瑞星卡卡安全论坛

首页 » 技术交流区 » 可疑文件交流 » fly2926.dll---ece5cecf1bca898ae2f2fdd9a0ca19f4
endurer - 2009-10-16 22:23:00

 附件: 您所在的用户组无法下载或查看附件

解压密码:virus

文件说明符 : C:\windows\system32\fly2926.dll
属性 : A---
数字签名:否
PE文件:是
语言 : 中文(中国)
文件版本 : 1, 0, 0, 1
说明 : MyTest3
版权 : 版权所有 (C) 2008
产品版本 : 1, 0, 0, 1
产品名称 : MyTest3 Dynamic Link Library
内部名称 : MyTest3
源文件名 : MyTest3.DLL
创建时间 : 2009-10-16 21:14:8
修改时间 : 2009-10-12 8:2:42
大小 : 168960 字节 165.0 KB
MD5 : ece5cecf1bca898ae2f2fdd9a0ca19f4
SHA1: D295394F4C961B0CE8E97711859C7D94772E68A7
CRC32: f43ab893
文件 fly2926.dll 接收于 2009.10.16 14:16:09 (UTC)
反病毒引擎版本最后更新扫描结果
a-squared4.5.0.412009.10.16Trojan-Downloader.Win32.Adload!IK
AhnLab-V35.0.0.22009.10.16-
AntiVir7.9.1.352009.10.16TR/Dldr.Small.jrs
Antiy-AVL2.0.3.72009.10.16Trojan/Win32.Filka.gen
Authentium5.1.2.42009.10.16W32/Downloader.F.gen!Eldorado
Avast4.8.1351.02009.10.14Win32:Trojan-gen
AVG8.5.0.4202009.10.16Agent2.USL
BitDefender7.22009.10.16Generic.Malware.FP!Pkg.D2BC4CFC
CAT-QuickHeal10.002009.10.16-
ClamAV0.94.12009.10.16Trojan.Clicker-3346
Comodo26212009.10.16-
DrWeb5.0.0.121822009.10.16Trojan.DownLoader.origin
eSafe7.0.17.02009.10.15Win32.TRDldr.Small.J
eTrust-Vet35.1.70712009.10.16-
F-Prot4.5.1.852009.10.15W32/Downloader.F.gen!Eldorado
F-Secure8.0.14470.02009.10.16Trojan-Spy.Win32.Filka.am
Fortinet3.120.0.02009.10.16PossibleThreat
GData192009.10.16Generic.Malware.FP!Pkg.D2BC4CFC
IkarusT3.1.1.72.02009.10.16Trojan-Downloader.Win32.Adload
Jiangmin11.0.8002009.10.16TrojanDownloader.Agent.btva
K7AntiVirus7.10.8722009.10.16Trojan.Win32.Malware.1
Kaspersky7.0.0.1252009.10.16Trojan-Spy.Win32.Filka.am
McAfee57722009.10.15-
McAfee+Artemis57722009.10.15Artemis!ECE5CECF1BCA
McAfee-GW-Edition6.8.52009.10.16Trojan.Dldr.Small.jrs
Microsoft1.51012009.10.16-
NOD3245142009.10.16a variant of Win32/Agent.PHX
Norman6.03.022009.10.16W32/Agent.RVOF
nProtect2009.1.8.02009.10.15-
Panda10.0.2.22009.10.15Trj/CI.A
PCTools4.4.2.02009.10.16-
Prevx3.02009.10.16High Risk Cloaked Malware
Rising21.51.44.002009.10.16-
Sophos4.46.02009.10.16Sus/VB-AM
Sunbelt3.2.1858.22009.10.15Trojan.Win32.Agent
Symantec1.4.4.122009.10.16Trojan.Cinmeng
TheHacker6.5.0.2.0432009.10.15-
TrendMicro8.950.0.10942009.10.16TROJ_CINMENG.JC
VBA323.12.10.112009.10.15Trojan-Spy.Win32.Filka.am
ViRobot2009.10.16.19882009.10.16-
VirusBuster4.6.5.02009.10.15-

附加信息
File size: 168960 bytes
MD5...: ece5cecf1bca898ae2f2fdd9a0ca19f4
SHA1..: d295394f4c961b0ce8e97711859c7d94772e68a7
SHA256: 6acae186d5d67c6b5908b83a8fdf047958e9e03cc17e6623d4f211994edb6cef
ssdeep: 3072:LA3dC2xHJoQtuRcsAKNiJ+ytjC8yf+KS3oV6GoIMc4CPz1xMSfXjI0kN2K4
WX5VK:LD2FJo1NxNDFyb3on5RlPhxM6TI0k1
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x95470
timedatestamp.....: 0x4ad1ea96 (Sun Oct 11 14:24:22 2009)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x6c000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x6d000 0x29000 0x28800 7.92 8fe59680bce4891a4c177623ee5a99a7
.rsrc 0x96000 0x1000 0x800 3.36 ee8b35b34cb598a6009b33a6d7d89cee

( 10 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect
> ADVAPI32.dll: RegEnumKeyA
> iphlpapi.dll: GetAdaptersInfo
> MFC42.DLL: -
> MSVCRT.dll: atol
> ole32.dll: CoInitialize
> OLEAUT32.dll: -
> USER32.dll: SetTimer
> WININET.dll: InternetOpenA
> WINMM.dll: timeGetTime

( 3 exports )
InstallHook, InstallMyDll, UnInstallHook
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win64 Executable Generic (52.5%)
UPX compressed Win32 Executable (18.7%)
Win32 EXE Yoda's Crypter (16.3%)
Win32 Executable Generic (5.2%)
Win32 Dynamic Link Library (generic) (4.6%)
packers (Antiy-AVL): UPX 0.89.6 - 1.02 / 1.05 - 1.22 DLL
sigcheck:
publisher....:
copyright....: ____ (C) 2008
product......: MyTest3 Dynamic Link Library
description..: MyTest3
original name: MyTest3.DLL
internal name: MyTest3
file version.: 1, 0, 0, 1
comments.....:
signers......: -
signing date.: -
verified.....: Unsigned
packers (Kaspersky): PE_Patch.UPX, UPX
packers (Avast): UPX
packers (F-Prot): UPX
<a href='http://info.prevx.com/aboutprogramtext.asp?PX5=6BE719130098A8F2947A021A84BE5300793EBF78' target='_blank'>http://info.prevx.com/aboutprogr ... 84BE5300793EBF78<;/a>
瑞星工程师19 - 2009-10-17 9:52:00
感谢楼主的支持,您提交的的样本已经上报,请继续关注瑞星~
1
查看完整版本: fly2926.dll---ece5cecf1bca898ae2f2fdd9a0ca19f4