D
delhpi
Unregistered / Unconfirmed
GUEST, unregistred user!
已经排除了最近那个 SYSCONST.DCU嵌入代码的病毒。反病毒引擎 版本 最后更新 扫描结果 a-squared 4.5.0.24 2009.08.20 Trojan-Downloader.Win32.Banload!IK AhnLab-V3 5.0.0.2 2009.08.20 - AntiVir 7.9.1.3 2009.08.19 - Antiy-AVL 2.0.3.7 2009.08.20 Trojan/Win32.Banload.gen Authentium 5.1.2.4 2009.08.19 - Avast 4.8.1335.0 2009.08.19 - AVG 8.5.0.406 2009.08.19 - BitDefender 7.2 2009.08.20 - CAT-QuickHeal 10.00 2009.08.19 TrojanDownloader.Banload.wsl ClamAV 0.94.1 2009.08.20 Trojan.Downloader-52652 Comodo 2030 2009.08.20 - DrWeb 5.0.0.12182 2009.08.20 - eTrust-Vet 31.6.6688 2009.08.19 - F-Prot 4.4.4.56 2009.08.19 - F-Secure 8.0.14470.0 2009.08.19 - Fortinet 3.120.0.0 2009.08.20 - GData 19 2009.08.20 - Ikarus T3.1.1.68.0 2009.08.20 Trojan-Downloader.Win32.Banload Jiangmin 11.0.800 2009.08.19 - K7AntiVirus 7.10.822 2009.08.19 Trojan-Downloader.Win32.Banload Kaspersky 7.0.0.125 2009.08.20 - McAfee 5714 2009.08.19 - McAfee+Artemis 5714 2009.08.19 - McAfee-GW-Edition 6.8.5 2009.08.19 Heuristic.LooksLike.Win32.Banload.I Microsoft 1.4903 2009.08.19 - NOD32 4349 2009.08.19 Win32/Delf.OQX Norman 6.01.09 2009.08.19 W32/Banload.AKJV nProtect 2009.1.8.0 2009.08.19 Trojan-Downloader/W32.Banload.370176.H Panda 10.0.0.14 2009.08.19 Trj/Nabload.ACN PCTools 4.4.2.0 2009.08.19 - Prevx 3.0 2009.08.20 High Risk Worm Rising 21.43.30.00 2009.08.20 - Sophos 4.44.0 2009.08.20 - Sunbelt 3.2.1858.2 2009.08.20 - Symantec 1.4.4.12 2009.08.20 - TheHacker 6.3.4.3.383 2009.08.13 Trojan/Downloader.Banload.aedv TrendMicro 8.950.0.1094 2009.08.20 - VBA32 3.12.10.9 2009.08.20 - ViRobot 2009.8.20.1892 2009.08.20 - VirusBuster 4.6.5.0 2009.08.19 - 附加信息 File size: 370176 bytes MD5...: 9c6e553a4e26244af8d1c29ae9c3c70c SHA1..: 409d869a26fe06f6ba50eac460c932f0fd16c493 SHA256: bbbb0b4ec7b0d0dafa94a2864f33e098b7fd11447b5bf288b87da184f242184a ssdeep: 6144:jjb9Jf117o1jqRnPDGVxmMMFeLOy7drQGZEAYYmQfp8L6Kl:/b9J91c1APqVx/VLO4EACP6g PEiD..: BobSoft Mini Delphi -> BoB / BobSoft TrID..: File type identificationWin32 Executable Borland Delphi 7 (69.1%)Win32 Executable Borland Delphi 6 (27.0%)Win32 Executable Delphi generic (1.5%)Win32 Executable Generic (0.8%)Win32 Dynamic Link Library (generic) (0.7%) PEInfo: PE Structure information( base data )entrypointaddress.: 0x4d320timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)machinetype.......: 0x14c (I386)( 8 sections )name viradd virsiz rawdsiz ntrpy md5CODE 0x1000 0x4c368 0x4c400 6.53 08af9ffcd3c406d31b83dae30cc8328cDATA 0x4e000 0x1124 0x1200 4.05 d9ce20782198ada98c359d6d39244555BSS 0x50000 0xbd9 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e.idata 0x51000 0x1f2a 0x2000 4.96 c8b543b87d8693f2a71754f9d0d5a184.tls 0x53000 0x10 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e.rdata 0x54000 0x18 0x200 0.21 de85a91d4020adeb5b34c6aceb8dee5e.reloc 0x55000 0x5544 0x5600 6.67 00db975e4f118f9f9a5e1a9825ff4be7.rsrc 0x5b000 0x5400 0x5400 4.19 087af3885e326163256ee9bfc6ea2290( 13 imports ) > kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetVersion, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle> user32.dll: GetKeyboardType, LoadStringA, MessageBoxA, CharNextA> advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey> oleaut32.dll: SysFreeString, SysReAllocStringLen, SysAllocStringLen> kernel32.dll: TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA> advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey> kernel32.dll: lstrcpyA, WriteFile, WaitForSingleObject, VirtualQuery, VirtualAlloc, Sleep, SizeofResource, SetThreadLocale, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResetEvent, ReadFile, MulDiv, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GlobalUnlock, GlobalReAlloc, GlobalHandle, GlobalLock, GlobalFree, GlobalFindAtomA, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetVersionExA, GetVersion, GetTickCount, GetThreadLocale, GetSystemInfo, GetStringTypeExA, GetStdHandle, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCurrentProcessId, GetCPInfo, GetACP, FreeResource, InterlockedExchange, FreeLibrary, FormatMessageA, FindResourceA, EnumCalendarInfoA, EnterCriticalSection, DeleteCriticalSection, CreateThread, CreateFileA, CreateEventA, CompareStringA, CloseHandle> version.dll: VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA> gdi32.dll: UnrealizeObject, StretchBlt, SetWindowOrgEx, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RestoreDC, RectVisible, RealizePalette, PatBlt, MoveToEx, MaskBlt, LineTo, IntersectClipRect, GetWindowOrgEx, GetTextMetricsA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetPixel, GetPaletteEntries, GetObjectA, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, ExcludeClipRect, DeleteObject, DeleteDC, CreateSolidBrush, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectA, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, BitBlt> user32.dll: CreateWindowExA, WindowFromPoint, WinHelpA, WaitMessage, UpdateWindow, UnregisterClassA, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, SystemParametersInfoA, ShowWindow, ShowScrollBar, ShowOwnedPopups, ShowCursor, SetWindowsHookExA, SetWindowPos, SetWindowPlacement, SetWindowLongA, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropA, SetParent, SetMenuItemInfoA, SetMenu, SetForegroundWindow, SetFocus, SetCursor, SetClassLongA, SetCapture, SetActiveWindow, SendMessageA, ScrollWindow, ScreenToClient, RemovePropA, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageA, RegisterClipboardFormatA, RegisterClassA, RedrawWindow, PtInRect, PostQuitMessage, PostMessageA, PeekMessageA, OffsetRect, OemToCharA, MessageBoxA, MapWindowPoints, MapVirtualKeyA, LoadStringA, LoadKeyboardLayoutA, LoadIconA, LoadCursorA, LoadBitmapA, KillTimer, IsZoomed, IsWindowVisible, IsWindowEnabled, IsWindow, IsRectEmpty, IsIconic, IsDialogMessageA, IsChild, InvalidateRect, IntersectRect, InsertMenuItemA, InsertMenuA, InflateRect, GetWindowThreadProcessId, GetWindowTextA, GetWindowRect, GetWindowPlacement, GetWindowLongA, GetWindowDC, GetTopWindow, GetSystemMetrics, GetSystemMenu, GetSysColorBrush, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetPropA, GetParent, GetWindow, GetMenuStringA, GetMenuState, GetMenuItemInfoA, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextA, GetIconInfo, GetForegroundWindow, GetFocus, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClientRect, GetClassNameA, GetClassInfoA, GetCapture, GetActiveWindow, FrameRect, FindWindowA, FillRect, EqualRect, EnumWindows, EnumThreadWindows, EndPaint, EnableWindow, EnableScrollBar, EnableMenuItem, DrawTextA, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawEdge, DispatchMessageA, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcA, DefMDIChildProcA, DefFrameProcA, CreatePopupMenu, CreateMenu, CreateIcon, ClientToScreen, CheckMenuItem, CallWindowProcA, CallNextHookEx, BeginPaint, CharNextA, CharLowerA, CharToOemA, AdjustWindowRectEx, ActivateKeyboardLayout> kernel32.dll: Sleep> oleaut32.dll: SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit> comctl32.dll: ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_SetDragCursorImage, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Remove, ImageList_DrawEx, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create( 0 exports ) PDFiD.: - RDS...: NSRL Reference Data Set- Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=29B0426000362671A69105114F702100B86057A6' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=29B0426000362671A69105114F702100B86057A6</a>