a-squared4.5.0.242009.09.10Trojan-Dropper.Agent!IKAhnLab-V35.0.0.22009.09.10-AntiVir7.9.1.142009.09.10-Antiy-AVL2.0.3.72009.09.10Trojan/Win32.Agent.genAuthentium5.1.2.42009.09.09-Avast4.8.1351.02009.09.09-AVG8.5.0.4122009.09.10-BitDefender7.22009.09.10-CAT-QuickHeal10.002009.09.10-ClamAV0.94.12009.09.10Trojan.Downloader-76358Comodo22722009.09.10TrojWare.Win32.TrojanDown loader.Agent.cmtmDrWeb5.0.0.121822009.09.10-eSafe7.0.17.02009.09.09-eTrust-Vet31.6.67282009.09.09-F-Prot4.5.1.852009.09.09-F-Secure8.0.14470.02009.09.10Trojan-Downloader.Win32.Agent.cmtmFortinet3.120.0.02009.0 9.10W32/Agent.CMTM!tr.dldrGData192009.09.10-IkarusT3.1.1.72.02009.09.10Trojan-Dropper.AgentJiangmin11.0.8002009.09.10-K7AntiVirus7.10.8402009.09.09-Kaspersky7.0.0.1252009.09.10Trojan-Downloader.Win32.Agent.cmtmMcAfee57362009.09.09-McAfee+Artemis57362009.09.09-McAfee-
GW-Edition6.8.52009.09.10Heuristic.BehavesLike.Win32. Worm.IMicrosoft1.50052009.09.10-NOD3244132009.09.10-Norman6.01.092009.09.09-nProtect2009.1.8.02009.09.10Trojan-Downloader/W32.Agent.520181Panda10.0.2.22009.09.09Suspicious filePCTools4.4.2.02009.09.09-Prevx3.02009.09.10-Rising21.46.32.002009.09.10-Sophos4.45.02009.09.10-Sunbelt3.2.1858.22009.09.10-Symantec1.4.4.122009.09.10-TheHacker6.3.4.3.3992009.09.09-TrendMicro8.950.0.10942009.09.10-VBA323.12.10.102009.09.09Trojan-Downloader.Win32.Agent.cmtmViRobot2009.9.10.192820 09.09.10-VirusBuster4.6.5.02009.09.09-Information additionnelleFile size: 520181 bytesMD5...: f83249eac1b9ac10dd20f494caecbee4SHA1..: e69eb584a8b94bf89515f459fb947914911873b4SHA256: 9ddc701ebccdd84906dc8e21791e81088895653d155d2024f4 c00f51808fc5ecssdeep: 12288:ljnpaiYpa34WDbXZ8COrhJmKBQnyBUErJRRsSO4QvNS3 mtxz3cEi+/3IWV
CvVch0:FnpaiYpa34BJz5BUErJ5Eyvl
PEiD..: -PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x1280
timedatestamp.....: 0x4a6ec1a7 (Tue Jul 28 09:15:19 2009)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x4210c 0x42200 6.11 5b872099849592f2861fb21600b11708
.data 0x44000 0x234 0x400 0.91 3d6c70273858cc6d79481c79af2742dc
.rdata 0x45000 0x2a34 0x2c00 5.08 31e0c56670e5b61f26fb5ad469276d13
.bss 0x48000 0x5210 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0x4e000 0xb48 0xc00 5.02 fec182c1aa4dd90aa7dd6e778ead045c
( 5 imports )
> ADVAPI32.DLL: AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken
> KERNEL32.dll: AddAtomA, CloseHandle, CreateFileA, CreateRemoteThread, CreateSemaphoreA, DeleteCriticalSection, EnterCriticalSection, ExitProcess, FindAtomA, GetAtomNameA, GetCommandLineA, GetCurrentProcess, GetExitCodeThread, GetLastError, GetModuleFileNameA, GetModuleHandleA, GetProcAddress, GetStartupInfoA, InitializeCriticalSection, InterlockedDecrement, InterlockedExchange, InterlockedIncrement, IsDBCSLeadByteEx, LeaveCriticalSection, MultiByteToWideChar, OpenProcess, ReleaseSemaphore, SetLastError, SetUnhandledExceptionFilter, Sleep, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, VirtualAllocEx, VirtualFreeEx, WaitForSingleObject, WideCharToMultiByte, WriteProcessMemory
> msvcrt.dll: _fdopen, _read, _strdup, _write
> msvcrt.dll: __getmainargs, __lc_codepage, __mb_cur_max, __p__environ, __p__fmode, __set_app_type, _assert, _cexit, _ctype, _errno, _filelengthi64, _fstati64, _iob, _lseeki64, _onexit, _setmode, abort, atexit, fclose, fflush, fgetpos, fopen, fputc, fread, free, fsetpos, fwrite, getc, getenv, localeconv, malloc, memchr, memcpy, memmove, memset, putc, setlocale, setvbuf, signal, sprintf, strcat, strcmp, strcoll, strcpy, strftime, strlen, strtod, strxfrm, ungetc, wcslen
> USER32.dll: FindWindowA, GetWindowThreadProcessId, MessageBoxA
( 0 exports )
RDS...: NSRL Reference Data Set
-pdfid.: -trid..: Win32 Executable MS Visual C++ (generic) (72.0%)
Win32 Executable Generic (16.2%)
Win16/32 Executable Delphi generic (3.9%)
Generic Win/DOS Executable (3.8%)
DOS Executable Generic (3.8%)
Trojan ?