瑞星卡卡安全论坛技术交流区可疑文件交流 Wsock22.dll---651ad08ef64d9ea775513f7c96be52b8

1   1  /  1  页   跳转

Wsock22.dll---651ad08ef64d9ea775513f7c96be52b8

Wsock22.dll---651ad08ef64d9ea775513f7c96be52b8


 附件: 您所在的用户组无法下载或查看附件

解压密码:virus

文件说明符 : C:\WINDOWS\system32\Wsock22.dll
属性 : A---
数字签名:否
PE文件:是
获取文件版本信息大小失败!
创建时间 : 2009-10-16 21:14:8
修改时间 : 2009-10-10 23:31:16
大小 : 57344 字节 56.0 KB
MD5 : 651ad08ef64d9ea775513f7c96be52b8
SHA1: 75B290A0714753A493E07A00E1F86A44CBD948CD
CRC32: 8ce4f96f
文件 Wsock22.dll 接收于 2009.10.16 15:07:57 (UTC)

反病毒引擎版本最后更新扫描结果
a-squared4.5.0.412009.10.16Trojan-Downloader.Small!IK
AhnLab-V35.0.0.22009.10.16-
AntiVir7.9.1.352009.10.16TR/Dldr.Small.jrs
Antiy-AVL2.0.3.72009.10.16-
Authentium5.1.2.42009.10.16-
Avast4.8.1351.02009.10.14-
AVG8.5.0.4202009.10.16-
BitDefender7.22009.10.16Trojan.Generic.2522864
CAT-QuickHeal10.002009.10.16Trojan.Agent.ATV
ClamAV0.94.12009.10.16-
Comodo26212009.10.16-
DrWeb5.0.0.121822009.10.16-
eSafe7.0.17.02009.10.15-
eTrust-Vet35.1.70712009.10.16-
F-Prot4.5.1.852009.10.15-
F-Secure8.0.14470.02009.10.16-
Fortinet3.120.0.02009.10.16-
GData192009.10.16Trojan.Generic.2522864
IkarusT3.1.1.72.02009.10.16Trojan-Downloader.Small
Jiangmin11.0.8002009.10.16Trojan/Clicker.fc
K7AntiVirus7.10.8722009.10.16-
Kaspersky7.0.0.1252009.10.16-
McAfee57722009.10.15-
McAfee+Artemis57722009.10.15Artemis!651AD08EF64D
McAfee-GW-Edition6.8.52009.10.16Trojan.Dldr.Small.jrs
Microsoft1.51012009.10.16-
NOD3245152009.10.16-
Norman6.03.022009.10.16-
nProtect2009.1.8.02009.10.15-
Panda10.0.2.22009.10.15Trj/CI.A
PCTools4.4.2.02009.10.16-
Prevx3.02009.10.16-
Rising21.51.44.002009.10.16-
Sophos4.46.02009.10.16-
Sunbelt3.2.1858.22009.10.15-
Symantec1.4.4.122009.10.16-
TheHacker6.5.0.2.0432009.10.15-
TrendMicro8.950.0.10942009.10.16TROJ_MALWARE.VTG
VBA323.12.10.112009.10.15-
ViRobot2009.10.16.19882009.10.16-
VirusBuster4.6.5.02009.10.15-
附加信息
File size: 57344 bytes
MD5...: 651ad08ef64d9ea775513f7c96be52b8
SHA1..: 75b290a0714753a493e07a00e1f86a44cbd948cd
SHA256: 5db3a7fe0d66bf7f716bfa12ec72ba57d264fed6ae1db859d9158718122e06d8
ssdeep: 768:kH1WPBzoEmcqRFNNURVe/A1T5KpYJewYgSS99kiB9gneC13EPiAo7zu4oZ2:
m1uoNlkeo1T5KpuYgSS9aL+on1x
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x2f71
timedatestamp.....: 0x4ab077b8 (Wed Sep 16 05:29:28 2009)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x8426 0x9000 6.36 ef13f29c4b70353dc563cc8f49eefe52
.rdata 0xa000 0xf5d 0x1000 5.23 53b47c4dcbe792ba2bac3799bcea9c02
.data 0xb000 0x2948 0x2000 2.45 f4e3772ee06265fa7ce614ead06246c9
.reloc 0xe000 0xf1a 0x1000 4.34 d5bef0c71191912622ea99fa9b82528b

( 5 imports )
> KERNEL32.dll: DeleteFileA, TerminateProcess, GetLastError, FindClose, FindNextFileA, FindFirstFileA, GetModuleFileNameA, CompareStringW, CompareStringA, LCMapStringW, LCMapStringA, CreateProcessA, SetEnvironmentVariableA, Sleep, RtlUnwind, LoadLibraryA, GetOEMCP, GetACP, GetCPInfo, GetStringTypeW, GetStringTypeA, MultiByteToWideChar, FlushFileBuffers, SetStdHandle, InterlockedIncrement, HeapFree, HeapAlloc, GetTimeZoneInformation, GetSystemTime, GetLocalTime, GetCommandLineA, GetVersion, HeapDestroy, HeapCreate, VirtualFree, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, ExitProcess, VirtualAlloc, HeapReAlloc, CloseHandle, WriteFile, GetCurrentThreadId, TlsSetValue, TlsAlloc, TlsFree, SetLastError, TlsGetValue, GetProcAddress, GetModuleHandleA, GetCurrentProcess, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStrings, GetEnvironmentStringsW, SetFilePointer, InterlockedDecrement
> USER32.dll: SendMessageA, GetWindowThreadProcessId, GetClassNameA, GetParent, CloseDesktop, SetForegroundWindow, EnumDesktopWindows, PostMessageA, CreateDesktopA, EnumChildWindows
> ADVAPI32.dll: RegQueryValueExA, RegCloseKey, RegOpenKeyExA
> SHELL32.dll: SHGetSpecialFolderPathA
> WS2_32.dll: -, -, -, -, -, -, -, -, -, -, -, -

( 3 exports )
GetDLlVersion, Run, Sunbelt
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler 4.0; MAXTHON 2.0)
http://blog.csdn.net/purpleendurer

宠辱不惊,笑看堂前花开花落; 去留无意,漫随天外云卷云舒。
分享到:
gototop
 

回复:Wsock22.dll---651ad08ef64d9ea775513f7c96be52b8

感谢楼主的支持,您提交的的样本已经上报,请继续关注瑞星~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT