genome.abog
ViRobot 2010.1.18.2142 2010.01.18 -
VirusBuster 5.0.21.0 2010.01.17 -
Rozšiřující informace
File size: 107008 bytes
MD5...: 5805035fcbc73888280bb11664554ec4
SHA1..: 6f94a6bf8075cf131c080c303e8f72b886f8cad5
SHA256: 129fbbc72fbcb0901923649ea6c5bdf6c72e385c0c4c7e2745c2241a35e51416
ssdeep: 1536:mmOH4+TcTpkHbWBt3yjRNfxiLxm4f6b29pVf6tyzLqAaBeMvyJEvIuZxf33
1T2X2:mINkHbWXmUqgpd6tyqAoeMvyYn9T2X2
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4d7c
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)
( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0x3f9b 0x4000 6.35 5ab2a23b3e45db7c28cc8295d883d63c
DATA 0x5000 0x164 0x200 2.88 310d1979919812ea7ea3eba831ed5c49
BSS 0x6000 0xdf1 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0x7000 0x212 0x400 2.53 0950f1cef82a2d5c458158a9d4630926
.tls 0x8000 0x4 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 0x9000 0x18 0x200 0.20 464e11218533a2251856b8bc9db70ff1
.reloc 0xa000 0x4d4 0x600 5.86 2a3f2fff85df315ec6c6eaeb544a9ade
.rsrc 0xb000 0x14e30 0x15000 6.08 dda8852ab36b0ea30a5ff7da1989b881
( 4 imports )
> kernel32.dll: GetCurrentThreadId, WideCharToMultiByte, ExitProcess, RtlUnwind, RaiseException, TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA, FreeLibrary, HeapFree, HeapReAlloc, HeapAlloc, GetProcessHeap
> oleaut32.dll: SysFreeString, SysReAllocStringLen
> kernel32.dll: LoadLibraryExA
> winmm.dll: timeGetTime
( 0 exports )
RDS...: NSRL Reference Data Set
-
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
<a href='
http://info.prevx.com/aboutprogramtext. ... 00EE1E5FEC' target='_blank'>
http://info.prevx.com/aboutprogramtext. ... E1E5FEC</a>
pdfid.: -
trid..: Win32 Executable Generic (58.3%)
Win16/32 Executable Delphi generic (14.1%)
Generic Win/DOS Executable (13.7%)
DOS Executable Generic (13.6%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
C:\gwequ.exe :
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.01.18 Win32.Worm.Palevo!IK
AhnLab-V3 5.0.0.2 2010.01.18 -
AntiVir 7.9.1.142 2010.01.18 DR/Delphi.Gen
Antiy-AVL 2.0.3.7 2010.01.18 Trojan/Win32.Agent.gen
Authentium 5.2.0.5 2010.01.16 -
Avast 4.8.1351.0 2010.01.18 -
AVG 9.0.0.730 2010.01.18 Worm/Generic.ATAM
BitDefender 7.2 2010.01.18 Backdoor.Agent.AAKZ
CAT-QuickHeal 10.00 2010.01.18 Win32.Worm.Pushbot.gen.8
ClamAV 0.94.1 2010.01.18 -
Comodo 3624 2010.01.18 -
DrWeb 5.0.1.12222 2010.01.18 BackDoor.IRC.Sdbot.8011
eSafe 7.0.17.0 2010.01.17 -
eTrust-Vet 35.2.7243 2010.01.18 -
F-Prot 4.5.1.85 2010.01.17 -
F-Secure 9.0.15370.0 2010.01.18 Backdoor.Agent.AAKZ
Fortinet 4.0.14.0 2010.01.18 -
GData 19 2010.01.18 Backdoor.Agent.AAKZ
Ikarus T3.1.1.80.0 2010.01.18 Win32.Worm.Palevo
Jiangmin 13.0.900 2010.01.18 -
K7AntiVirus 7.10.949 2010.01.16 -
Kaspersky 7.0.0.125 2010.01.18 Backdoor.Win32.SdBot.qxy
McAfee 5864 2010.01.17 -
McAfee+Artemis 5864 2010.01.17 Artemis!F0A88C1CAB11
McAfee-GW-Edition 6.8.5 2010.01.18 Heuristic.LooksLike.Worm.Palevo.H
Microsoft 1.5302 2010.01.18 -
NOD32 4783 2010.01.18 Win32/AutoRun.IRCBot.DZ
Norman 6.04.03 2010.01.18 -
nProtect 2009.1.8.0 2010.01.18 -
Panda 10.0.2.2 2010.01.17 Trj/CI.A
PCTools 7.0.3.5 2010.01.18 Trojan.IRCBot
Prevx 3.0 2010.01.18 Internet Chat High Risk Worm
Rising 22.31.00.04 2010.01.18 Trojan.Win32.Generic.51F77DFD
Sophos 4.49.0 2010.01.18 Mal/Generic-A
Sunbelt 3.2.1858.2 2010.01.17 Trojan.Win32.Buzus.bzaz (v)
Symantec 20091.2.0.41 2010.01.18 W32.IRCBot
TheHacker 6.5.0.6.154 2010.01.18 -
TrendMicro 9.120.0.1004 2010.01.18 -
VBA32 3.12.12.1 2010.01.17 -
ViRobot 2010.1.18.2142 2010.01.18 Backdoor.Win32.IRCBot.205312.E
VirusBuster 5.0.21.0 2010.01.17 -
Rozšiřující informace
File size: 110592 bytes
MD5...: f0a88c1cab119d85ffa48c46199ea6d9
SHA1..: 705baba22ac9215d1f3c70e308c57cf3fbed30e7
SHA256: fd425ec8094eab430fda6b5bd042f7bb382a5093e77676f701fe2435744dfbda
ssdeep: 3072:p4NpHXWfk8+V6cn1L7KG9jpR0yn6fhYFr8uMcHw7:pIlQk5VZ3TgWFrX+7
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x5444
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)
( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0x5f78 0x6000 6.43 e216bc9735b46e3adaee7d060cb2ddd4
DATA 0x7000 0x188 0x200 3.50 43eff15759d185240b6c4c3c921db27a
BSS 0x8000 0xdd1 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0x9000 0x41c 0x600 3.40 a49ca0dc29c1c5859f1e9d62119d8016
.tls 0xa000 0x8 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 0xb000 0x18 0x200 0.20 a59d5deeda3151a72e3841f3a8a37fbd
.reloc 0xc000 0x6a0 0x800 6.05 86a29457ee475a7682e90b7fd37f3efd
.rsrc 0xd000 0x139a0 0x13a00 6.07 0b2be534e945db45a8289dd00b54142c
( 6 imports )
> kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetVersion, GetCurrentThreadId, WideCharToMultiByte, MultiByteToWideChar, GetThreadLocale, GetStartupInfoA, GetLocaleInfoA, GetCommandLineA, FreeLibrary, ExitProcess, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle
> user32.dll: GetKeyboardType, MessageBoxA
> advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey
> oleaut32.dll: SysFreeString, SysReAllocStringLen, SysAllocStringLen
> kernel32.dll: TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA
> kernel32.dll: LoadLibraryExA, GetTickCount
( 0 exports )
RDS...: NSRL Reference Data Set
-
ThreatExpert info: <a href='
http://www.threatexpert.com/report.aspx ... 46199ea6d9' target='_blank'>
http://www.threatexpert.com/report.aspx ... 99ea6d9</a>
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
<a href='
http://info.prevx.com/aboutprogramtext. ... 005BE7B14D' target='_blank'>
http://info.prevx.com/aboutprogramtext. ... BE7B14D</a>
pdfid.: -
trid..: Win32 Executable Generic (58.3%)
Win16/32 Executable Delphi generic (14.1%)
Generic Win/DOS Executable (13.7%)
DOS Executable Generic (13.6%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
