Code:
Datei kbdir32.dll empfangen 2010.07.11 14:35:04 (UTC)
Antivirus Version letzte aktualisierung Ergebnis
a-squared 5.0.0.31 2010.07.11 Trojan.SuspectCRC!IK
AhnLab-V3 2010.07.10.00 2010.07.09 -
AntiVir 8.2.4.10 2010.07.09 -
Antiy-AVL 2.0.3.7 2010.07.09 -
Authentium 5.2.0.5 2010.07.10 -
Avast 4.8.1351.0 2010.07.11 -
Avast5 5.0.332.0 2010.07.11 -
AVG 9.0.0.836 2010.07.11 -
BitDefender 7.2 2010.07.11 Trojan.Generic.4342427
CAT-QuickHeal 11.00 2010.07.10 Trojan.Agent.ATV
ClamAV 0.96.0.3-git 2010.07.11 -
Comodo 5393 2010.07.11 -
DrWeb 5.0.2.03300 2010.07.11 -
eSafe 7.0.17.0 2010.07.11 -
eTrust-Vet 36.1.7696 2010.07.10 -
F-Prot 4.6.1.107 2010.07.10 -
F-Secure 9.0.15370.0 2010.07.11 Trojan.Generic.4342427
Fortinet 4.1.143.0 2010.07.11 -
GData 21 2010.07.11 Trojan.Generic.4342427
Ikarus T3.1.1.84.0 2010.07.11 Trojan.SuspectCRC
Jiangmin 13.0.900 2010.07.11 -
Kaspersky 7.0.0.125 2010.07.11 -
McAfee 5.400.0.1158 2010.07.11 -
McAfee-GW-Edition 2010.1 2010.07.05 Heuristic.BehavesLike.Win32.PasswordStealer.H
Microsoft 1.5902 2010.07.11 -
NOD32 5269 2010.07.11 -
Norman 6.05.11 2010.07.11 -
nProtect 2010-07-11.01 2010.07.11 Trojan.Generic.4342427
Panda 10.0.2.7 2010.07.11 -
PCTools 7.0.3.5 2010.07.11 -
Prevx 3.0 2010.07.11 High Risk Cloaked Malware
Rising 22.55.04.04 2010.07.09 -
Sophos 4.55.0 2010.07.11 Troj/Phagen-Gen
Sunbelt 6566 2010.07.10 Trojan.Win32.Generic!BT
Symantec 20101.1.0.89 2010.07.11 -
TheHacker 6.5.2.1.311 2010.07.11 -
TrendMicro 9.120.0.1004 2010.07.11 -
TrendMicro-HouseCall 9.120.0.1004 2010.07.11 -
VBA32 3.12.12.6 2010.07.09 -
ViRobot 2010.6.29.3912 2010.07.11 -
VirusBuster 5.0.27.0 2010.07.10 Trojan.Agent.OSQS
weitere Informationen
File size: 22016 bytes
MD5...: b78b963089ba3384a0b88a2daaf27232
SHA1..: f6970f3e13ab93e73cdf12d8fa7c59471255f484
SHA256: 0c58391cce7f9fcbd09dad9397f640c2de864e1b2e0ac9c3ae910ba81a51fdbf
ssdeep: 384:IsMgKQgYk1hTwiaCgBnBln6XnTXiVZpEPZRFICxK8rzo:IsMgpgPwiaCgP16<br>SEhRFFTk<br>
PEiD..: -
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x4b8f<br>timedatestamp.....: 0x74edaad5 (Mon Mar 01 05:47:01 2032)<br>machinetype.......: 0x14c (I386)<br><br>( 4 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x46e2 0x4800 6.31 5b7151230bd2a97b7b15de9db9b4d47a<br>.data 0x6000 0xc4 0x200 0.18 4a86b5fa947b0886c1a3bdb9ac73b3bb<br>.rsrc 0x7000 0x2e0 0x400 2.33 cf5d7e36470214ed74cb6572b3645b7d<br>.reloc 0x8000 0x27a 0x400 3.60 c3ccfdf825fcbee521680d0a792c6bcb<br><br>( 5 imports ) <br>> ADVAPI32.dll: RegQueryValueExA, RegOpenKeyExA, GetUserNameA, RegCloseKey<br>> USER32.dll: CharNextA, LoadStringA, CharUpperA, wvsprintfA, CharLowerA<br>> KERNEL32.dll: GetModuleFileNameW, lstrcpyW, SystemTimeToFileTime, GetFileTime, GetSystemTime, DisableThreadLibraryCalls, GetTickCount, GetVersionExA, VirtualFree, WaitForSingleObject, IsBadReadPtr, GetModuleFileNameA, InterlockedIncrement, lstrlenA, lstrlenW, InterlockedDecrement, GetStringTypeExA, GetThreadLocale, CloseHandle, ReadFile, GetFileSize, CreateFileA, GetCurrentProcess, GetProcAddress, GetModuleHandleA, VirtualAlloc, WriteProcessMemory, VirtualAllocEx, LoadLibraryA, CreateRemoteThread, VirtualProtect, lstrcmpA, Sleep, MoveFileExA, GetVolumeInformationA, FreeLibrary, GetComputerNameA, CreateThread, FreeLibraryAndExitThread<br>> WININET.dll: InternetGetConnectedState, InternetCanonicalizeUrlA, InternetCrackUrlA, InternetOpenA, InternetConnectA, HttpOpenRequestA, HttpSendRequestA, InternetQueryDataAvailable, InternetReadFile, InternetCloseHandle, InternetCheckConnectionA<br>> MSVCRT.dll: __2@YAPAXI@Z, realloc, __3@YAXPAX@Z, memset, _except_handler3, _adjust_fdiv, malloc, _initterm, free, memcpy<br><br>( 31 exports ) <br>TSPI_lineAnswer, TSPI_lineClose, TSPI_lineDial, TSPI_lineDrop, TSPI_lineGetAddressCaps, TSPI_lineGetAddressID, TSPI_lineGetAddressStatus, TSPI_lineGetCallInfo, TSPI_lineGetCallStatus, TSPI_lineGetDevCaps, TSPI_lineGetDevConfig, TSPI_lineGetID, TSPI_lineGetIcon, TSPI_lineGetLineDevStatus, TSPI_lineGetNumAddressIDs, TSPI_lineMakeCall, TSPI_lineNegotiateTSPIVersion, TSPI_lineOpen, TSPI_lineSetAppSpecific, TSPI_lineSetDevConfig, TSPI_lineSetStatusMessages, TSPI_phoneNegotiateTSPIVersion, TSPI_providerEnumDevices, TSPI_providerGenericDialogData, TSPI_providerInit, TSPI_providerInstall, TSPI_providerShutdown, TSPI_providerUIIdentify, TUISPI_lineConfigDialog, TUISPI_lineConfigDialogEdit, TUISPI_providerInstall<br>
RDS...: NSRL Reference Data Set<br>-
pdfid.: -
trid..: Win32 Executable MS Visual C++ (generic) (65.2%)<br>Win32 Executable Generic (14.7%)<br>Win32 Dynamic Link Library (generic) (13.1%)<br>Generic Win/DOS Executable (3.4%)<br>DOS Executable Generic (3.4%)
<a href='http://info.prevx.com/aboutprogramtext.asp?PX5=D4C94B090045866356B6004EF2C870001B7CC320' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=D4C94B090045866356B6004EF2C870001B7CC320</a>
sigcheck:<br>publisher....: <br>copyright....: <br>product......: <br>description..: <br>original name: <br>internal name: <br>file version.: 1.0<br>comments.....: <br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
Die Log von Panda: