瑞星卡卡安全论坛

首页 » 技术交流区 » 可疑文件交流 » Wsock3.dll---fa0fd54b125f6645688df13306bf33a7
endurer - 2009-10-16 23:07:00

 附件: 您所在的用户组无法下载或查看附件
解压密码:virus

文件说明符 : C:\WINDOWS\system32\Wsock3.dll
属性 : A---
数字签名:否
PE文件:是
获取文件版本信息大小失败!
创建时间 : 2009-10-16 21:14:8
修改时间 : 2009-10-10 23:37:32
大小 : 24576 字节 24.0 KB
MD5 : fa0fd54b125f6645688df13306bf33a7
SHA1: D2A249E9BF3A7A2D7D3B5E9F662E33ED545120FA
CRC32: 26521d15
文件 Wsock3.dll 接收于 2009.10.16 14:59:23 (UTC)

反病毒引擎版本最后更新扫描结果
a-squared4.5.0.412009.10.16Trojan-Downloader.Small!IK
AhnLab-V35.0.0.22009.10.16-
AntiVir7.9.1.352009.10.16TR/Dldr.Small.jrs
Antiy-AVL2.0.3.72009.10.16-
Authentium5.1.2.42009.10.16-
Avast4.8.1351.02009.10.14-
AVG8.5.0.4202009.10.16-
BitDefender7.22009.10.16-
CAT-QuickHeal10.002009.10.16Trojan.Agent.ATV
ClamAV0.94.12009.10.16-
Comodo26212009.10.16-
DrWeb5.0.0.121822009.10.16-
eSafe7.0.17.02009.10.15-
eTrust-Vet35.1.70712009.10.16-
F-Prot4.5.1.852009.10.15-
F-Secure8.0.14470.02009.10.16-
Fortinet3.120.0.02009.10.16-
GData192009.10.16-
IkarusT3.1.1.72.02009.10.16Trojan-Downloader.Small
Jiangmin11.0.8002009.10.16TrojanDownloader.Agent.btfv
K7AntiVirus7.10.8722009.10.16-
Kaspersky7.0.0.1252009.10.16-
McAfee57722009.10.15-
McAfee+Artemis57722009.10.15Artemis!FA0FD54B125F
McAfee-GW-Edition6.8.52009.10.16Trojan.Dldr.Small.jrs
Microsoft1.51012009.10.16-
NOD3245142009.10.16-
Norman6.03.022009.10.16-
nProtect2009.1.8.02009.10.15-
Panda10.0.2.22009.10.15-
PCTools4.4.2.02009.10.16-
Prevx3.02009.10.16-
Rising21.51.44.002009.10.16-
Sophos4.46.02009.10.16-
Sunbelt3.2.1858.22009.10.15-
Symantec1.4.4.122009.10.16-
TheHacker6.5.0.2.0432009.10.15-
TrendMicro8.950.0.10942009.10.16-
VBA323.12.10.112009.10.15-
ViRobot2009.10.16.19882009.10.16-
VirusBuster4.6.5.02009.10.15Trojan.DL.Small.CMKJ
附加信息
File size: 24576 bytes
MD5...: fa0fd54b125f6645688df13306bf33a7
SHA1..: d2a249e9bf3a7a2d7d3b5e9f662e33ed545120fa
SHA256: cce21dbbbad6ea214f0d3cf801ccf94e73ce49c31b897717e47c57a048c82ae1
ssdeep: 192:kHAyup9BNkXDkSbH6TvB6yoR59AsxHip/MIQPjkYnW:sjuPkXoSbHUcBAOip
fQP
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x281b
timedatestamp.....: 0x4ab07887 (Wed Sep 16 05:32:55 2009)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x18e0 0x2000 5.50 878d100e85f08df1e3037e7cfec7e011
.rdata 0x3000 0x460 0x1000 1.68 c062e70577399f19c5dc2244fb091a85
.data 0x4000 0x294 0x1000 1.27 193607719e5f80eb00330c5ea0aec4cf
.reloc 0x5000 0x2e6 0x1000 1.20 8f4fe5f3171c93cb362218bbf9a63071

( 5 imports )
> KERNEL32.dll: GetLastError, DisableThreadLibraryCalls, Sleep, CreateProcessA, TerminateProcess
> USER32.dll: SendMessageA, GetWindowThreadProcessId, GetClassNameA, CloseDesktop, SetForegroundWindow, GetParent, EnumDesktopWindows, PostMessageA, CreateDesktopA, EnumChildWindows
> ADVAPI32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey
> WS2_32.dll: -, -, -, -, -, -, -, -, -, -, -, -
> MSVCRT.dll: _adjust_fdiv, _initterm, time, srand, strchr, rand, atoi, sprintf, malloc, strstr, free

( 3 exports )
GetDLlVersion, Run, Sunbelt
RDS...: NSRL Reference Data Set
-
pdfid.: -
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler 4.0; MAXTHON 2.0)
瑞星工程师19 - 2009-10-17 9:55:00
感谢楼主的支持,您提交的的样本已经上报,请继续关注瑞星~
1
查看完整版本: Wsock3.dll---fa0fd54b125f6645688df13306bf33a7