c:\windows\system32\BSETUP.TMP :
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.01.18 -
AhnLab-V3 5.0.0.2 2010.01.18 -
AntiVir 7.9.1.142 2010.01.18 -
Antiy-AVL 2.0.3.7 2010.01.18 -
Authentium 5.2.0.5 2010.01.16 -
Avast 4.8.1351.0 2010.01.18 -
AVG 9.0.0.730 2010.01.18 -
BitDefender 7.2 2010.01.18 -
CAT-QuickHeal 10.00 2010.01.18 -
ClamAV 0.94.1 2010.01.18 -
Comodo 3624 2010.01.18 -
DrWeb 5.0.1.12222 2010.01.18 -
eSafe 7.0.17.0 2010.01.17 -
eTrust-Vet 35.2.7243 2010.01.18 -
F-Prot 4.5.1.85 2010.01.17 -
F-Secure 9.0.15370.0 2010.01.18 -
Fortinet 4.0.14.0 2010.01.18 -
GData 19 2010.01.18 -
Ikarus T3.1.1.80.0 2010.01.18 -
Jiangmin 13.0.900 2010.01.18 -
K7AntiVirus 7.10.949 2010.01.16 -
Kaspersky 7.0.0.125 2010.01.18 -
McAfee 5864 2010.01.17 -
McAfee+Artemis 5864 2010.01.17 -
McAfee-GW-Edition 6.8.5 2010.01.18 -
Microsoft 1.5302 2010.01.18 -
NOD32 4783 2010.01.18 -
Norman 6.04.03 2010.01.18 -
nProtect 2009.1.8.0 2010.01.18 -
Panda 10.0.2.2 2010.01.17 -
PCTools 7.0.3.5 2010.01.18 -
Prevx 3.0 2010.01.18 -
Rising 22.31.00.04 2010.01.18 -
Sophos 4.49.0 2010.01.18 -
Sunbelt 3.2.1858.2 2010.01.17 -
Symantec 20091.2.0.41 2010.01.18 -
TheHacker 6.5.0.6.154 2010.01.18 -
TrendMicro 9.120.0.1004 2010.01.18 -
VBA32 3.12.12.1 2010.01.17 -
ViRobot 2010.1.18.2142 2010.01.18 -
VirusBuster 5.0.21.0 2010.01.17 -
Rozšiřující informace
File size: 3 bytes
MD5...: 05fd9bf017c84467ace9b9ac43d7deec
SHA1..: e24a7d67c27a32e0b5a94f7acc7a43bc2ffff93e
SHA256: a100ee3b09fa4530371ec3fee7c86c743490840f433de98870dc569bdf988803
ssdeep: 3:y:y
PEiD..: -
PEInfo: -
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Unknown!
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
c:\windows\system32\dwwin.exe :
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.01.18 -
AhnLab-V3 5.0.0.2 2010.01.18 -
AntiVir 7.9.1.142 2010.01.18 -
Antiy-AVL 2.0.3.7 2010.01.18 -
Authentium 5.2.0.5 2010.01.16 -
Avast 4.8.1351.0 2010.01.18 -
AVG 9.0.0.730 2010.01.18 -
BitDefender 7.2 2010.01.18 -
CAT-QuickHeal 10.00 2010.01.18 -
ClamAV 0.94.1 2010.01.18 -
Comodo 3624 2010.01.18 -
DrWeb 5.0.1.12222 2010.01.18 -
eSafe 7.0.17.0 2010.01.17 -
eTrust-Vet 35.2.7243 2010.01.18 -
F-Prot 4.5.1.85 2010.01.17 -
F-Secure 9.0.15370.0 2010.01.18 -
Fortinet 4.0.14.0 2010.01.18 -
GData 19 2010.01.18 -
Ikarus T3.1.1.80.0 2010.01.18 -
Jiangmin 13.0.900 2010.01.18 -
K7AntiVirus 7.10.949 2010.01.16 -
Kaspersky 7.0.0.125 2010.01.18 -
McAfee 5864 2010.01.17 -
McAfee+Artemis 5864 2010.01.17 -
McAfee-GW-Edition 6.8.5 2010.01.18 -
Microsoft 1.5302 2010.01.18 -
NOD32 4783 2010.01.18 -
Norman 6.04.03 2010.01.18 -
nProtect 2009.1.8.0 2010.01.18 -
Panda 10.0.2.2 2010.01.17 -
PCTools 7.0.3.5 2010.01.18 -
Prevx 3.0 2010.01.18 -
Rising 22.31.00.04 2010.01.18 -
Sophos 4.49.0 2010.01.18 -
Sunbelt 3.2.1858.2 2010.01.17 -
Symantec 20091.2.0.41 2010.01.18 -
TheHacker 6.5.0.6.154 2010.01.18 -
TrendMicro 9.120.0.1004 2010.01.18 -
VBA32 3.12.12.1 2010.01.17 -
ViRobot 2010.1.18.2142 2010.01.18 -
VirusBuster 5.0.21.0 2010.01.17 -
Rozšiřující informace
File size: 180224 bytes
MD5...: 1f70f7026a4d778309d39ffb4dc08e75
SHA1..: 908443e9f40b468b7bbbb771a7fb799ba9121fb2
SHA256: 6b967b4853c391c8c8e77059192ccfe936bbf8e110106b4ba37c4237b8afd7f3
ssdeep: 3072:wH7taLQQ+BZfNEyaIytZ7JBxkJ5OblLmzRKukr8tPq3bMl3/ILlqz98dP1G
d:staLQRfeoW7JBxk7QlCkukItPgbMl3/7
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x749a
timedatestamp.....: 0x3f8e134e (Thu Oct 16 03:41:02 2003)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x28e92 0x29000 6.65 eb5aaa0f29ddd4838ad3b95f2ab37002
.data 0x2a000 0x8154 0x1000 0.97 e76486527bc3baee910420fd8ab4437d
.rsrc 0x33000 0xaa4 0x1000 2.88 2db9e5c668dd01a3c628a58179a6a1e0
( 11 imports )
> ADVAPI32.DLL: RegCloseKey, RegOpenKeyExA, RegQueryValueExA, RegEnumKeyExA, RegQueryInfoKeyA, RegQueryValueExW, DeregisterEventSource, ReportEventA, RegisterEventSourceW, RegEnumValueA, GetUserNameA
> COMCTL32.DLL: -
> GDI32.DLL: DeleteDC, RestoreDC, DeleteObject, GetTextMetricsA, GetTextFaceA, SelectObject, CreateFontA, GetDeviceCaps, SetMapMode, SaveDC, Polyline, CreatePen, ExtTextOutW, GetTextExtentPoint32W, SetTextAlign, SetBkMode, SetTextColor, CreateFontIndirectA, GetObjectA
> KERNEL32.DLL: MultiByteToWideChar, GetCommandLineA, ExitProcess, GetCommandLineW, MapViewOfFile, ReleaseMutex, WaitForSingleObject, WaitForMultipleObjects, LeaveCriticalSection, EnterCriticalSection, DeleteFileW, GetModuleHandleA, GetStartupInfoA, GetStartupInfoW, CloseHandle, CreateThread, Sleep, GetCurrentProcess, TerminateProcess, SetUnhandledExceptionFilter, MulDiv, FreeLibrary, GetProcAddress, WideCharToMultiByte, GetModuleFileNameA, LoadLibraryA, GetSystemDefaultLangID, GetUserDefaultLangID, GetACP, GetSystemDefaultLCID, GetVersionExA, InitializeCriticalSection, GetProcessHeap, DeleteCriticalSection, lstrcpyA, GetLastError, GetProfileStringA, SetEvent, CreateSemaphoreA, CreateFileMappingA, GetFileSize, CreateFileA, UnmapViewOfFile, DeleteFileA, RemoveDirectoryA, RemoveDirectoryW, GetTickCount, SetEnvironmentVariableA, ReadProcessMemory, VirtualQueryEx, GetSystemInfo, GetFileAttributesA, CreateDirectoryA, FindNextFileA, FindClose, FindFirstFileA, GetWindowsDirectoryA, WriteFile, SetFilePointer, CreateFileW, GetTempPathW, GetFileAttributesW, CreateDirectoryW, LockResource, LoadResource, FindResourceExA, GetSystemDirectoryA, SetEndOfFile, ExpandEnvironmentStringsA, ExpandEnvironmentStringsW, IsDBCSLeadByte, CreateProcessA, CreateProcessW, SuspendThread, GetSystemTime, GetComputerNameA, CreateMutexA, TlsAlloc, TlsFree, TlsSetValue, VirtualFree, TlsGetValue, GetTempPathA, ResumeThread, GetCurrentThreadId, TerminateThread, GetCurrentProcessId, IsValidCodePage, HeapAlloc, VirtualAlloc, DuplicateHandle, lstrcmpW, GetStringTypeW, DebugBreak, GetThreadSelectorEntry, GetLocaleInfoA, LCMapStringW, GetThreadContext, HeapFree, SetLastError, GetSystemTimeAsFileTime, OutputDebugStringA, LCMapStringA, GetStringTypeA, RtlUnwind
> OLEAUT32.DLL: -, -, -, -, -
> SHELL32.DLL: ExtractIconExA, ShellExecuteExA
> SHLWAPI.DLL: AssocQueryStringW, UrlGetPartA, wnsprintfA
> URLMON.DLL: CreateURLMoniker
> USER32.DLL: GetScrollInfo, IsDlgButtonChecked, LoadIconA, DrawFocusRect, SetWindowTextW, GetWindow, LoadCursorA, DestroyIcon, GetWindowPlacement, IsIconic, LoadStringW, GetWindowThreadProcessId, EnumWindows, CharPrevA, CallWindowProcA, CallWindowProcW, IsWindowUnicode, EnableWindow, DrawIconEx, DestroyWindow, SetWindowLongA, GetSysColor, SendDlgItemMessageA, GetClientRect, SetScrollInfo, SystemParametersInfoA, CheckDlgButton, SetDlgItemTextA, SetFocus, EndDialog, GetDlgItem, ShowWindow, SetCursor, InvalidateRect, DialogBoxParamW, DialogBoxParamA, CreateDialogParamW, CreateDialogParamA, SetWindowTextA, GetDC, MapWindowPoints, GetSysColorBrush, FillRect, ReleaseDC, GetSystemMetrics, SetForegroundWindow, GetWindowLongA, GetWindowRect, SetWindowPos, RegisterClassExA, CreateWindowExA, GetMessageA, IsDialogMessageA, TranslateMessage, DispatchMessageA, PostQuitMessage, KillTimer, SetTimer, SendMessageA, PostMessageA, DefWindowProcA
> VERSION.DLL: GetFileVersionInfoSizeA, GetFileVersionInfoSizeW, VerQueryValueA, GetFileVersionInfoW, GetFileVersionInfoA
> WININET.DLL: InternetReadFileExA, InternetWriteFile, HttpSendRequestExA, InternetSetOptionA, HttpEndRequestA, InternetSetStatusCallback, InternetAutodial, InternetGetConnectedState, InternetCloseHandle, InternetQueryOptionA, HttpQueryInfoA, HttpOpenRequestA, InternetConnectA, InternetOpenA
( 0 exports )
RDS...: NSRL Reference Data Set
-
sigcheck:
publisher....: Microsoft Corporation
copyright....: Copyright(c) Microsoft Corporation 1999-2001._ All rights reserved.
product......: Microsoft Application Error Reporting
description..: Microsoft Application Error Reporting
original name: DW.Exe
internal name: DW
file version.: 10.0.5815
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
trid..: Win64 Executable Generic (54.6%)
Win32 Executable MS Visual C++ (generic) (24.0%)
Windows Screen Saver (8.3%)
Win32 Executable Generic (5.4%)
Win32 Dynamic Link Library (generic) (4.8%)
pdfid.: -
c:\documents and settings\Sele\Nabídka Start\Programy\Po spuštění\ihaupd32.exe :
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.01.18 Trojan.Win32.Bredolab!IK
AhnLab-V3 5.0.0.2 2010.01.18 -
AntiVir 7.9.1.142 2010.01.18 DR/Delphi.Gen
Antiy-AVL 2.0.3.7 2010.01.18 -
Authentium 5.2.0.5 2010.01.16 -
Avast 4.8.1351.0 2010.01.18 Win32:Bredolab-BN
AVG 9.0.0.730 2010.01.18 Win32/Cryptor
BitDefender 7.2 2010.01.18 Trojan.Downloader.Bredolab.CK
CAT-QuickHeal 10.00 2010.01.18 Win32.Trojan.Monder.gen.4
ClamAV 0.94.1 2010.01.18 Trojan.Agent-136630
