瑞星卡卡安全论坛技术交流区可疑文件交流 bfilo.exe---27739801917eb54129f7d2a666363fad

1   1  /  1  页   跳转

bfilo.exe---27739801917eb54129f7d2a666363fad

bfilo.exe---27739801917eb54129f7d2a666363fad


 附件: 您所在的用户组无法下载或查看附件

解压密码:virus


O23 - 服务: ISBCCCS (IMAPI System By Catch CD-Burning COM Service) - C:\WINDOWS\system32\bfilo.exe (自动)

文件说明符 : C:\WINDOWS\bfilo.exe
属性 : A---
数字签名:否
PE文件:是
语言 : 英语(美国)
文件版本 : 1, 0, 0, 1
说明 : mssvr Module
版权 : Copyright 2009
产品版本 : 1, 0, 0, 1
产品名称 : mssvr Module
内部名称 : mssvr
源文件名 : mssvr.EXE
创建时间 : 2009-10-16 23:17:14
修改时间 : 2009-10-9 18:26:58
大小 : 45056 字节 44.0 KB
MD5 : 27739801917eb54129f7d2a666363fad
SHA1: ACE452E7EA6F1AC2A85FB2549AF7AF077038908F
CRC32: 6a23889f
文件 bfilo.exe 接收于 2009.10.16 15:34:47 (UTC)

反病毒引擎版本最后更新扫描结果
a-squared4.5.0.412009.10.16Trojan-Downloader.Win32.Phinit!IK
AhnLab-V35.0.0.22009.10.16-
AntiVir7.9.1.352009.10.16TR/Downloader.Gen
Antiy-AVL2.0.3.72009.10.16-
Authentium5.1.2.42009.10.16-
Avast4.8.1351.02009.10.14-
AVG8.5.0.4202009.10.16Generic4.OPG
BitDefender7.22009.10.16Application.Generic.236077
CAT-QuickHeal10.002009.10.16-
ClamAV0.94.12009.10.16-
Comodo26222009.10.16-
DrWeb5.0.0.121822009.10.16-
eSafe7.0.17.02009.10.15-
eTrust-Vet35.1.70712009.10.16-
F-Prot4.5.1.852009.10.15-
F-Secure8.0.14470.02009.10.16-
Fortinet3.120.0.02009.10.16-
GData192009.10.16Application.Generic.236077
IkarusT3.1.1.72.02009.10.16Trojan-Downloader.Win32.Phinit
Jiangmin11.0.8002009.10.16TrojanDownloader.Agent.bttt
K7AntiVirus7.10.8722009.10.16-
Kaspersky7.0.0.1252009.10.16-
McAfee57722009.10.15-
McAfee+Artemis57722009.10.15Artemis!27739801917E
McAfee-GW-Edition6.8.52009.10.16Heuristic.BehavesLike.Win32.Rootkit.L
Microsoft1.51012009.10.16TrojanDownloader:Win32/Phinit.B
NOD3245152009.10.16probably a variant of Win32/Adware.NewWeb
Norman6.03.022009.10.16-
nProtect2009.1.8.02009.10.15-
Panda10.0.2.22009.10.15Trj/CI.A
PCTools4.4.2.02009.10.16-
Prevx3.02009.10.16-
Rising21.51.44.002009.10.16-
Sophos4.46.02009.10.16Mal/Generic-A
Sunbelt3.2.1858.22009.10.15-
Symantec1.4.4.122009.10.16-
TheHacker6.5.0.2.0432009.10.15-
TrendMicro8.950.0.10942009.10.16-
VBA323.12.10.112009.10.15-
ViRobot2009.10.16.19882009.10.16-
VirusBuster4.6.5.02009.10.15-
附加信息
File size: 45056 bytes
MD5...: 27739801917eb54129f7d2a666363fad
SHA1..: ace452e7ea6f1ac2a85fb2549af7af077038908f
SHA256: fdb6fd1a972cdc7e8330b9c0bce54950ee6f334699d3e43449fee1492559ba57
ssdeep: 768:lWYfyi0Kpi6fZ/MMDA6TNwqMwhpYMB2vK29aGv7rdsoex29ONft:UYf/0Kpi
6f5MINwqp4ooKzgshNft
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x5f5a
timedatestamp.....: 0x4acf0ff2 (Fri Oct 09 10:26:58 2009)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x5606 0x6000 5.97 b5929e53dac0c3f0a1d05a01e10eb7af
.rdata 0x7000 0x1d96 0x2000 4.59 224d6575735b5412d442ecad59f1f567
.data 0x9000 0x9f0 0x1000 3.41 1e5cc91d3d2b81a4203d15383c21a3f4
.rsrc 0xa000 0x968 0x1000 2.40 417379093d7a6ba21678e79f9154001c

( 9 imports )
> WININET.dll: InternetCloseHandle, InternetOpenUrlA, InternetOpenA, InternetReadFile
> MFC42.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> MSVCRT.dll: free, malloc, memcpy, sprintf, _splitpath, memset, strcpy, realloc, memcmp, __0exception@@QAE@ABV0@@Z, strlen, _CxxThrowException, strcmp, _strupr, atol, _mbslwr, __dllonexit, _onexit, __1type_info@@UAE@XZ, _except_handler3, _exit, _XcptFilter, exit, _acmdln, __getmainargs, _stricmp, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, __CxxFrameHandler, _controlfp
> KERNEL32.dll: GetStartupInfoA, GetPrivateProfileSectionNamesA, GetPrivateProfileStringA, WritePrivateProfileStringA, MoveFileExA, GetTickCount, WinExec, DeleteFileA, CreateToolhelp32Snapshot, Process32First, Process32Next, GetWindowsDirectoryA, CreateDirectoryA, lstrcatA, lstrcpyA, LoadLibraryA, GetProcAddress, InitializeCriticalSection, IsDBCSLeadByte, lstrcpynA, LoadLibraryExA, GetLastError, CloseHandle, GetCurrentProcess, GetCurrentThread, GetModuleFileNameA, SetLastError, Sleep, GetCurrentThreadId, lstrcmpiA, GetCommandLineA, lstrlenA, lstrlenW, MultiByteToWideChar, GetShortPathNameA, GetModuleHandleA, WideCharToMultiByte, FreeLibrary, SizeofResource, LoadResource, FindResourceA, OpenProcess
> USER32.dll: PostThreadMessageA, GetMessageA, CharNextA, LoadStringA, KillTimer, SetTimer, TranslateMessage, DispatchMessageA
> ADVAPI32.dll: RegEnumKeyExA, RegCreateKeyExA, RegOpenKeyExA, StartServiceCtrlDispatcherA, RegDeleteValueA, RegSetValueExA, RegCloseKey, RegQueryValueExA, SetServiceStatus, RegisterServiceCtrlHandlerA, RegDeleteKeyA, OpenServiceA, ControlService, QueryServiceStatus, DeleteService, OpenSCManagerA, CreateServiceA, ChangeServiceConfig2A, CloseServiceHandle, GetAclInformation, AddAce, InitializeAcl, GetAce, AddAccessAllowedAce, LookupAccountNameA, GetTokenInformation, OpenThreadToken, OpenProcessToken, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, GetLengthSid, CopySid, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegQueryInfoKeyA, RegEnumValueA, CreateProcessAsUserA
> ole32.dll: CoTaskMemAlloc, CoTaskMemFree, CoTaskMemRealloc, CoInitializeEx, CoUninitialize, CoInitializeSecurity, CoRegisterClassObject, CoRevokeClassObject, CoCreateInstance, CoInitialize
> OLEAUT32.dll: -, -, -, -, -
> MSVCP60.dll: __0out_of_range@std@@QAE@ABV01@@Z, __1out_of_range@std@@UAE@XZ, __1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ, ___7out_of_range@std@@6B@, __0logic_error@std@@QAE@ABV_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@1@@Z, _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, __Tidy@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEX_N@Z, __0logic_error@std@@QAE@ABV01@@Z

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....:
copyright....: Copyright 2009
product......: mssvr Module
description..: mssvr Module
original name: mssvr.EXE
internal name: mssvr
file version.: 1, 0, 0, 1
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned



用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler 4.0; MAXTHON 2.0)
http://blog.csdn.net/purpleendurer

宠辱不惊,笑看堂前花开花落; 去留无意,漫随天外云卷云舒。
分享到:
gototop
 

回复:bfilo.exe---27739801917eb54129f7d2a666363fad

感谢楼主的支持,您提交的的样本已经上报,请继续关注瑞星~
gototop
 

回复: bfilo.exe---27739801917eb54129f7d2a666363fad


 附件: 您所在的用户组无法下载或查看附件
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT