nein - hab ich leider nicht drauf geachtet....
Code:
Datei cbXRIyyv.dll empfangen 2008.06.10 14:16:22 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.5.30.1 2008.06.10 -
AntiVir 7.8.0.55 2008.06.10 -
Authentium 5.1.0.4 2008.06.09 -
Avast 4.8.1195.0 2008.06.10 Win32:Vundo@dll
AVG 7.5.0.516 2008.06.10 Generic10.AKCA
BitDefender 7.2 2008.06.10 -
CAT-QuickHeal 9.50 2008.06.09 -
ClamAV 0.92.1 2008.06.10 -
DrWeb 4.44.0.09170 2008.06.10 -
eSafe 7.0.15.0 2008.06.09 -
eTrust-Vet 31.6.5862 2008.06.10 -
Ewido 4.0 2008.06.10 -
F-Prot 4.4.4.56 2008.06.09 W32/Virtumonde.Y.gen!Eldorado
F-Secure 6.70.13260.0 2008.06.10 -
Fortinet 3.14.0.0 2008.06.10 -
GData 2.0.7306.1023 2008.06.10 Win32:Vundo
Ikarus T3.1.1.26.0 2008.06.10 -
Kaspersky 7.0.0.125 2008.06.10 -
McAfee 5313 2008.06.09 -
Microsoft None 2008.06.10 -
NOD32v2 3172 2008.06.10 probably a variant of Win32/Adware.Virtumonde.FP
Norman 5.80.02 2008.06.09 -
Panda 9.0.0.4 2008.06.09 -
Prevx1 V2 2008.06.10 -
Rising 20.48.12.00 2008.06.10 Trojan.Win32.Virtumod.ak
Sophos 4.30.0 2008.06.10 -
Sunbelt 3.0.1145.1 2008.06.05 -
Symantec 10 2008.06.10 -
TheHacker 6.2.92.341 2008.06.10 -
VBA32 3.12.6.7 2008.06.09 -
VirusBuster 4.3.26:9 2008.06.09 -
Webwasher-Gateway 6.6.2 2008.06.10 -
weitere Informationen
File size: 320768 bytes
MD5...: 7b6c925cd4fbca7cfd1ccca356988eb7
SHA1..: 3424dbb2d8e34bd7d56cf72243e08af365ca1e95
SHA256: 893e44c522b0e0c65412a0825ec074195ccab05733d7f61a21412b2e460c0428
SHA512: 2cd3c1bfb3c5e7af2b6b770f880fb0627dc66f709292d4a3b5da38fcba65b57a<br>72188336f07f286ca62d90742262221d80aadde266ec5b4f9aba8cbf7f33d3a8
PEiD..: Armadillo v1.xx - v2.xx
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x1000126a<br>timedatestamp.....: 0x484003d4 (Fri May 30 13:40:36 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 7 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x2000 0x2000 4.70 2683a99634f80a48d61743d688656fbb<br>.text 0x3000 0x1000 0xa00 4.67 99a202463c94c73fbbe33abdf9902730<br>.reloc 0x4000 0xe000 0xd400 8.00 953fb97c390eb5ef639c79edfea9cb33<br>CRT 0x12000 0xc000 0xb400 8.00 4fb381353f44ed213210e6ae1f696fab<br>.idata 0x1e000 0x1000 0xe00 7.95 6f090c5177c6b1714567794b10cf163e<br>.text 0x1f000 0x8000 0x8000 7.99 f8a02b75cfdab7982fb76f38d8f6ae63<br>.bss 0x27000 0x76000 0x2a100 8.00 1c6cbef7978aabe80827e72c90f49e6e<br><br>( 3 imports ) <br>> kernel32.dll: CloseHandle, CreateFileA, DeleteFileA, ExitProcess, FindClose, FindFirstFileA, FreeLibrary, GetCommandLineA, GetFileSize, GetFileType, GetProcAddress, LoadLibraryA, OpenProcess, ReadFile, ResumeThread, SetEndOfFile, SetFilePointer, Sleep, TerminateThread, UnhandledExceptionFilter, VirtualAlloc, VirtualFree, VirtualProtect, WaitForSingleObject, WinExec, WriteFile<br>> user32.dll: BeginPaint, BeginPaint, GetDC, GetDesktopWindow, GetSystemMetrics, GetWindow, GetWindowDC, GetWindowTextA, GetWindowTextLengthA, InvalidateRect, IsWindow, KillTimer, LoadCursorA, LoadIconA, LoadStringA, MessageBoxA, PeekMessageA, PostMessageA, PostQuitMessage, RegisterClassA, ReleaseCapture, ReleaseDC, SendMessageA, SetCursor, SetForegroundWindow, SetMenu, SetMenuItemInfoA, SetPropA, SetScrollPos, SetScrollRange, SetSysColors, SetTimer, SetWindowLongA, SetWindowPos, ShowWindow, SystemParametersInfoA, TranslateMessage, UpdateWindow, ValidateRect, WaitMessage, wvsprintfA<br>> gdi32.dll: CombineRgn, CreateBrushIndirect, CreateCompatibleBitmap, CreateCompatibleDC, CreateDIBSection, CreateRectRgn, CreateSolidBrush, DeleteDC, DeleteObject, GetDeviceCaps, GetPixel, GetStockObject, MoveToEx, Rectangle, RestoreDC, SaveDC, TextOutA<br><br>( 0 exports ) <br>
Code:
Datei ljJCtuUL.dll empfangen 2008.06.10 14:21:53 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.5.30.1 2008.06.10 -
AntiVir 7.8.0.55 2008.06.10 TR/Vundo.HG
Authentium 5.1.0.4 2008.06.09 -
Avast 4.8.1195.0 2008.06.10 Win32:Trojan-gen {Other}
AVG 7.5.0.516 2008.06.10 Generic10.AIJD
BitDefender 7.2 2008.06.10 Trojan.Vundo.EPZ
CAT-QuickHeal 9.50 2008.06.09 -
ClamAV 0.92.1 2008.06.10 -
DrWeb 4.44.0.09170 2008.06.10 -
eSafe 7.0.15.0 2008.06.09 -
eTrust-Vet 31.6.5862 2008.06.10 Win32/Vundo.ABZ
Ewido 4.0 2008.06.10 -
F-Prot 4.4.4.56 2008.06.09 W32/Virtumonde.Y.gen!Eldorado
F-Secure 6.70.13260.0 2008.06.10 -
Fortinet 3.14.0.0 2008.06.10 -
GData 2.0.7306.1023 2008.06.10 Win32:Trojan-gen
Ikarus T3.1.1.26.0 2008.06.10 Trojan.Vundo.EPZ
Kaspersky 7.0.0.125 2008.06.10 -
McAfee 5313 2008.06.09 -
Microsoft None 2008.06.10 -
NOD32v2 3172 2008.06.10 -
Norman 5.80.02 2008.06.09 W32/Virtumonde.WTH
Panda 9.0.0.4 2008.06.09 Spyware/Virtumonde
Prevx1 V2 2008.06.10 Fraudulent Security Program
Rising 20.48.12.00 2008.06.10 Trojan.Win32.Virtumod.al
Sophos 4.30.0 2008.06.10 -
Sunbelt 3.0.1145.1 2008.06.05 -
Symantec 10 2008.06.10 Trojan.Vundo
TheHacker 6.2.92.341 2008.06.10 -
VBA32 3.12.6.7 2008.06.09 -
VirusBuster 4.3.26:9 2008.06.09 -
Webwasher-Gateway 6.6.2 2008.06.10 Trojan.Vundo.HG
weitere Informationen
File size: 33408 bytes
MD5...: 8c45b3bd39860a7d63f1dfff88f513a4
SHA1..: a135739a750bfd4a932cc884aab94ccd9089175a
SHA256: 7911a1e355d66874231c6bdcf414ee667a4c55deb2e2d463a9284ce1e1b1d566
SHA512: cd0e4f480e33da7ff182b5bef7f645297846f4863d14fa4e5eac43f139993d0b<br>b625b7d8cd37a4fd66e80c537dc5c17a040d773cfc9333fadc1a5e09e2a1c9cd
PEiD..: Armadillo v1.xx - v2.xx
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x1000106c<br>timedatestamp.....: 0x4821945b (Wed May 07 11:36:59 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x2000 0x2000 5.03 59a49d0bf0c4009555cdc007723df394<br>BSS 0x3000 0x2000 0x1800 2.16 35dfc25d4b7eb3a1f8572f1add53acbc<br>CODE 0x5000 0x1000 0xa00 7.93 112bfd01851c30793eceaa655c2b63bf<br>BSS 0x6000 0x2000 0x1600 7.96 fbdfde627d250cd6e527ca6dae707ecc<br>.data 0x8000 0x8000 0x2680 7.87 7859cffa083f84da64413e7e14b53729<br><br>( 5 imports ) <br>> kernel32.dll: CloseHandle, CreateFileA, DeleteCriticalSection, DeleteFileA, EnterCriticalSection, GetFileSize, GetFileType, GetProcAddress, InitializeCriticalSection, LeaveCriticalSection, LoadLibraryA, OpenMutexA, OpenProcess, ResumeThread, Sleep, TerminateThread, VirtualAlloc, VirtualFree, VirtualProtect, WaitForSingleObject, WinExec<br>> user32.dll: BeginPaint, GetCapture, GetCursorPos, GetDC, GetSystemMetrics, GetWindow, GetWindowDC, GetWindowDC, GetWindowTextA, GetWindowTextLengthA, InvalidateRect, IsWindow, KillTimer, LoadCursorA, LoadIconA, LoadStringA, MessageBoxA, PeekMessageA, PostMessageA, PostQuitMessage<br>> gdi32.dll: CombineRgn, CreateBrushIndirect, CreateCompatibleBitmap, CreateCompatibleDC, CreateDIBSection, CreateRectRgn, CreateSolidBrush, DeleteDC, DeleteObject, GetDeviceCaps, GetPixel, GetStockObject, MoveToEx, Rectangle, RestoreDC, SaveDC, SelectObject, SetBkColor, SetBkMode, SetBrushOrgEx, SetPixel, StretchBlt, TextOutA<br>> shell32.dll: DragAcceptFiles, SHBrowseForFolder<br>> comdlg32.dll: ChooseColorA, ChooseFontA, GetSaveFileNameA<br><br>( 0 exports ) <br>
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=AFAFA67F802439F282A0002DDDE82A00288738BE
----
C:\WINDOWS\system32\nemvfsgg.dll
diese datei ist nicht da
Code:
Datei mjveiboy.dll empfangen 2008.06.06 16:01:29 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 - - -
AntiVir - - -
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - Suspicious File
eTrust-Vet - - -
Ewido - - -
F-Prot - - W32/Virtumonde.Y.gen!Eldorado
F-Secure - - -
FileAdvisor - - -
Fortinet - - -
GData - - -
Ikarus - - -
Kaspersky - - -
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - -
Panda - - Suspicious file
Prevx1 - - -
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - -
TheHacker - - -
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - Win32.Malware.gen (suspicious)
weitere Informationen
MD5: e4cfb557c4fca9e7d3c8b112853b186d
SHA1: 9e2693706b1c59abf994d62d201c453e57921b69
SHA256: 443164a70443cf2d23528bd85c0787a5a707e81b4b88eb808d4633900aebcd31
SHA512: e149872e3a1ddcebbac483a9c6941ae9d45bcf08e5ef5b6be2ca9de97b58239439d40fa0eb6b66f3bbaf915bcf21b84757aaba28619ede4663f50bc535c20f07
Code:
Datei mmchwjcu.dll empfangen 2008.06.09 20:15:36 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 - - -
AntiVir - - TR/Vundo.HN
Authentium - - -
Avast - - Win32:Vundo@dll
AVG - - -
BitDefender - - Trojan.Vundo.ESN
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - Trojan.Virtumod.412
eSafe - - -
eTrust-Vet - - Win32/Vundo.ABS
Ewido - - -
F-Prot - - W32/Virtumonde.Y.gen!Eldorado
F-Secure - - -
Fortinet - - Adware/VirtuMonde
GData - - Win32:Vundo
Ikarus - - -
Kaspersky - - not-a-virus:AdWare.Win32.Virtumonde.yag
McAfee - - -
Microsoft - - Trojan:Win32/Vundo.gen!E
NOD32v2 - - -
Norman - - W32/Adclicker.DSV
Panda - - Suspicious file
Prevx1 - - Fraudulent Security Program
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - Trojan.Adclicker
TheHacker - - Adware/Virtumonde.yag
VBA32 - - AdWare.Win32.Virtumonde.yag
VirusBuster - - -
Webwasher-Gateway - - Trojan.Vundo.HN
weitere Informationen
MD5: d79ebe2a78986161e8b190d0c3661dc5
SHA1: 5388746d7c5b9c64afea538c07a2a0701ad0f329
SHA256: bd7b1b73b028ba837ec28a1dcdde71ff795dd10a71044ad9beb65284b9906ada
SHA512: 2b74c3945161c10f75e7eb0bd7e507ba5693f5d800c29115efff4800b52dca4009d0d5faa0536634a2521f1b92cc2106bb083a629c7d86aa2703386b3fb322a0
bei den letzten beiden dateien sagt mir der check - wurde bereits analysiert (von mir aber nicht) ist das so richtig?
Code:
Datei mmchwjcu.dll empfangen 2008.06.09 20:15:36 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 - - -
AntiVir - - TR/Vundo.HN
Authentium - - -
Avast - - Win32:Vundo@dll
AVG - - -
BitDefender - - Trojan.Vundo.ESN
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - Trojan.Virtumod.412
eSafe - - -
eTrust-Vet - - Win32/Vundo.ABS
Ewido - - -
F-Prot - - W32/Virtumonde.Y.gen!Eldorado
F-Secure - - -
Fortinet - - Adware/VirtuMonde
GData - - Win32:Vundo
Ikarus - - -
Kaspersky - - not-a-virus:AdWare.Win32.Virtumonde.yag
McAfee - - -
Microsoft - - Trojan:Win32/Vundo.gen!E
NOD32v2 - - -
Norman - - W32/Adclicker.DSV
Panda - - Suspicious file
Prevx1 - - Fraudulent Security Program
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - Trojan.Adclicker
TheHacker - - Adware/Virtumonde.yag
VBA32 - - AdWare.Win32.Virtumonde.yag
VirusBuster - - -
Webwasher-Gateway - - Trojan.Vundo.HN
weitere Informationen
MD5: d79ebe2a78986161e8b190d0c3661dc5
SHA1: 5388746d7c5b9c64afea538c07a2a0701ad0f329
SHA256: bd7b1b73b028ba837ec28a1dcdde71ff795dd10a71044ad9beb65284b9906ada
SHA512: 2b74c3945161c10f75e7eb0bd7e507ba5693f5d800c29115efff4800b52dca4009d0d5faa0536634a2521f1b92cc2106bb083a629c7d86aa2703386b3fb322a0
C:\WINDOWS\system32\OVFLlnnn.ini2 kann ich nicht finden
Code:
Datei vqaguoxb.dll empfangen 2008.06.10 14:59:23 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.5.30.1 2008.06.10 -
AntiVir 7.8.0.55 2008.06.10 TR/LogActivity.A
Authentium 5.1.0.4 2008.06.09 -
Avast 4.8.1195.0 2008.06.10 Win32:Vundo@dll
AVG 7.5.0.516 2008.06.10 -
BitDefender 7.2 2008.06.10 -
CAT-QuickHeal 9.50 2008.06.09 Trojan.Vundo.gen
ClamAV 0.92.1 2008.06.10 -
DrWeb 4.44.0.09170 2008.06.10 -
eSafe 7.0.15.0 2008.06.09 -
eTrust-Vet 31.6.5862 2008.06.10 -
Ewido 4.0 2008.06.10 -
F-Prot 4.4.4.56 2008.06.09 W32/Virtumonde.Y.gen!Eldorado
F-Secure 6.70.13260.0 2008.06.10 Trojan:W32/Vundo.R
Fortinet 3.14.0.0 2008.06.10 -
GData 2.0.7306.1023 2008.06.10 Win32:Vundo
Ikarus T3.1.1.26.0 2008.06.10 Virus.Win32.Vundo@dll
Kaspersky 7.0.0.125 2008.06.10 not-a-virus:AdWare.Win32.Virtumonde.ykb
McAfee 5313 2008.06.09 -
Microsoft None 2008.06.10 -
NOD32v2 3172 2008.06.10 -
Norman 5.80.02 2008.06.09 -
Panda 9.0.0.4 2008.06.09 -
Prevx1 V2 2008.06.10 Malicious Software
Rising 20.48.12.00 2008.06.10 -
Sophos 4.30.0 2008.06.10 Mal/Generic-A
Sunbelt 3.0.1145.1 2008.06.05 -
Symantec 10 2008.06.10 Trojan.Adclicker
TheHacker 6.2.92.341 2008.06.10 -
VBA32 3.12.6.7 2008.06.09 -
VirusBuster 4.3.26:9 2008.06.09 -
Webwasher-Gateway 6.6.2 2008.06.10 Trojan.LogActivity.A
weitere Informationen
File size: 95232 bytes
MD5...: 201a2866fc277e73f23418e487aef6ac
SHA1..: 575c1e7360e8d347728662f923b62bf826a2aa13
SHA256: ae36a62f6112a114d776731b58a9dde297f184c2c2e57f2273f691c0535b54e9
SHA512: 6accacbb14c5804be70b1d2a66fa28e66f445178f4ee16252adb775a1c188261<br>6175b55c67fabd97c968d0acaece9851f2a089b1be9f303873a3743406b7ac4b
PEiD..: Armadillo v1.xx - v2.xx
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x1000141c<br>timedatestamp.....: 0x483c23d4 (Tue May 27 15:08:04 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 9 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x2000 0x2000 4.85 7bf9a47d491f0d87a042baa281fae78c<br>CODE 0x3000 0x2000 0x1800 1.86 d4d056368403b4f915773710b3f2de73<br>.data 0x5000 0x1000 0x800 7.91 8e13c421b4959088af6496e5d979a903<br>CRT 0x6000 0x1000 0xe00 7.94 937f5f5dbd0d1fdc86f29023055831fa<br>DATA 0x7000 0x3000 0x3000 7.98 3a8e9d01b76c04e600dbcffd604e78c1<br>DATA 0xa000 0x2000 0x2000 7.98 d52f0f9cd840970e53e107f6751de722<br>.idata 0xc000 0x3000 0x2e00 7.99 f7238c6afc2456c65374190af411efce<br>.code 0xf000 0x4000 0x3c00 7.99 a29126c3c3495c065474ec942f241334<br>CRT 0x13000 0x13000 0x4e00 7.94 718d7a6874c1909759f70f5863f56c20<br><br>( 3 imports ) <br>> kernel32.dll: DeleteFileA, ExitProcess, FindClose, FindFirstFileA, FreeLibrary, GetCommandLineA, GetCurrentThreadId, GetFileSize, GetFileType, GetLastError, GetModuleFileNameA, GetModuleHandleA, GetProcAddress, LoadLibraryA, lstrcpyn, lstrlen, MultiByteToWideChar, ReadFile, SetEndOfFile, SetFilePointer, UnhandledExceptionFilter, VirtualAlloc, VirtualFree, VirtualProtect, WideCharToMultiByte, WriteFile<br>> user32.dll: BeginPaint, GetWindowDC, SetPropA, SetScrollPos, SetScrollRange, SetSysColors, SetTimer, SetWindowLongA, SetWindowPos, ShowWindow, SystemParametersInfoA, TranslateMessage, UpdateWindow, ValidateRect, WaitMessage, wvsprintfA<br>> gdi32.dll: GetPixel, GetStockObject, MoveToEx, Rectangle, RestoreDC, SaveDC, SelectObject, SetBkColor, SetBkMode, SetBrushOrgEx, SetPixel, SetStretchBltMode, SetTextColor, SetWindowOrgEx, StretchBlt, TextOutA<br><br>( 0 exports ) <br>
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=3175024A00282B03746D012DDDE82A00823B39F0
Code:
Datei xdarvywg.dll empfangen 2008.06.10 15:01:51 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.5.30.1 2008.06.10 -
AntiVir 7.8.0.55 2008.06.10 ADSPY/Virtumonde.xmw