Comodo 3624 2010.01.18 -
DrWeb 5.0.1.12222 2010.01.18 Trojan.Botnetlog.11
eSafe 7.0.17.0 2010.01.17 Win32.DRDelphi
eTrust-Vet 35.2.7243 2010.01.18 Win32/Bredolab.C!generic
F-Prot 4.5.1.85 2010.01.17 -
F-Secure 9.0.15370.0 2010.01.18 Trojan.Downloader.Bredolab.CK
Fortinet 4.0.14.0 2010.01.18 W32/PackBredolab.D!tr
GData 19 2010.01.18 Trojan.Downloader.Bredolab.CK
Ikarus T3.1.1.80.0 2010.01.18 Trojan.Win32.Bredolab
Jiangmin 13.0.900 2010.01.18 Backdoor/Bredolab.bdi
K7AntiVirus 7.10.949 2010.01.16 -
Kaspersky 7.0.0.125 2010.01.18 Backdoor.Win32.Bredolab.btx
McAfee 5864 2010.01.17 Generic Dropper.lr.gen
McAfee+Artemis 5864 2010.01.17 Generic Dropper.lr.gen
McAfee-GW-Edition 6.8.5 2010.01.18 Trojan.Dropper.Delphi.Gen
Microsoft 1.5302 2010.01.18 -
NOD32 4783 2010.01.18 a variant of Win32/Kryptik.BUW
Norman 6.04.03 2010.01.18 -
nProtect 2009.1.8.0 2010.01.18 -
Panda 10.0.2.2 2010.01.17 Trj/CI.A
PCTools 7.0.3.5 2010.01.18 HeurEngine.MaliciousPacker
Prevx 3.0 2010.01.18 Medium Risk Malware
Rising 22.31.00.04 2010.01.18 -
Sophos 4.49.0 2010.01.18 Mal/BredoPk-B
Sunbelt 3.2.1858.2 2010.01.17 Trojan.Win32.Bredolab.Gen.2 (v)
Symantec 20091.2.0.41 2010.01.18 Packed.Generic.265
TheHacker 6.5.0.6.154 2010.01.18 Trojan/Bredolab.gen
TrendMicro 9.120.0.1004 2010.01.18 TROJ_BREDLAB.SMP
VBA32 3.12.12.1 2010.01.17 -
ViRobot 2010.1.18.2142 2010.01.18 -
VirusBuster 5.0.21.0 2010.01.17 Trojan.Fraudload.Gen!Pac.5
Rozšiřující informace
File size: 32768 bytes
MD5...: ea0fded9c20b1663a150f6a5818a2d43
SHA1..: d8764cc3b74c40d8e099e9a0670797d8c3f692d9
SHA256: 02a3b98006068188407b3b48979108a86464284c508967ec7bdf7b47902bef93
ssdeep: 384:cxu++BwQlXi/gfvcQTAoTvv79bGC4zoVfXs/aRi6tusWbZO:cQ++BbsYncQt
Td7ZXsRXh
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x109a
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x19c1 0x1a00 0.69 be27be6b58482b17438f8bf3e453808d
.rdata 0x3000 0x5d2 0x600 3.88 3113c9dc5fc5939925b1c5851c911e46
.data 0x4000 0xab7 0xa00 5.49 9072a7b47e3a975e6bdcc490fdf726c0
.rsrc 0x5000 0xb1b7 0x5200 7.68 43ce0db7eef5a2a863276fe5a8bd2f09
( 3 imports )
> kernel32.dll: GetProcAddress, LoadLibraryA, GetCommandLineA, Sleep, CreateEventA, GetModuleHandleA, GlobalAlloc, GlobalFree, LocalFree, GetStdHandle, GetTickCount, FreeLibrary, lstrlenA, GetStartupInfoA, lstrcpyA
> gdi32.dll: PatBlt, LineTo, DeleteObject, SetPixel, GetPixel, CreateSolidBrush, GetBkColor, SetBkMode, CreateCompatibleDC, GetStockObject, GetTextMetricsA, GetObjectA, BitBlt, GetTextColor
> msvcrt.dll: __p__fmode, exit, __getmainargs, _except_handler3, __setusermatherr, __CxxFrameHandler, __set_app_type, wcschr, _adjust_fdiv, wcslen, _acmdln, _controlfp, _XcptFilter, toupper, rand
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
<a href='
http://info.prevx.com/aboutprogramtext. ... 00A3CE0174' target='_blank'>
http://info.prevx.com/aboutprogramtext. ... 3CE0174</a>