C:\WINDOWS\system32\Vstar.exe


 附件: 您所在的用户组无法下载或查看附件

解压密码:virus

文件说明符 : C:\WINDOWS\system32\Vstar.exe
属性 : A---
数字签名:否
PE文件:是
获取文件版本信息大小失败!
创建时间 : 2008-8-19 18:4:10
修改时间 : 2008-8-20 8:40:42
大小 : 167928 字节 163.1016 KB
MD5 : 7c67dd0ded099088d877c422bef7f48d
SHA1: 7BCDE157A4D57D9467490B4759662BA7A4C7620C
CRC32: c47b7d3c

文件 Vstar.exe 接收于 2008.09.07 15:46:53 (CET)
反病毒引擎版本最后更新扫描结果
AhnLab-V32008.9.6.02008.09.07Win-Trojan/Clicker.167928
AntiVir7.8.1.282008.09.05HEUR/Malware
Authentium5.1.0.42008.09.06W32/Heuristic-210!Eldorado
Avast4.8.1195.02008.09.06Win32:Trojan-gen {Other}
AVG8.0.0.1612008.09.07SHeur.BZYB
BitDefender7.22008.09.07Trojan.Generic.581775
CAT-QuickHeal9.502008.09.06(Suspicious) - DNAScan
ClamAV0.93.12008.09.07-
DrWeb4.44.0.091702008.09.07DLOADER.Trojan
eSafe7.0.17.02008.09.07Suspicious File
eTrust-Vet31.6.60722008.09.05-
Ewido4.02008.09.07-
F-Prot4.4.4.562008.09.06W32/Heuristic-210!Eldorado
F-Secure8.0.14332.02008.09.07W32/Suspicious_U.gen
Fortinet3.112.0.02008.09.07PossibleThreat
GData192008.09.07Win32:Trojan-gen
IkarusT3.1.1.34.02008.09.07Virus.Win32.Trojan
K7AntiVirus7.10.4432008.09.05Trojan.Win32.Malware.1
Kaspersky7.0.0.1252008.09.07Heur.Trojan.Generic
McAfee53782008.09.05Generic.dx
Microsoft1.39032008.09.07-
NOD32v234232008.09.06Win32/TrojanDownloader.Delf.OFT
Norman5.80.022008.09.05W32/Packed_Upack.A
Panda9.0.0.42008.09.07Suspicious file
PCTools4.4.2.02008.09.07Packed/Upack
Prevx1V22008.09.07Fraudulent Security Program
Rising20.60.62.002008.09.07-
Sophos4.33.02008.09.07Sus/ComPack-K
Sunbelt3.1.1610.12008.09.05VIPRE.Suspicious
Symantec102008.09.07-
TheHacker6.3.0.8.0752008.09.06W32/Behav-Heuristic-060
TrendMicro8.700.0.10042008.09.05PAK_Generic.006
VBA323.12.8.52008.09.07-
ViRobot2008.9.5.13652008.09.06-
VirusBuster4.5.11.02008.09.06Packed/Upack
Webwasher-Gateway6.6.22008.09.05Heuristic.Malware


附加信息
File size: 167928 bytes
MD5...: 7c67dd0ded099088d877c422bef7f48d
SHA1..: 7bcde157a4d57d9467490b4759662ba7a4c7620c
SHA256: c8d92f65664c4e19fc6ab80af7449f3e0d5a8aadf8419993f412f5c060922763
SHA512: 5b571e9bcbbf0e014ce4ff481583f2774998d7e1a06592766055ecdb9a2645ac
1814136c98a71be97cbdd584cd61ca92a5e985acdf00210f6fc5a1654bcace05
PEiD..: -
TrID..: File type identification
DOS Executable Generic (100.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x801018
timedatestamp.....: 0x8011b0beL (invalid)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
PS 0x1000 0x78000 0x1f0 5.42 ec5abf4b8f2d05b60bb6515985e3d7ae
0x79000 0x30000 0x28df8 7.99 3f0a7be66fbe776b7d3e22fb72ad93e8
0xa9000 0x1000 0x1f0 5.42 ec5abf4b8f2d05b60bb6515985e3d7ae

( 0 imports )

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogr ... 2807518C200E0C1D215
ThreatExpert info: http://www.threatexpert.com/repo ... 088d877c422bef7f48d
packers (Authentium): UPack
packers (F-Prot): UPack
packers (Kaspersky): PE_Patch, UPack


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Maxthon)
最后编辑麦青儿 最后编辑于 2008-09-08 00:04:49
http://blog.csdn.net/purpleendurer

宠辱不惊,笑看堂前花开花落; 去留无意,漫随天外云卷云舒。