a-squared 4.5.0.50 2010.03.03 -
AhnLab-V3 5.0.0.2 2010.03.03 -
AntiVir 8.2.1.180 2010.03.03 -
Antiy-AVL 2.0.3.7 2010.03.03 Worm/Win32.Sohanad.gen
Authentium 5.2.0.5 2010.03.03 -
Avast 4.8.1351.0 2010.03.03 -
Avast5 5.0.332.0 2010.03.03 -
AVG 9.0.0.730 2010.03.03 -
BitDefender 7.2 2010.03.03 -
CAT-QuickHeal 10.00 2010.03.03 Trojan.Agent.ATV
ClamAV 0.96.0.0-git 2010.03.03 -
Comodo 4091 2010.02.28 -
DrWeb 5.0.1.12222 2010.03.03 -
eSafe 7.0.17.0 2010.03.02 -
eTrust-Vet 35.2.7337 2010.03.03 -
F-Prot 4.5.1.85 2010.03.02 -
F-Secure 9.0.15370.0 2010.03.03 -
Fortinet 4.0.14.0 2010.02.28 -
GData 19 2010.03.03 -
Ikarus T3.1.1.80.0 2010.03.03 -
Jiangmin 13.0.900 2010.03.03 -
K7AntiVirus 7.10.987 2010.03.02 IM-Worm.Win32.Sohanad
Kaspersky 7.0.0.125 2010.03.03 -
McAfee 5908 2010.03.02 Generic.dx
McAfee+Artemis 5908 2010.03.02 Generic.dx
McAfee-GW-Edition 6.8.5 2010.03.03 Heuristic.BehavesLike.Win32.Obfuscated.C
Microsoft 1.5502 2010.03.03 -
NOD32 4911 2010.03.03 -
Norman 6.04.08 2010.03.02 -
nProtect 2009.1.8.0 2010.03.03 -
Panda 10.0.2.2 2010.03.02 Trj/CI.A
PCTools 7.0.3.5 2010.03.03 -
Prevx 3.0 2010.03.03 -
Rising 22.37.02.04 2010.03.03 -
Sophos 4.50.0 2010.03.03 -
Sunbelt 5737 2010.03.03 -
Symantec 20091.2.0.41 2010.03.03 -
TheHacker 6.5.1.7.218 2010.03.03 W32/Sohanad.gk
TrendMicro 9.120.0.1004 2010.03.03 -
VBA32 3.12.12.2 2010.03.02 -
ViRobot 2010.3.3.2210 2010.03.03 -
VirusBuster 5.0.27.0 2010.03.02 -
Rozšiřující informace
File size: 232403 bytes
MD5 : 6550eb136ff031175958443677b838ac
SHA1 : be80773450c4b4a9382ae9a1e7ca9a2fbd759517
SHA256: 563ad967e12c2cfe2ebbf5fef540712e42b7460d925f457af6d785e71b1de651
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x95AD0
timedatestamp.....: 0x47493EAA (Sun Nov 25 10:21:46 2007)
machinetype.......: 0x14C (Intel I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x5E000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x5F000 0x37000 0x36E00 7.92 b56dfa384552a5a1d5f8025f75acf06b
.rsrc 0x96000 0x2000 0x1800 4.81 224e79549a658ee9e345316d3dc71072
( 13 imports )
> advapi32.dll: RegCloseKey
> comctl32.dll: ImageList_Remove
> comdlg32.dll: GetSaveFileNameW
> gdi32.dll: LineTo
> kernel32.dll: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> mpr.dll: WNetUseConnectionW
> ole32.dll: CoInitialize
> oleaut32.dll: -
> shell32.dll: DragFinish
> user32.dll: GetDC
> version.dll: VerQueryValueW
> winmm.dll: timeGetTime
> wsock32.dll: -
( 0 exports )
TrID : File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
ThreatExpert:
http://www.threatexpert.com/report.aspx ... 3677b838acssdeep: 6144:FRT9A65pP1wlYgrN1y6V1X1RonMequ8+my5ET7aP3:RA65XwlYgrHy6V17kr8+m73aP3
sigcheck: publisher....: n/a
copyright....: n/a
product......: n/a
description..:
original name: n/a
internal name: n/a
file version.: 3, 2, 10, 0
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
Prevx Info:
http://info.prevx.com/aboutprogramtext. ... 0041DD48E0PEiD : -
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX
CWSandbox:
http://research.sunbelt-software.com/pa ... 3677b838acRDS : NSRL Reference Data Set
Tech tam je O.o