瑞星卡卡安全论坛技术交流区可疑文件交流 EndViewRun.dll---c2ee6991360293ad4ba89e3a432f4d80

1   1  /  1  页   跳转

EndViewRun.dll---c2ee6991360293ad4ba89e3a432f4d80

EndViewRun.dll---c2ee6991360293ad4ba89e3a432f4d80


 附件: 您所在的用户组无法下载或查看附件

解压密码:virus

文件说明符 : C:\WINDOWS\system32\EndViewRun.dll
属性 : A---
数字签名:否
PE文件:是
获取文件版本信息大小失败!
创建时间 : 2009-10-16 21:14:8
修改时间 : 2009-10-11 0:40:8
大小 : 24576 字节 24.0 KB
MD5 : c2ee6991360293ad4ba89e3a432f4d80
SHA1: 79F5A303788B1BB790F46456C2CBBC02D8E99211
CRC32: bce75fe6

文件 EndViewRun.dll 接收于 2009.10.16 14:07:15 (UTC)

反病毒引擎版本最后更新扫描结果
a-squared4.5.0.412009.10.16Trojan-Downloader.Small!IK
AhnLab-V35.0.0.22009.10.16-
AntiVir7.9.1.352009.10.16TR/Dldr.Small.jrs
Antiy-AVL2.0.3.72009.10.16-
Authentium5.1.2.42009.10.16-
Avast4.8.1351.02009.10.14-
AVG8.5.0.4202009.10.16-
BitDefender7.22009.10.16-
CAT-QuickHeal10.002009.10.16Trojan.Agent.ATV
ClamAV0.94.12009.10.16-
Comodo26212009.10.16-
DrWeb5.0.0.121822009.10.16-
eSafe7.0.17.02009.10.15Win32.TRDldr.Small.J
eTrust-Vet35.1.70712009.10.16-
F-Prot4.5.1.852009.10.15-
F-Secure8.0.14470.02009.10.16-
Fortinet3.120.0.02009.10.16PossibleThreat
GData192009.10.16-
IkarusT3.1.1.72.02009.10.16Trojan-Downloader.Small
Jiangmin11.0.8002009.10.16Trojan/Clicker.hj
K7AntiVirus7.10.8722009.10.16Trojan.Win32.Malware.1
Kaspersky7.0.0.1252009.10.16-
McAfee57722009.10.15-
McAfee+Artemis57722009.10.15Artemis!C2EE69913602
McAfee-GW-Edition6.8.52009.10.16Trojan.Dldr.Small.jrs
Microsoft1.51012009.10.16-
NOD3245142009.10.16-
Norman6.03.022009.10.16-
nProtect2009.1.8.02009.10.15-
Panda10.0.2.22009.10.15-
PCTools4.4.2.02009.10.16-
Prevx3.02009.10.16-
Rising21.51.44.002009.10.16-
Sophos4.46.02009.10.16Mal/Generic-A
Sunbelt3.2.1858.22009.10.15-
Symantec1.4.4.122009.10.16-
TheHacker6.5.0.2.0432009.10.15-
TrendMicro8.950.0.10942009.10.16-
VBA323.12.10.112009.10.15-
ViRobot2009.10.16.19882009.10.16-
VirusBuster4.6.5.02009.10.15Trojan.DL.Small.CLDP
附加信息
File size: 24576 bytes
MD5...: c2ee6991360293ad4ba89e3a432f4d80
SHA1..: 79f5a303788b1bb790f46456c2cbbc02d8e99211
SHA256: c8756ba9e31fee5032d6eb3e1f3ad3abef905f0e71cc1135d5b1ac61be106117
ssdeep: 192:VkRzZHh4AgG3E4/x+jWpXMViL0zlgpsstzsae7h3kYB+l:uZeehWWpX7p1Te
7hJA
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x249b
timedatestamp.....: 0x4ab07c55 (Wed Sep 16 05:49:09 2009)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1560 0x2000 4.81 666c35c1d0ed0fbe1d637a81420629bc
.rdata 0x3000 0x57e 0x1000 2.06 18d595a83347bb08c12a162a0ae9bf86
.data 0x4000 0x290 0x1000 1.23 4da1c77d1edeb2fb91f7cd11750ad755
.reloc 0x5000 0x2d0 0x1000 1.13 16fffa6a2f77f96ca97f93fbd68336be

( 6 imports )
> KERNEL32.dll: DeleteFileA, TerminateProcess, FindClose, FindNextFileA, FindFirstFileA, Sleep, DisableThreadLibraryCalls, CreateProcessA, GetLastError
> USER32.dll: EnumChildWindows, GetWindowThreadProcessId, GetClassNameA, GetParent, CloseDesktop, SetForegroundWindow, EnumDesktopWindows, PostMessageA, CreateDesktopA, SendMessageA
> ADVAPI32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey
> SHELL32.dll: SHGetSpecialFolderPathA
> WS2_32.dll: -, -, -, -, -, -, -, -, -, -, -, -
> MSVCRT.dll: _adjust_fdiv, _initterm, time, srand, strchr, rand, atoi, strcmp, strcat, strcpy, _strcmpi, sprintf, malloc, strstr, free, strlen, memset, memcpy

( 3 exports )
GetDLlVersion, Run, Sunbelt
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler 4.0; MAXTHON 2.0)
http://blog.csdn.net/purpleendurer

宠辱不惊,笑看堂前花开花落; 去留无意,漫随天外云卷云舒。
分享到:
gototop
 

回复:EndViewRun.dll---c2ee6991360293ad4ba89e3a432f4d80

感谢楼主的支持,您提交的的样本已经上报,请继续关注瑞星~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT