瑞星卡卡安全论坛

首页 » 技术交流区 » 可疑文件交流 » hatben.dll
endurer - 2009-3-2 12:44:00

 附件: 您所在的用户组无法下载或查看附件



解压密码:virus


文件说明符 : C:\WINDOWS\hatben.dll
属性 : -SH-
数字签名:否
PE文件:是
语言 : 中文(中国)
文件版本 : 1, 0, 2, 1
说明 : Microsoft WinEvent Support
版权 : Copyright ? 2002
备注 : Microsoft WinEvent
产品版本 : 1, 0, 2, 1
产品名称 : Microsoft(R) Windows(R) Operating System
公司名称 :  Microsoft Corporation
内部名称 : wthelp
源文件名 : wthelp.dll
创建时间 : 2009-2-23 9:46:19
修改时间 : 2009-2-23 9:46:20
大小 : 45056 字节 44.0 KB
MD5 : 324dcaf42ee74c1b1491a0492a67abcb
SHA1: 49E5475BBCDB3D1A7B4C678292163D067C262CF7
CRC32: 8ef0bc80

文件 hatben.dll 接收于 2009.03.02 05:21:34 (CET)
反病毒引擎版本最后更新扫描结果
a-squared4.0.0.1012009.03.02Trojan.Generic!IK
AhnLab-V35.0.0.22009.02.27-
AntiVir7.9.0.982009.03.01TR/Gendal.45056.5
Authentium5.1.0.42009.03.01-
Avast4.8.1335.02009.03.01Win32:Trojan-gen {Other}
AVG8.0.0.2372009.03.01Clicker.KVF
BitDefender7.22009.03.02Trojan.Generic.338183
CAT-QuickHealNone2009.02.28-
ClamAV0.94.12009.03.02-
Comodo9862009.02.20-
DrWeb4.44.0.091702009.03.02Trojan.DownLoader.36054
eSafe7.0.17.02009.02.26-
eTrust-Vet31.6.63792009.03.02-
F-Prot4.4.4.562009.03.01-
F-Secure8.0.14470.02009.03.01-
Fortinet3.117.0.02009.03.02Adware/AdClicker
GData192009.03.02Trojan.Generic.338183
IkarusT3.1.1.45.02009.03.02Trojan.Generic
K7AntiVirus7.10.6492009.02.27Trojan.Win32.Malware.1
Kaspersky7.0.0.1252009.03.02-
McAfee55402009.03.01AdClicker-ET
McAfee+Artemis55402009.03.01AdClicker-ET
Microsoft1.43062009.03.01-
NOD3238992009.03.02probably a variant of Win32/TrojanClicker.Agent
Norman6.00.062009.02.27-
nProtect2009.1.8.02009.03.02Trojan/W32.Small.45056.AG
Panda10.0.0.102009.03.01Generic Trojan
PCTools4.4.2.02009.03.01-
Prevx1V22009.03.02Medium Risk Malware
Rising21.19.00.002009.03.02-
SecureWeb-Gateway6.7.62009.03.02Trojan.Gendal.45056.5
Sophos4.39.02009.03.02-
Sunbelt3.2.1858.22009.02.28-
Symantec102009.03.02Trojan Horse
TheHacker6.3.2.6.2682009.03.01-
TrendMicro8.700.0.10042009.03.02TROJ_CLICKER.BRQ
VBA323.12.10.12009.03.01Trojan.DownLoader.36054
ViRobot2009.2.28.16292009.03.02-
VirusBuster4.5.11.02009.03.01-

附加信息
File size: 45056 bytes
MD5...: 324dcaf42ee74c1b1491a0492a67abcb
SHA1..: 49e5475bbcdb3d1a7b4c678292163d067c262cf7
SHA256: 84a65d9161979f4f695fde29eb0c2639e1e8aab385fada4fdd06e55d5d31e0ab
SHA512: c973f0f20c7162176c6891a0dd55d419f9deb9b6af3942acd9d59e3ab5418b30
5bf09396938a36d5924c0cedbf3a32880c4d45603cdca6d9becc1f010b3fae95
ssdeep: 768:QxhT8nf2/WPsTt3KWgBTWu3Io9X8j9FmBX:QxhT8OqsZKxbYoF8j9IBX
PEiD..: Armadillo v1.xx - v2.xx
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x13b9
timedatestamp.....: 0x478cd644 (Tue Jan 15 15:50:28 2008)
machinetype.......: 0x14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3ccc 0x4000 6.33 ea1e7c233261cfc18a53f6d8e0918c3e
.rdata 0x5000 0x1b08 0x2000 4.36 f1c22b52bf870a7fd13c14e3349c9b5c
.data 0x7000 0x940 0x1000 0.79 22b826ad68012b30852118c238308dcd
WTShared 0x8000 0x4 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rsrc 0x9000 0x438 0x1000 1.10 3cb88c9f7f329cedec7bcb4524d28313
.reloc 0xa000 0xa62 0x1000 4.15 2f0a3268cc1d39a2fd87ec0cf8d4d871

( 2 imports )
> KERNEL32.dll: VirtualQuery, OpenProcess, SetLastError, CreateFileA, UnmapViewOfFile, CloseHandle, MapViewOfFile, OpenFileMappingA, FlushInstructionCache, VirtualProtect, RtlUnwind, GetStringTypeW, GetStringTypeA, LCMapStringW, GetCommandLineA, GetVersion, ExitProcess, TerminateProcess, GetCurrentProcess, GetCurrentThreadId, TlsSetValue, TlsAlloc, TlsFree, TlsGetValue, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, DeleteCriticalSection, GetModuleFileNameA, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStrings, GetEnvironmentStringsW, HeapDestroy, HeapCreate, VirtualFree, HeapFree, WriteFile, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, HeapAlloc, GetCPInfo, GetACP, GetOEMCP, VirtualAlloc, HeapReAlloc, GetProcAddress, LoadLibraryA, MultiByteToWideChar, LCMapStringA
> USER32.dll: GetWindowTextA, GetWindowThreadProcessId, SetWindowsHookExA, UnhookWindowsHookEx, CallNextHookEx, FindWindowA

( 1 exports )
StartWTHelp
Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=84C47A3F00FC9A1CB07600EA61BCB7008DB501A8' target='_blank'>http://info.prevx.com/aboutprogr ... 61BCB7008DB501A8<;/a>
CWSandbox info: <a href='http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=324dcaf42ee74c1b1491a0492a67abcb' target='_blank'>http://research.sunbelt-software ... 1491a0492a67abcb<;/a>


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; QQDownload 1.7; InfoPath.1)
RisingCSC - 2009-3-2 13:31:00
感谢您对瑞星的支持,您所上报的文件已经收集,我们会抓紧分析并跟帖回复。
RisingCSC - 2009-3-3 9:46:00
经过分析,您所上报的文件不是病毒。
1
查看完整版本: hatben.dll