瑞星卡卡安全论坛技术交流区可疑文件交流 dlllhost.exe---5fc6c0348b8b91423dc8dd38843bc846

1   1  /  1  页   跳转

dlllhost.exe---5fc6c0348b8b91423dc8dd38843bc846

dlllhost.exe---5fc6c0348b8b91423dc8dd38843bc846


 附件: 您所在的用户组无法下载或查看附件

解压密码:virus



文件说明符 : C:\WINDOWS\system32\dlllhost.exe
属性 : A---
数字签名:否
PE文件:是
语言 : 中文(中国)
文件版本 : 1, 0, 0, 3
说明 : Microsoft 基础类应用程序
版权 : 版权所有 (C) 2006
产品版本 : 1, 0, 0, 3
产品名称 : dllhost
内部名称 : dllhost
源文件名 : dllhost.exe
创建时间 : 2009-10-16 21:14:8
修改时间 : 2009-10-11 11:12:0
大小 : 385024 字节 376.0 KB
MD5 : 5fc6c0348b8b91423dc8dd38843bc846
SHA1: 495B253FDBCC97F5D46A83712A563A4ACD9D96C4
CRC32: 49c0b324

文件 dlllhost.exe 接收于 2009.10.16 13:46:54 (UTC)
反病毒引擎版本最后更新扫描结果
a-squared4.5.0.412009.10.16-
AhnLab-V35.0.0.22009.10.16-
AntiVir7.9.1.352009.10.16-
Antiy-AVL2.0.3.72009.10.16-
Authentium5.1.2.42009.10.16-
Avast4.8.1351.02009.10.14-
AVG8.5.0.4202009.10.16-
BitDefender7.22009.10.16-
CAT-QuickHeal10.002009.10.16-
ClamAV0.94.12009.10.16-
Comodo26212009.10.16-
DrWeb5.0.0.121822009.10.16-
eSafe7.0.17.02009.10.15-
eTrust-Vet35.1.70712009.10.16Win32/Spykon.A
F-Prot4.5.1.852009.10.15-
F-Secure8.0.14470.02009.10.16-
Fortinet3.120.0.02009.10.16-
GData192009.10.16-
IkarusT3.1.1.72.02009.10.16-
Jiangmin11.0.8002009.10.16-
K7AntiVirus7.10.8722009.10.16-
Kaspersky7.0.0.1252009.10.16-
McAfee57722009.10.15-
McAfee+Artemis57722009.10.15Artemis!5FC6C0348B8B
McAfee-GW-Edition6.8.52009.10.16-
Microsoft1.51012009.10.16-
NOD3245142009.10.16-
Norman6.03.022009.10.16W32/Obfuscated.S!genr
nProtect2009.1.8.02009.10.15-
Panda10.0.2.22009.10.15-
PCTools4.4.2.02009.10.16-
Prevx3.02009.10.16-
Rising21.51.44.002009.10.16-
Sophos4.46.02009.10.16-
Sunbelt3.2.1858.22009.10.15-
Symantec1.4.4.122009.10.16-
TheHacker6.5.0.2.0432009.10.15-
TrendMicro8.950.0.10942009.10.16-
VBA323.12.10.112009.10.15-
ViRobot2009.10.16.19882009.10.16-
VirusBuster4.6.5.02009.10.15-

附加信息
File size: 385024 bytes
MD5...: 5fc6c0348b8b91423dc8dd38843bc846
SHA1..: 495b253fdbcc97f5d46a83712a563a4acd9d96c4
SHA256: fd424bb7e662583588a8f2ada4c080848ceaac9bf91f555778edc1e6d6a6e732
ssdeep: 6144:lt5TeFXjGdFVsH/YL0zDogX1FbFTFH/2db8CPuq5gTA:lTTeRjGdFyYL0fr
1FFTgR8b+
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x186c5
timedatestamp.....: 0x48d15a7f (Wed Sep 17 19:29:03 2008)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x43792 0x44000 6.52 a3f9e237178851d18473a408a4251397
.rdata 0x45000 0xf782 0x10000 4.63 2271ba1f5249331d014755d589f960a3
.data 0x55000 0x8f68 0x5000 2.92 48a11602a6d7497d519cbddd7c8b27de
.rsrc 0x5e000 0x3cd8 0x4000 4.63 12d05f431a77d1d103453bcf8f9a1956

( 14 imports )
> WININET.dll: DeleteUrlCacheEntry, FindNextUrlCacheEntryA, FindFirstUrlCacheEntryA, InternetSetFilePointer, InternetSetStatusCallback, InternetGetLastResponseInfoA, HttpQueryInfoA, HttpSendRequestA, HttpOpenRequestA, InternetConnectA, InternetSetOptionExA, InternetCloseHandle, InternetWriteFile, InternetOpenA, InternetCanonicalizeUrlA, InternetCrackUrlA, InternetReadFile, InternetQueryDataAvailable
> KERNEL32.dll: GetOEMCP, LocalFileTimeToFileTime, SystemTimeToFileTime, SetErrorMode, SizeofResource, RtlUnwind, RaiseException, GetStartupInfoA, GetCommandLineA, ExitProcess, TerminateProcess, HeapFree, CreateThread, ExitThread, HeapAlloc, GetTimeZoneInformation, GetACP, HeapReAlloc, HeapSize, SetStdHandle, GetFileType, LCMapStringA, GetCPInfo, SetUnhandledExceptionFilter, SetHandleCount, GetStdHandle, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, GetEnvironmentVariableA, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, IsBadWritePtr, GetStringTypeA, GetStringTypeW, IsBadReadPtr, IsBadCodePtr, CompareStringA, CompareStringW, SetEnvironmentVariableA, GetProcessVersion, GetCurrentDirectoryA, GlobalFlags, TlsGetValue, LocalReAlloc, TlsSetValue, GlobalReAlloc, TlsFree, GlobalHandle, TlsAlloc, FileTimeToLocalFileTime, FileTimeToSystemTime, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection, LocalAlloc, EnterCriticalSection, GetShortPathNameA, GetThreadLocale, GetStringTypeExA, GetVolumeInformationA, MoveFileA, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, ReadFile, GetCurrentProcess, DuplicateHandle, FormatMessageA, LocalFree, GlobalUnlock, MulDiv, lstrlenW, GetLastError, GetDiskFreeSpaceA, GetFileTime, SetFileTime, GetFullPathNameA, GetProfileStringA, GetProfileIntA, SearchPathA, lstrcpynA, GetTempPathA, GetTempFileNameA, SetLastError, GlobalFree, WritePrivateProfileStringA, GetPrivateProfileStringA, GetVersion, lstrcatA, GlobalGetAtomNameA, GlobalAddAtomA, GlobalFindAtomA, lstrcpyA, MultiByteToWideChar, lstrlenA, InterlockedDecrement, InterlockedIncrement, CreateEventA, SuspendThread, SetThreadPriority, ResumeThread, SetEvent, WaitForSingleObject, GlobalLock, GlobalAlloc, GlobalDeleteAtom, lstrcmpA, lstrcmpiA, GetCurrentThread, GetCurrentThreadId, FreeLibrary, LoadLibraryA, GetProcAddress, WideCharToMultiByte, FindFirstFileA, GetFileAttributesA, SetFileAttributesA, RemoveDirectoryA, DeleteFileA, FindNextFileA, FindClose, CreateFileA, GetFileSize, SetFilePointer, WriteFile, CloseHandle, GetTickCount, GetVersionExA, FindResourceA, LoadResource, LockResource, GetModuleHandleA, GetModuleFileNameA, Sleep, GetPrivateProfileIntA, LCMapStringW
> USER32.dll: TabbedTextOutA, DrawTextA, GrayStringA, LoadCursorA, GetSysColorBrush, DestroyIcon, CharNextA, CopyAcceleratorTableA, SetRect, GetNextDlgGroupItem, MessageBeep, CreateDialogIndirectParamA, EndDialog, WindowFromPoint, InflateRect, RegisterClipboardFormatA, GetDCEx, LockWindowUpdate, PostThreadMessageA, SetParent, PtInRect, GetClassNameA, LoadStringA, IsZoomed, CharUpperA, RedrawWindow, DefMDIChildProcA, DrawMenuBar, TranslateMDISysAccel, DefFrameProcA, BringWindowToTop, UnpackDDElParam, ReuseDDElParam, SetMenu, GetDesktopWindow, TranslateAcceleratorA, SetRectEmpty, FindWindowA, InvalidateRect, RemoveMenu, SetCapture, ReleaseCapture, SetTimer, KillTimer, MapDialogRect, SetWindowContextHelpId, DestroyMenu, LoadMenuA, LoadAcceleratorsA, ShowWindow, MoveWindow, SetWindowTextA, IsDialogMessageA, EndPaint, LoadIconA, SendDlgItemMessageA, MapWindowPoints, GetSysColor, SetActiveWindow, IsWindow, SetFocus, AdjustWindowRectEx, ScreenToClient, EqualRect, GetClientRect, BeginDeferWindowPos, CopyRect, EndDeferWindowPos, InsertMenuA, GetScrollInfo, SetScrollInfo, ShowScrollBar, GetScrollRange, SetScrollRange, GetScrollPos, SetScrollPos, GetTopWindow, IsChild, GetCapture, WinHelpA, wsprintfA, GetClassInfoA, RegisterClassA, GetMenu, GetMenuItemCount, GetSubMenu, GetMenuItemID, GetDlgItem, GetWindowTextLengthA, GetWindowTextA, GetDlgCtrlID, DefWindowProcA, UnregisterClassA, HideCaret, ShowCaret, ExcludeUpdateRgn, DrawFocusRect, DefDlgProcA, IsWindowUnicode, DestroyWindow, CreateWindowExA, GetClassLongA, SetPropA, UnhookWindowsHookEx, GetPropA, CallWindowProcA, RemovePropA, GetMessageTime, GetMessagePos, GetForegroundWindow, SetForegroundWindow, GetWindow, SetWindowLongA, SetWindowPos, BeginPaint, GetWindowDC, ReleaseDC, GetDC, GetMenuStringA, DeleteMenu, RegisterWindowMessageA, OffsetRect, IntersectRect, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetWindowRect, GetSystemMetrics, GetMenuCheckMarkDimensions, LoadBitmapA, GetMenuState, ModifyMenuA, SetMenuItemBitmaps, CheckMenuItem, EnableMenuItem, GetFocus, GetNextDlgTabItem, GetMessageA, TranslateMessage, DispatchMessageA, GetActiveWindow, GetKeyState, CallNextHookEx, ValidateRect, IsWindowVisible, PeekMessageA, GetCursorPos, SetWindowsHookExA, GetLastActivePopup, IsWindowEnabled, GetWindowLongA, MessageBoxA, SetCursor, ShowOwnedPopups, PostQuitMessage, ScrollWindow, ClientToScreen, GetParent, SendMessageA, EnableWindow, UpdateWindow, PostMessageA, DeferWindowPos
> GDI32.dll: GetDeviceCaps, GetViewportExtEx, GetWindowExtEx, CreateSolidBrush, CreatePatternBrush, PtVisible, RectVisible, TextOutA, ExtTextOutA, GetTextColor, GetBkColor, GetMapMode, PatBlt, SetRectRgn, CombineRgn, CreateRectRgnIndirect, CreateFontIndirectA, BitBlt, CreateCompatibleDC, GetTextExtentPointA, CreateRectRgn, CreateDIBitmap, GetClipBox, Escape, CreateBitmap, IntersectClipRect, ExcludeClipRect, SelectClipRgn, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SetMapMode, SetBkMode, GetStockObject, RestoreDC, SaveDC, DeleteDC, DeleteObject, GetTextMetricsA, SelectObject, GetTextExtentPoint32A, DPtoLP, LPtoDP, GetObjectA, SetBkColor, SetTextColor
> comdlg32.dll: GetFileTitleA, GetOpenFileNameA, GetSaveFileNameA
> WINSPOOL.DRV: ClosePrinter, OpenPrinterA, DocumentPropertiesA
> ADVAPI32.dll: RegQueryValueExA, RegSetValueA, RegCreateKeyA, GetFileSecurityA, SetFileSecurityA, RegDeleteValueA, RegSetValueExA, RegQueryValueA, RegOpenKeyExA, RegCreateKeyExA, RegDeleteKeyA, RegOpenKeyA, RegCloseKey
> SHELL32.dll: SHGetFileInfoA, DragQueryFileA, DragFinish, SHGetSpecialFolderPathA, ExtractIconA
> COMCTL32.dll: -
> oledlg.dll: -
> ole32.dll: StgOpenStorageOnILockBytes, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal, CoTaskMemFree, CoTaskMemAlloc, OleInitialize, OleUninitialize, CoFreeUnusedLibraries, CoGetClassObject, CoRegisterMessageFilter, CoRevokeClassObject, CLSIDFromString, CLSIDFromProgID, OleFlushClipboard, OleIsCurrentClipboard
> OLEPRO32.DLL: -
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> WSOCK32.dll: -, -

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable MS Visual C++ (generic) (53.1%)
Windows Screen Saver (18.4%)
Win32 Executable Generic (12.0%)
Win32 Dynamic Link Library (generic) (10.6%)
Generic Win/DOS Executable (2.8%)
sigcheck:
publisher....:
copyright....: ____ (C) 2006
product......: dllhost
description..: Microsoft _______
original name: dllhost.exe
internal name: dllhost
file version.: 1, 0, 0, 3
comments.....:
signers......: -
signing date.: -
verified.....: Unsigned


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler 4.0; MAXTHON 2.0)
http://blog.csdn.net/purpleendurer

宠辱不惊,笑看堂前花开花落; 去留无意,漫随天外云卷云舒。
分享到:
gototop
 

回复:dlllhost.exe---5fc6c0348b8b91423dc8dd38843bc846

样本已经收集,感谢您对瑞星的支持!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT