瑞星卡卡安全论坛

首页 » 技术交流区 » 可疑文件交流 » e54.dll---adcf542a58f026d5819de1844946ba5e
endurer - 2009-10-16 22:05:00

 附件: 您所在的用户组无法下载或查看附件

解压密码:virus

O2 - BHO BHO Class - {AA3D3193-E700-4087-BD8B-CDC2CDC0820F} = C:\WINDOWS\system32\e54.dll



文件说明符 : C:\WINDOWS\system32\e54.dll
属性 : A---
数字签名:否
PE文件:是
语言 : 英语(美国)
文件版本 : 1, 0, 2, 8
说明 : Transaction Module
版权 : Copyright 2006
备注 : Microsoft Corporation
产品版本 : 1, 0, 2, 8
产品名称 : Flacdker Product
公司名称 : Microsoft Corporation
内部名称 : COM Services
源文件名 : COM Services
创建时间 : 2009-10-16 21:14:8
修改时间 : 2009-10-12 8:45:0
大小 : 36864 字节 36.0 KB
MD5 : adcf542a58f026d5819de1844946ba5e
SHA1: A9015DAE74731B92EC60C6F07E4A5942CFBA7604
CRC32: 569e90ba
文件 e54.dll 接收于 2009.10.16 13:55:18 (UTC)
反病毒引擎版本最后更新扫描结果
a-squared4.5.0.412009.10.16AdWare.Bdsearch!IK
AhnLab-V35.0.0.22009.10.16-
AntiVir7.9.1.352009.10.16-
Antiy-AVL2.0.3.72009.10.16AdWare/Win32.BHO.gen
Authentium5.1.2.42009.10.16-
Avast4.8.1351.02009.10.14Win32:BHO-XK
AVG8.5.0.4202009.10.16Generic4.OHD
BitDefender7.22009.10.16Gen:Adware.Heur.cu8@A8haDCab
CAT-QuickHeal10.002009.10.16-
ClamAV0.94.12009.10.16-
Comodo26212009.10.16-
DrWeb5.0.0.121822009.10.16-
eSafe7.0.17.02009.10.15Win32.Adclicker
eTrust-Vet35.1.70712009.10.16-
F-Prot4.5.1.852009.10.15-
F-Secure8.0.14470.02009.10.16AdWare.Win32.BHO.iwa
Fortinet3.120.0.02009.10.16-
GData192009.10.16Gen:Adware.Heur.cu8@A8haDCab
IkarusT3.1.1.72.02009.10.16AdWare.Bdsearch
Jiangmin11.0.8002009.10.16Adware/BHO.qz
K7AntiVirus7.10.8722009.10.16-
Kaspersky7.0.0.1252009.10.16not-a-virus:AdWare.Win32.BHO.iwa
McAfee57722009.10.15Generic PWS!hv.ah
McAfee+Artemis57722009.10.15Artemis!ADCF542A58F0
McAfee-GW-Edition6.8.52009.10.16-
Microsoft1.51012009.10.16-
NOD3245142009.10.16-
Norman6.03.022009.10.16-
nProtect2009.1.8.02009.10.15Trojan-Clicker/W32.BHO.36864.CR
Panda10.0.2.22009.10.15Trj/CI.A
PCTools4.4.2.02009.10.16-
Prevx3.02009.10.16Medium Risk Malware
Rising21.51.44.002009.10.16-
Sophos4.46.02009.10.16-
Sunbelt3.2.1858.22009.10.15-
Symantec1.4.4.122009.10.16Trojan.Adclicker
TheHacker6.5.0.2.0432009.10.15-
TrendMicro8.950.0.10942009.10.16-
VBA323.12.10.112009.10.15AdWare.Win32.BHO.iwa
ViRobot2009.10.16.19882009.10.16-
VirusBuster4.6.5.02009.10.15-

附加信息
File size: 36864 bytes
MD5...: adcf542a58f026d5819de1844946ba5e
SHA1..: a9015dae74731b92ec60c6f07e4a5942cfba7604
SHA256: 7847b3cbe5cd013554ee4a5cacc6b584f399cd04dc4e256a2531d236a2fa3a28
ssdeep: 384:XAWGdzwoT77MeIcgTHRTHAnZbARpI5pAWS0Eo3gQ:tozwmdURTHAZbARpapt
hg
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x38a3
timedatestamp.....: 0x4ac54a37 (Fri Oct 02 00:32:55 2009)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x2b56 0x3000 5.89 ef17b40a04182ac076d8ecbbc334d85a
.rdata 0x4000 0x111e 0x2000 3.13 303f5715b1bb0e440de516ee229506dd
.data 0x6000 0x1864 0x1000 1.80 ef3b419523d7ead49fbaaa19500e25d8
.rsrc 0x8000 0xe30 0x1000 3.95 5415be4baa86fc6de2277a09cbbf89ae
.reloc 0x9000 0x898 0x1000 3.37 78e8fab4b81c496c2dfbad5ccdc8a63e

( 8 imports )
> MFC42.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> MSVCRT.dll: strcpy, wcslen, _CxxThrowException, sscanf, _strnicmp, sprintf, strstr, strlen, memcmp, __CxxFrameHandler, _purecall, _mbslwr, __1type_info@@UAE@XZ, _adjust_fdiv, malloc, _initterm, free, _strlwr, _except_handler3, _onexit, __dllonexit, _mbsstr, memcpy, _terminate@@YAXXZ
> KERNEL32.dll: CreateEventA, CreateThread, Sleep, SetEvent, lstrlenW, InterlockedDecrement, EnterCriticalSection, InterlockedIncrement, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection, GetModuleFileNameA, WaitForSingleObject, CreateFileMappingA, MultiByteToWideChar, GetLastError, WideCharToMultiByte, LocalFree, LocalAlloc
> USER32.dll: SendMessageA, FindWindowExA, IsCharAlphaNumericA
> ADVAPI32.dll: RegNotifyChangeKeyValue
> OLEAUT32.dll: -, -, -, -, -, -, -, -
> ATL.DLL: -, -, -, -, -, -, -, -, -, -
> MSVCP60.dll: __Tidy@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEX_N@Z, _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, __1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ, __Hstd@@YA_AV_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@0@ABV10@PBD@Z, __C@_1___Nullstr@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@CAPBDXZ@4DB, __Hstd@@YA_AV_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@0@ABV10@0@Z

( 4 exports )
DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer
RDS...: NSRL Reference Data Set
-
pdfid.: -
packers (Antiy-AVL): CrypToCrackPeProtector0.93
sigcheck:
publisher....: Microsoft Corporation
copyright....: Copyright 2006
product......: Flacdker Product
description..: Transaction Module
original name: COM Services
internal name: COM Services
file version.: 1, 0, 2, 8
comments.....: Microsoft Corporation
signers......: -
signing date.: -
verified.....: Unsigned
<a href='http://info.prevx.com/aboutprogramtext.asp?PX5=756B25D5005CD4E4909000E3E730F100EAFF256C' target='_blank'>http://info.prevx.com/aboutprogr ... E730F100EAFF256C<;/a>
trid..: DirectShow filter (43.0%)
Windows OCX File (26.3%)
Win64 Executable Generic (18.2%)
Win32 Executable MS Visual C++ (generic) (8.0%)
Win32 Executable Generic (1.8%)


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler 4.0; MAXTHON 2.0)
瑞星工程师19 - 2009-10-17 9:49:00
感谢楼主的支持,您提交的的样本已经上报,请继续关注瑞星~
1
查看完整版本: e54.dll---adcf542a58f026d5819de1844946ba5e