Authentium 5.1.0.4 2008.06.09 -
Avast 4.8.1195.0 2008.06.10 Win32:Vundo@dll
AVG 7.5.0.516 2008.06.10 Generic10.AHPK
BitDefender 7.2 2008.06.10 Trojan.Vundo.EQW
CAT-QuickHeal 9.50 2008.06.09 Trojan.Vundo.gen
ClamAV 0.92.1 2008.06.10 Trojan.Vundo-3749
DrWeb 4.44.0.09170 2008.06.10 -
eSafe 7.0.15.0 2008.06.09 -
eTrust-Vet 31.6.5862 2008.06.10 Win32/Nisrest.AC
Ewido 4.0 2008.06.10 -
F-Prot 4.4.4.56 2008.06.09 W32/Virtumonde.Y.gen!Eldorado
F-Secure 6.70.13260.0 2008.06.10 -
Fortinet 3.14.0.0 2008.06.10 Adware/VirtuMonde
GData 2.0.7306.1023 2008.06.10 Win32:Vundo
Ikarus T3.1.1.26.0 2008.06.10 Virus.Win32.Vundo@dll
Kaspersky 7.0.0.125 2008.06.10 not-a-virus:AdWare.Win32.Virtumonde.xmw
McAfee 5313 2008.06.09 Vundo
Microsoft None 2008.06.10 -
NOD32v2 3172 2008.06.10 Win32/Adware.Virtumonde
Norman 5.80.02 2008.06.09 -
Panda 9.0.0.4 2008.06.09 Spyware/Virtumonde
Prevx1 V2 2008.06.10 Fraudulent Security Program
Rising 20.48.12.00 2008.06.10 -
Sophos 4.30.0 2008.06.10 Troj/ConHook-AN
Sunbelt 3.0.1145.1 2008.06.05 -
Symantec 10 2008.06.10 Trojan.Adclicker
TheHacker 6.2.92.341 2008.06.10 Adware/Virtumonde.xmw
VBA32 3.12.6.7 2008.06.09 AdWare.Win32.Virtumonde.xmw
VirusBuster 4.3.26:9 2008.06.09 -
Webwasher-Gateway 6.6.2 2008.06.10 Ad-Spyware.Virtumonde.xmw
weitere Informationen
File size: 95232 bytes
MD5...: 28d69d1b2e2269e8ac351f77fa4a266f
SHA1..: 531306cac9f1706edbe36be71093496a6e791925
SHA256: f5023638f306e4e3a64509f39585e5f4767d49cf4a5b9ba80575cca4b59c4c57
SHA512: 8dd4ef9178017f0798f38069d9948e416b9bef40afb43f5b796f9d5681ed4395<br>7d7d7e50356acd5c47f7076542a4fc615615a1ff0c20de73b6df36af10f60f87
PEiD..: Armadillo v1.xx - v2.xx
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x10001315<br>timedatestamp.....: 0x483c23d4 (Tue May 27 15:08:04 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x2000 0x2000 5.07 5596708d80a1b346ced07acfe66f4209<br>.idata 0x3000 0x2000 0x1800 2.17 adc9f81daed998c534f5124293b00d4c<br>BSS 0x5000 0x2000 0x1200 7.96 81cf3fa89cb0df0031f89ccbf25d7d49<br>.reloc 0x7000 0x7000 0x6a00 7.99 235413a27816eb29a96379b48cb100c9<br>.bss 0xe000 0x18000 0xa200 7.98 9a67951078fab0a71b40f0f33419363c<br><br>( 4 imports ) <br>> kernel32.dll: CloseHandle, CreateFileA, DeleteCriticalSection, DeleteFileA, GetProcAddress, LeaveCriticalSection, LoadLibraryA, OpenMutexA, OpenProcess, ResumeThread, Sleep, TerminateThread, VirtualAlloc, VirtualFree, VirtualProtect, WaitForSingleObject, WinExec<br>> user32.dll: BeginPaint, FindWindowExA, GetCapture, GetCursorPos, GetDC, GetSystemMetrics, GetWindow, GetWindowDC, GetWindowDC, GetWindowTextA, GetWindowTextLengthA, InvalidateRect, IsWindow, KillTimer, LoadCursorA, LoadIconA, LoadStringA, MessageBoxA, PeekMessageA, PostMessageA, PostQuitMessage, RegisterClassA, ReleaseCapture, ReleaseDC, SendMessageA, SetCursor, SetForegroundWindow, SetMenu, SetMenuItemInfoA, SetPropA, SetScrollPos, SetScrollRange, SetSysColors, SetTimer, SetWindowLongA, SetWindowPos, ShowWindow, SystemParametersInfoA, TranslateMessage<br>> gdi32.dll: DeleteObject, GetDeviceCaps, GetPixel, GetStockObject, MoveToEx, Rectangle, RestoreDC<br>> shell32.dll: DllRegisterServer, DllUnregisterServer, DragAcceptFiles, DragFinish, DragQueryFile, DragQueryPoint, SHBrowseForFolder, Shell_NotifyIcon<br><br>( 0 exports ) <br>
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=444F201400854FAB74F6012DDDE82A00992C9B8B
Code:
Datei qoMfeFyv.dll empfangen 2008.06.10 15:05:02 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.5.30.1 2008.06.10 -
AntiVir 7.8.0.55 2008.06.10 TR/Dldr.ConHook.aku
Authentium 5.1.0.4 2008.06.09 -
Avast 4.8.1195.0 2008.06.10 Win32:Trojan-gen {Other}
AVG 7.5.0.516 2008.06.10 BHO.EGZ
BitDefender 7.2 2008.06.10 Trojan.Vundo.ESD
CAT-QuickHeal 9.50 2008.06.09 -
ClamAV 0.92.1 2008.06.10 Trojan.Conhook-60
DrWeb 4.44.0.09170 2008.06.10 -
eSafe 7.0.15.0 2008.06.09 -
eTrust-Vet 31.6.5862 2008.06.10 -
Ewido 4.0 2008.06.10 -
F-Prot 4.4.4.56 2008.06.09 W32/Virtumonde.Y.gen!Eldorado
F-Secure 6.70.13260.0 2008.06.10 -
Fortinet 3.14.0.0 2008.06.10 -
GData 2.0.7306.1023 2008.06.10 Win32:Trojan-gen
Ikarus T3.1.1.26.0 2008.06.10 Trojan.Win32.Vundo.C
Kaspersky 7.0.0.125 2008.06.10 -
McAfee 5313 2008.06.09 -
Microsoft None 2008.06.10 -
NOD32v2 3172 2008.06.10 -
Norman 5.80.02 2008.06.09 -
Panda 9.0.0.4 2008.06.09 -
Prevx1 V2 2008.06.10 Fraudulent Security Program
Rising 20.48.12.00 2008.06.10 Trojan.Win32.VUNDO.bgj
Sophos 4.30.0 2008.06.10 -
Sunbelt 3.0.1145.1 2008.06.05 -
Symantec 10 2008.06.10 -
TheHacker 6.2.92.341 2008.06.10 -
VBA32 3.12.6.7 2008.06.10 -
VirusBuster 4.3.26:9 2008.06.09 -
Webwasher-Gateway 6.6.2 2008.06.10 Trojan.Dldr.ConHook.aku
weitere Informationen
File size: 33408 bytes
MD5...: 97f5abc910d7cbe8ec4c3d3564ec8e1d
SHA1..: c60fe21c91ef27efe51fc4d85fc74be96fdd388e
SHA256: 13fb0f3ee116d399c337b306e47eba30ba73d29183d67ca4cd65e93f51731801
SHA512: 52a34c5000d068a2fe4bd63494812b44221687c60bdbd798dddf353a31dbd762<br>193683703aab0cda3c8ff364afbb2d51d4fe7d3e7652b93072b0eccef0b4135a
PEiD..: Armadillo v1.xx - v2.xx
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x10001266<br>timedatestamp.....: 0x4821945b (Wed May 07 11:36:59 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 3 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x2000 0x2000 4.99 e747c95549706f9d2596c11f3d381118<br>.code 0x3000 0x2000 0x1800 1.79 675075c064019334b340cf3e65e411e5<br>.idata 0x5000 0xb000 0x4680 7.94 becaa212bb59fe3ac4312458faf28c15<br><br>( 3 imports ) <br>> kernel32.dll: ExitProcess, FindClose, FindFirstFileA, FreeLibrary, GetProcAddress, LoadLibraryA, UnhandledExceptionFilter, VirtualAlloc, VirtualFree, VirtualProtect, WriteFile<br>> user32.dll: BeginPaint, DestroyCursor, DestroyWindow, EndPaint, ExitWindowsEx, FindWindowExA, GetCapture, GetCursorPos, GetDC, GetSystemMetrics, GetWindow, GetWindowDC, GetWindowDC, GetWindowTextA, GetWindowTextLengthA, InvalidateRect, IsWindow, KillTimer, LoadCursorA, LoadIconA, LoadStringA, MessageBoxA, PeekMessageA, PostMessageA, PostQuitMessage, RegisterClassA<br>> gdi32.dll: CreateBrushIndirect, CreateCompatibleBitmap, CreateCompatibleDC, CreateDIBSection, CreateRectRgn, CreateSolidBrush, DeleteDC, DeleteObject, GetDeviceCaps, GetPixel, GetStockObject, MoveToEx, Rectangle, RestoreDC, SaveDC, SelectObject, SetBkColor, SetBkMode<br><br>( 0 exports ) <br>
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=ADDB073D80F184EB821D002DDDE82A0065A0E6BB
Code:
Datei boqnrwdmpbe.dll empfangen 2008.06.10 15:06:55 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.5.30.1 2008.06.10 -
AntiVir 7.8.0.55 2008.06.10 ADSPY/AdSpy.Gen
Authentium 5.1.0.4 2008.06.09 W32/Adware-RegBHO-based.1!Maximus
Avast 4.8.1195.0 2008.06.10 Win32:Vapsup-EB
AVG 7.5.0.516 2008.06.10 Downloader.Adload.MA
BitDefender 7.2 2008.06.10 -
CAT-QuickHeal 9.50 2008.06.09 Trojan.Vapsup.fzl
ClamAV 0.92.1 2008.06.10 -
DrWeb 4.44.0.09170 2008.06.10 -
eSafe 7.0.15.0 2008.06.09 Win32.Vapsup.fzl
eTrust-Vet 31.6.5862 2008.06.10 Win32/Pripecs!generic
Ewido 4.0 2008.06.10 -
F-Prot 4.4.4.56 2008.06.09 W32/Adware-RegBHO-based.1!Maximus
F-Secure 6.70.13260.0 2008.06.10 Trojan.Win32.Vapsup.fzl
Fortinet 3.14.0.0 2008.06.10 W32/Emogen.AC!tr
GData 2.0.7306.1023 2008.06.10 Trojan.Win32.Vapsup.fzl
Ikarus T3.1.1.26.0 2008.06.10 Virus.Win32.Vapsup.EB
Kaspersky 7.0.0.125 2008.06.10 Trojan.Win32.Vapsup.fzl
McAfee 5313 2008.06.09 -
Microsoft None 2008.06.10 -
NOD32v2 3172 2008.06.10 -
Norman 5.80.02 2008.06.09 -
Panda 9.0.0.4 2008.06.09 -
Prevx1 V2 2008.06.10 Fraudulent Security Program
Rising 20.48.12.00 2008.06.10 Trojan.Win32.Vapsup.elr
Sophos 4.30.0 2008.06.10 Mal/Emogen-AC
Sunbelt 3.0.1145.1 2008.06.05 Adware.NetAdware.Gen
Symantec 10 2008.06.10 Trojan.Fakeavalert
TheHacker 6.2.92.341 2008.06.10 Trojan/Vapsup.fzl
VBA32 3.12.6.7 2008.06.10 Trojan.Win32.Vapsup.fzl
VirusBuster 4.3.26:9 2008.06.09 -
Webwasher-Gateway 6.6.2 2008.06.10 Ad-Spyware.AdSpy.Gen
weitere Informationen
File size: 249856 bytes
MD5...: c79e80bc5cc76307d2e4fa29f8c186a5
SHA1..: df3d2f082609cfa7db6efd451d900ec1137424ad
SHA256: 97373ed48ac1c800a884646e28665c68f30a927d742c56c83845bf8b7da79cb5
SHA512: 838bc6e23656435bd81ddb9ad7887da134653b0bf6ddf744b6fca681277fb4b0<br>bf9f0b721f77d492511c2fc68c543579e01a817d23bc6d94711d53dd8d329245
PEiD..: -
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x1001457c<br>timedatestamp.....: 0x48425516 (Sun Jun 01 07:51:50 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x24cbb 0x25000 6.66 074ab00e77404ba01a01d44915be421c<br>.rdata 0x26000 0x10463 0x11000 4.55 ee89243248d215e010c9afa056dd656c<br>.data 0x37000 0x39a4 0x2000 3.89 93c91182f1cc9eeb89028ae3d49de07d<br>.rsrc 0x3b000 0xaf8 0x1000 3.33 cb760c9b78fd3c13f3478dbe68391c69<br>.reloc 0x3c000 0x2df0 0x3000 4.99 6c029566c8a6c24e5509063ce619c137<br><br>( 6 imports ) <br>> KERNEL32.dll: lstrcmpiW, MultiByteToWideChar, SizeofResource, LoadResource, FindResourceW, LoadLibraryExW, GetModuleHandleW, DisableThreadLibraryCalls, GetModuleFileNameW, RaiseException, GetLastError, EnterCriticalSection, FreeLibrary, DeleteCriticalSection, LeaveCriticalSection, GetProcAddress, LoadLibraryW, CloseHandle, CreateFileA, SetEndOfFile, WriteConsoleW, InterlockedDecrement, InterlockedIncrement, GlobalAlloc, Sleep, CreateThread, LocalAlloc, lstrlenW, FormatMessageW, InitializeCriticalSection, LocalFree, GetConsoleOutputCP, WriteConsoleA, FlushFileBuffers, SetStdHandle, CreateFileW, SetEnvironmentVariableW, SetEnvironmentVariableA, CompareStringW, CompareStringA, GetStringTypeW, GetStringTypeA, GetConsoleMode, GetConsoleCP, InterlockedExchange, GetACP, GetLocaleInfoA, GetThreadLocale, GetVersionExA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapReAlloc, HeapAlloc, HeapFree, VirtualProtect, VirtualAlloc, GetModuleHandleA, GetSystemInfo, VirtualQuery, GetCurrentThreadId, GetCommandLineA, GetProcessHeap, RtlUnwind, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, HeapSize, ExitProcess, HeapDestroy, HeapCreate, VirtualFree, WriteFile, GetStdHandle, GetModuleFileNameA, GetCPInfo, GetOEMCP, LCMapStringA, WideCharToMultiByte, LCMapStringW, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetFilePointer, ReadFile, SetHandleCount, GetFileType, GetStartupInfoA, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, LoadLibraryA<br>> USER32.dll: UnregisterClassA, MessageBoxW, CharNextW, ShowWindow<br>> ADVAPI32.dll: RegOpenKeyExW, RegQueryInfoKeyW, RegCloseKey, RegDeleteKeyW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegEnumKeyExW, RegQueryValueExW<br>> ole32.dll: CoTaskMemRealloc, CreateStreamOnHGlobal, CoTaskMemFree, CoTaskMemAlloc, StringFromGUID2, CoCreateInstance<br>> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -<br>> SHLWAPI.dll: StrToIntW<br><br>( 4 exports ) <br>DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer<br>
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=D5D648DA00E5F73AD0FC0396373A760065F71F27
Code:
Datei wxofsfif.dll empfangen 2008.06.10 15:09:00 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.5.30.1 2008.06.10 -
AntiVir 7.8.0.55 2008.06.10 TR/Vundo.ERH
Authentium 5.1.0.4 2008.06.09 -
Avast 4.8.1195.0 2008.06.10 Win32:Vundo@dll
AVG 7.5.0.516 2008.06.10 -
BitDefender 7.2 2008.06.10 Trojan.Vundo.ERH
CAT-QuickHeal 9.50 2008.06.09 -
ClamAV 0.92.1 2008.06.10 -
DrWeb 4.44.0.09170 2008.06.10 -
eSafe 7.0.15.0 2008.06.09 -
eTrust-Vet 31.6.5862 2008.06.10 -
Ewido 4.0 2008.06.10 -
F-Prot 4.4.4.56 2008.06.09 W32/Virtumonde.Y.gen!Eldorado
F-Secure 6.70.13260.0 2008.06.10 -
Fortinet 3.14.0.0 2008.06.10 -
GData 2.0.7306.1023 2008.06.10 Win32:Vundo
Ikarus T3.1.1.26.0 2008.06.10 Trojan.Win32.Vundo.E
Kaspersky 7.0.0.125 2008.06.10 -
McAfee 5313 2008.06.09 -
Microsoft None 2008.06.10 -
NOD32v2 3172 2008.06.10 -
Norman 5.80.02 2008.06.09 -
Panda 9.0.0.4 2008.06.09 Spyware/Virtumonde
Prevx1 V2 2008.06.10 Fraudulent Security Program
Rising 20.48.12.00 2008.06.10 -
Sophos 4.30.0 2008.06.10 Mal/Generic-A
Sunbelt 3.0.1145.1 2008.06.05 -
Symantec 10 2008.06.10 -
TheHacker 6.2.92.341 2008.06.10 -
VBA32 3.12.6.7 2008.06.10 -
VirusBuster 4.3.26:9 2008.06.09 -
Webwasher-Gateway 6.6.2 2008.06.10 Trojan.Vundo.ERH
weitere Informationen
File size: 95744 bytes
MD5...: 069c4ceff20f7da9c89834eb0701dcee
SHA1..: 4cd000f5bedd47714006d1d0533bfe0cce0d0f61
SHA256: 39e3a63458750c346fa512b43c7809f3f01d0f931423cfce54b834f2959477f9
SHA512: f71d006e44fdcc32affefbc0d228638fac5223d7f0a502a8eb6af325d1c100cc<br>ba445ec33ec674ec34c1bb6f92a5a6415f6d70610a1d0ecbc216cb4daeaba610
PEiD..: Armadillo v1.xx - v2.xx
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x100012b8<br>timedatestamp.....: 0x483c23d4 (Tue May 27 15:08:04 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 4 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x2000 0x2000 5.00 99b126dde8d72a325f1335c6ba429a20<br>BSS 0x3000 0x2000 0x1a00 2.20 b0086ce6eaeac67112e98093e213b083<br>CODE 0x5000 0x2000 0x1400 7.96 b0aa4c495dea6e1213d6e14355e4e1b1<br>.rsrc 0x7000 0x1f000 0x10a00 7.99 88bfce32d4156a181c30e49749f4cf6b<br><br>( 3 imports ) <br>> kernel32.dll: CloseHandle, CreateFileA, DeleteFileA, ExitProcess, FindClose, FindFirstFileA, FreeLibrary, GetCommandLineA, GetFileSize, GetFileType, GetLastError, GetModuleFileNameA, GetModuleHandleA, GetProcAddress, LoadLibraryA, lstrcpyn, OpenMutexA, OpenProcess, ReadFile, ResumeThread, SetEndOfFile, SetFilePointer, Sleep, TerminateThread, UnhandledExceptionFilter, VirtualAlloc, VirtualFree, VirtualProtect, WaitForSingleObject, WinExec, WriteFile<br>> user32.dll: BeginPaint, BeginPaint, CheckMenuRadioItem, CheckRadioButton, CreateMenu, CreateWindowExA, DestroyCursor, DestroyWindow, EndPaint, GetWindowDC, PeekMessageA, PostMessageA, PostQuitMessage, RegisterClassA, ReleaseCapture, ReleaseDC, SendMessageA, SetCursor, SetForegroundWindow, SetMenu, SetMenuItemInfoA, SetPropA, SetScrollPos, SetScrollRange, SetSysColors, SetTimer, SetWindowLongA, SetWindowPos, ShowWindow, SystemParametersInfoA, TranslateMessage, UpdateWindow, ValidateRect, WaitMessage, wvsprintfA<br>> gdi32.dll: CombineRgn, CreateBrushIndirect, CreateCompatibleBitmap, CreateCompatibleDC, CreateDIBSection, CreateRectRgn, CreateSolidBrush, DeleteDC, DeleteObject, GetDeviceCaps, GetPixel, GetStockObject, MoveToEx, Rectangle, RestoreDC<br><br>( 0 exports ) <br>
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=319737F8006159E77691012DDDE82A002A87B378
C:\WINDOWS\system32\xxGMnUvw.ini2 habe ich nicht gefunden
C:\WINDOWS\system32\QXbayyxx.ini2 habe ich nicht gefunden
C:\WINDOWS\system32\GhgOonnn.ini2 habe ich nicht gefunden
Code:
Datei mlJBQKCS.dll empfangen 2008.06.10 15:14:31 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.5.30.1 2008.06.10 -
AntiVir 7.8.0.55 2008.06.10 TR/Vundo.HG
Authentium 5.1.0.4 2008.06.09 -
Avast 4.8.1195.0 2008.06.10 Win32:Trojan-gen {Other}
AVG 7.5.0.516 2008.06.10 Generic10.AIJD
BitDefender 7.2 2008.06.10 Trojan.Vundo.EPZ
CAT-QuickHeal 9.50 2008.06.09 -
ClamAV 0.92.1 2008.06.10 -
DrWeb 4.44.0.09170 2008.06.10 -
eSafe 7.0.15.0 2008.06.09 -
eTrust-Vet 31.6.5862 2008.06.10 Win32/Vundo.ABZ
Ewido 4.0 2008.06.10 -
F-Prot 4.4.4.56 2008.06.09 W32/Virtumonde.Y.gen!Eldorado
F-Secure 6.70.13260.0 2008.06.10 -
Fortinet 3.14.0.0 2008.06.10 -
GData 2.0.7306.1023 2008.06.10 Win32:Trojan-gen
Ikarus T3.1.1.26.0 2008.06.10 Trojan.Vundo.EPZ
Kaspersky 7.0.0.125 2008.06.10 -
McAfee 5313 2008.06.09 -
Microsoft None 2008.06.10 -
NOD32v2 3172 2008.06.10 -
Norman 5.80.02 2008.06.09 W32/Virtumonde.WTH
Panda 9.0.0.4 2008.06.09 Spyware/Virtumonde
Prevx1 V2 2008.06.10 Fraudulent Security Program
Rising 20.48.12.00 2008.06.10 Trojan.Win32.Virtumod.al
Sophos 4.30.0 2008.06.10 -
Sunbelt 3.0.1145.1 2008.06.05 -
Symantec 10 2008.06.10 Trojan.Vundo
TheHacker 6.2.92.341 2008.06.10 -
VBA32 3.12.6.7 2008.06.10 -
VirusBuster 4.3.26:9 2008.06.09 -
Webwasher-Gateway 6.6.2 2008.06.10 Trojan.Vundo.HG
weitere Informationen
File size: 33408 bytes
MD5...: 39b234aa148ee339813697b025e3e2c7
SHA1..: 1ae300edec0202543e6972f03e6a82d8bda63290
SHA256: ea63cbcd463615a9f4524d354aab4c676b46953deba5dd773b9bfd94442ffae5
SHA512: 16ce3de66d2a027819c3a46e8a888847c685d0e4220ba317d4c7f4f29a42ac67<br>346aec3d076693bb114c4ca11f1bfa89ca75c89dc39a6aec7a9a565ec168c747
PEiD..: Armadillo v1.xx - v2.xx
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x1000106c<br>timedatestamp.....: 0x4821945b (Wed May 07 11:36:59 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x2000 0x2000 5.03 59a49d0bf0c4009555cdc007723df394<br>BSS 0x3000 0x2000 0x1800 2.16 35dfc25d4b7eb3a1f8572f1add53acbc<br>CODE 0x5000 0x1000 0xa00 7.93 112bfd01851c30793eceaa655c2b63bf<br>BSS 0x6000 0x2000 0x1600 7.96 fbdfde627d250cd6e527ca6dae707ecc<br>.data 0x8000 0x8000 0x2680 7.87 6f9dfa415809f4ffbd6d21a9811a7692<br><br>( 5 imports ) <br>> kernel32.dll: CloseHandle, CreateFileA, DeleteCriticalSection, DeleteFileA, EnterCriticalSection, GetFileSize, GetFileType, GetProcAddress, InitializeCriticalSection, LeaveCriticalSection, LoadLibraryA, OpenMutexA, OpenProcess, ResumeThread, Sleep, TerminateThread, VirtualAlloc, VirtualFree, VirtualProtect, WaitForSingleObject, WinExec<br>> user32.dll: BeginPaint, GetCapture, GetCursorPos, GetDC, GetSystemMetrics, GetWindow, GetWindowDC, GetWindowDC, GetWindowTextA, GetWindowTextLengthA, InvalidateRect, IsWindow, KillTimer, LoadCursorA, LoadIconA, LoadStringA, MessageBoxA, PeekMessageA, PostMessageA, PostQuitMessage<br>> gdi32.dll: CombineRgn, CreateBrushIndirect, CreateCompatibleBitmap, CreateCompatibleDC, CreateDIBSection, CreateRectRgn, CreateSolidBrush, DeleteDC, DeleteObject, GetDeviceCaps, GetPixel, GetStockObject, MoveToEx, Rectangle, RestoreDC, SaveDC, SelectObject, SetBkColor, SetBkMode, SetBrushOrgEx, SetPixel, StretchBlt, TextOutA<br>> shell32.dll: DragAcceptFiles, SHBrowseForFolder<br>> comdlg32.dll: ChooseColorA, ChooseFontA, GetSaveFileNameA<br><br>( 0 exports ) <br>
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=AFAFA67F802439F282A0002DDDE82A0001C00E9E
Code:
Datei ljJCtuUL.dll empfangen 2008.06.10 15:16:23 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.5.30.1 2008.06.10 -
AntiVir 7.8.0.55 2008.06.10 TR/Vundo.HG
Authentium 5.1.0.4 2008.06.09 -
Avast 4.8.1195.0 2008.06.10 Win32:Trojan-gen {Other}
AVG 7.5.0.516 2008.06.10 Generic10.AIJD
BitDefender 7.2 2008.06.10 Trojan.Vundo.EPZ
CAT-QuickHeal 9.50 2008.06.09 -
ClamAV 0.92.1 2008.06.10 -
DrWeb 4.44.0.09170 2008.06.10 -
eSafe 7.0.15.0 2008.06.09 -
eTrust-Vet 31.6.5862 2008.06.10 Win32/Vundo.ABZ
Ewido 4.0 2008.06.10 -
F-Prot 4.4.4.56 2008.06.09 W32/Virtumonde.Y.gen!Eldorado
F-Secure 6.70.13260.0 2008.06.10 -
Fortinet 3.14.0.0 2008.06.10 -
GData 2.0.7306.1023 2008.06.10 Win32:Trojan-gen
Ikarus T3.1.1.26.0 2008.06.10 Trojan.Vundo.EPZ
Kaspersky 7.0.0.125 2008.06.10 -
McAfee 5313 2008.06.09 -
Microsoft None 2008.06.10 -
NOD32v2 3172 2008.06.10 -
Norman 5.80.02 2008.06.09 W32/Virtumonde.WTH
Panda 9.0.0.4 2008.06.09 Spyware/Virtumonde
Prevx1 V2 2008.06.10 Fraudulent Security Program
Rising 20.48.12.00 2008.06.10 Trojan.Win32.Virtumod.al
Sophos 4.30.0 2008.06.10 -
Sunbelt 3.0.1145.1 2008.06.05 -
Symantec 10 2008.06.10 Trojan.Vundo
TheHacker 6.2.92.341 2008.06.10 -
VBA32 3.12.6.7 2008.06.10 -
VirusBuster 4.3.26:9 2008.06.09 -
Webwasher-Gateway 6.6.2 2008.06.10 Trojan.Vundo.HG
weitere Informationen
File size: 33408 bytes
MD5...: 8c45b3bd39860a7d63f1dfff88f513a4
SHA1..: a135739a750bfd4a932cc884aab94ccd9089175a
SHA256: 7911a1e355d66874231c6bdcf414ee667a4c55deb2e2d463a9284ce1e1b1d566
SHA512: cd0e4f480e33da7ff182b5bef7f645297846f4863d14fa4e5eac43f139993d0b<br>b625b7d8cd37a4fd66e80c537dc5c17a040d773cfc9333fadc1a5e09e2a1c9cd
PEiD..: Armadillo v1.xx - v2.xx
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x1000106c<br>timedatestamp.....: 0x4821945b (Wed May 07 11:36:59 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x2000 0x2000 5.03 59a49d0bf0c4009555cdc007723df394<br>BSS 0x3000 0x2000 0x1800 2.16 35dfc25d4b7eb3a1f8572f1add53acbc<br>CODE 0x5000 0x1000 0xa00 7.93 112bfd01851c30793eceaa655c2b63bf<br>BSS 0x6000 0x2000 0x1600 7.96 fbdfde627d250cd6e527ca6dae707ecc<br>.data 0x8000 0x8000 0x2680 7.87 7859cffa083f84da64413e7e14b53729<br><br>( 5 imports ) <br>> kernel32.dll: CloseHandle, CreateFileA, DeleteCriticalSection, DeleteFileA, EnterCriticalSection, GetFileSize, GetFileType, GetProcAddress, InitializeCriticalSection, LeaveCriticalSection, LoadLibraryA, OpenMutexA, OpenProcess, ResumeThread, Sleep, TerminateThread, VirtualAlloc, VirtualFree, VirtualProtect, WaitForSingleObject, WinExec<br>> user32.dll: BeginPaint, GetCapture, GetCursorPos, GetDC, GetSystemMetrics, GetWindow, GetWindowDC, GetWindowDC, GetWindowTextA, GetWindowTextLengthA, InvalidateRect, IsWindow, KillTimer, LoadCursorA, LoadIconA, LoadStringA, MessageBoxA, PeekMessageA, PostMessageA, PostQuitMessage<br>> gdi32.dll: CombineRgn, CreateBrushIndirect, CreateCompatibleBitmap, CreateCompatibleDC, CreateDIBSection, CreateRectRgn, CreateSolidBrush, DeleteDC, DeleteObject, GetDeviceCaps, GetPixel, GetStockObject, MoveToEx, Rectangle, RestoreDC, SaveDC, SelectObject, SetBkColor, SetBkMode, SetBrushOrgEx, SetPixel, StretchBlt, TextOutA<br>> shell32.dll: DragAcceptFiles, SHBrowseForFolder<br>> comdlg32.dll: ChooseColorA, ChooseFontA, GetSaveFileNameA<br><br>( 0 exports ) <br>
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=AFAFA67F802439F282A0002DDDE82A00288738BE
Code:
Datei enqf.exe empfangen 2008.06.10 15:17:42 (CET)
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.5.30.1 2008.06.10 -
AntiVir 7.8.0.55 2008.06.10 ADSPY/Vapsup.dco
Authentium 5.1.0.4 2008.06.09 -
Avast 4.8.1195.0 2008.06.10 Win32:Vapsup-BO
AVG 7.5.0.516 2008.06.10 Downloader.Adload.LA
BitDefender 7.2 2008.06.10 -
CAT-QuickHeal 9.50 2008.06.09 Trojan.Vapsup.fzb
ClamAV 0.92.1 2008.06.10 -
DrWeb 4.44.0.09170 2008.06.10 Trojan.Popuper.6130
eSafe 7.0.15.0 2008.06.09 Win32.Vapsup.gas
eTrust-Vet 31.6.5862 2008.06.10 Win32/Pripecs!generic
Ewido 4.0 2008.06.10 -
F-Prot 4.4.4.56 2008.06.09 -
F-Secure 6.70.13260.0 2008.06.10 Trojan.Win32.Vapsup.gas
Fortinet 3.14.0.0 2008.06.10 W32/Vapsup.GAS!tr
GData 2.0.7306.1023 2008.06.10 Trojan.Win32.Vapsup.gas
Ikarus T3.1.1.26.0 2008.06.10 Virus.Win32.Vapsup.BO
Kaspersky 7.0.0.125 2008.06.10 Trojan.Win32.Vapsup.gas
McAfee 5313 2008.06.09 -
Microsoft None 2008.06.10 -
NOD32v2 3172 2008.06.10 -
Norman 5.80.02 2008.06.09 -
Panda 9.0.0.4 2008.06.09 Adware/VapSup
Prevx1 V2 2008.06.10 -
Rising 20.48.12.00 2008.06.10 Trojan.Win32.Undef.hje
Sophos 4.30.0 2008.06.10 -
Sunbelt 3.0.1145.1 2008.06.05 Adware.NetAdware.Gen
Symantec 10 2008.06.10 -
TheHacker 6.2.92.341 2008.06.10 Trojan/Vapsup.gas
VBA32 3.12.6.7 2008.06.10 Trojan.Popuper.6130
VirusBuster 4.3.26:9 2008.06.09 -
Webwasher-Gateway 6.6.2 2008.06.10 Ad-Spyware.Vapsup.dco
weitere Informationen
File size: 94208 bytes
MD5...: fc7c4a8a85aaec4e64c734ba8c23ecfd
SHA1..: d51aa73ae3bbe5b1ad00f2af626609b9e90d8cc0
SHA256: 5bd1eb434e7adcf49d6da619e77c341f4dad61fa306669fa219702414edc77dc
SHA512: 6d71b82aa3cf7cfc49be3a6a03ebf712dddd6db7eb7388d0260fe7d05f9a955f<br>de278633a7193aee2a7795607ed8deca3cd122014540683b0c5fd9604c9d2aa0
PEiD..: -
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x404f76<br>timedatestamp.....: 0x483e82e1 (Thu May 29 10:18:09 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 4 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0xd05f 0xe000 6.34 a93daa64328dada62c03e2340e4aea11<br>.rdata 0xf000 0x4160 0x5000 4.64 85c1dd11919feb70cc3eb032f7c07ec6<br>.data 0x14000 0x2e04 0x2000 1.51 9a7aa8c78256cab9ff17ed7f006d8417<br>.rsrc 0x17000 0xb0 0x1000 3.06 c67885160d1d4da2f4a5f0d18956abe6<br><br>( 2 imports ) <br>> KERNEL32.dll: LoadLibraryW, SetLastError, CloseHandle, GetLastError, GetProcAddress, OpenProcess, FreeLibrary, GetCurrentProcessId, MultiByteToWideChar, TerminateProcess, RaiseException, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlUnwind, EnterCriticalSection, LeaveCriticalSection, HeapFree, GetCommandLineA, GetVersionExA, HeapAlloc, GetProcessHeap, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, GetCurrentThreadId, InterlockedDecrement, Sleep, HeapSize, ExitProcess, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, DeleteCriticalSection, GetCPInfo, GetACP, GetOEMCP, LCMapStringA, WideCharToMultiByte, LCMapStringW, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, WriteFile, GetModuleFileNameA, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, LoadLibraryA, InitializeCriticalSection, SetStdHandle, GetConsoleCP, GetConsoleMode, FlushFileBuffers, SetFilePointer, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA<br>> ADVAPI32.dll: RegSetValueExW<br><br>( 0 exports ) <br>