This is a report processed by VirusTotal on 03/25/2006 at 22:01:28 (CET) after scanning the file "boot.exe" file.
Antivirus Version Update Result
AntiVir 6.34.0.14 03.25.2006 Heuristic/Crypted.Modified
Avast 4.6.695.0 03.25.2006 no virus found
AVG 386 03.24.2006 no virus found
Avira 6.34.0.54 03.25.2006 no virus found
BitDefender 7.2 03.25.2006 Dropped:Generic.Malware.SBdld.C27EE256
CAT-QuickHeal 8.00 03.25.2006 (Suspicious) - DNAScan
ClamAV devel-20060202 03.24.2006 no virus found
DrWeb 4.33 03.25.2006 DLOADER.Trojan
eTrust-InoculateIT 23.71.111 03.25.2006 no virus found
eTrust-Vet 12.4.2133 03.24.2006 no virus found
Ewido 3.5 03.25.2006 no virus found
Fortinet 2.71.0.0 03.25.2006 suspicious
F-Prot 3.16c 03.23.2006 could be infected with an unknown virus
Ikarus 0.2.59.0 03.24.2006 no virus found
Kaspersky 4.0.2.24 03.25.2006 no virus found
McAfee 4726 03.24.2006 New Malware.n
NOD32v2 1.1458 03.24.2006 probably unknown NewHeur_PE virus
Norman 5.70.10 03.24.2006 W32/Malware
Panda 9.0.0.4 03.25.2006 Suspicious file
Sophos 4.04.0 03.25.2006 no virus found
Symantec 8.0 03.25.2006 no virus found
TheHacker 5.9.7.119 03.24.2006 no virus found
UNA 1.83 03.23.2006 no virus found
VBA32 3.10.5 03.24.2006 no virus found
EF checksum Manager:
5b0d7f335ab2caf84492ad16d5488707 *boot.exe
1c41f534a2a546fb2d2eb6826c87bcc2 *boot.hta
950816b199757c6f95f38ecb5730e3f0 *CTFM0N.EXE
d9b00b2d3e5fac95232d705d31d910b6 *foo
bee2d56838823f13c1fcb5a28b565342 *GServers.inf
b8b8d3837430683b8beff77c346b0655 *LServers.inf
8e5d4b7b48533a77e171c1cdaa10aa60 *m1.exe
1282933e75046660dcfcf5684680b537 *m2.exe
d05de03c17208f09a333cec5228778e6 *m3.exe
d05de03c17208f09a333cec5228778e6 *m4.exe
e9cd6ba14c866e20e8867e26d79ecb6e *m5.exe
8862cda1204e91cc3561b22c17eed901 *m6.exe
ab652dab12afdad853fd59207dd2d68b *Packet.dll
ab44be5bef7864ced429720f2b827c16 *SVCH0ST.exe
d05de03c17208f09a333cec5228778e6 *svchpst.exe
e9cd6ba14c866e20e8867e26d79ecb6e *svchpsz.exe
8e5d4b7b48533a77e171c1cdaa10aa60 *svchs0t.exe
12aa2da30d1d2889511b4c1d14fb99b9 *WanPacket.dll
bitdefender:
boot.exe Suspect: Dropped:Generic.Malware.SBdld.C27EE256
m2.exe Infected: BehavesLike:Win32.FileInfector
m3.exe Suspect: Dropped:Generic.Malware.SM.7976D641
m4.exe Suspect: Dropped:Generic.Malware.SM.7976D641
unpackedm2.exe Infected: BehavesLike:Win32.FileInfector
unpackedm3.ExE Suspect: BehavesLike:Trojan.Downloader
unpackedm4.ExE Suspect: BehavesLike:Trojan.Downloader
svchpst.exe Suspect: Dropped:Generic.Malware.SM.7976D641
CTFM0N.EXE Infected: Trojan.NSAnti.A
SVCH0ST.exe Infected: Trojan.NSAnti.A
svchpsz.exe和m5和FSG加壳的m1没有报出,脱壳也未报出。其它全部启发。
Dr.web:
ctfmon和svchost是007加壳,除了这两个其它的Dr.web都能启发和报出。
vba32:
D:\virusanalysis\sniffer\boot.hta : 感染了 Trojan-Downloader.JS.Psyme.as#1
D:\virusanalysis\sniffer\CTFM0N.EXE : 是可疑的 Backdoor.PcClient.24
D:\virusanalysis\sniffer\m1.exe : 是可疑的 Malware.Agent.115 (paranoid heuristics)
D:\virusanalysis\sniffer\m2.exe : 是可疑的 Malware.Agent.86
D:\virusanalysis\sniffer\m2_Unpack.exe : 是可疑的 Trojan-PSW.Lmir.24
D:\virusanalysis\sniffer\m5.exe : 是可疑的 Malware.Agent.115 (paranoid heuristics)
D:\virusanalysis\sniffer\m6.exe:<RAR>\CTFM0N.EXE : 是可疑的 Backdoor.PcClient.24
D:\virusanalysis\sniffer\m6.exe:<RAR>\SVCH0ST.exe : 是可疑的 Backdoor.PcClient.24
D:\virusanalysis\sniffer\SVCH0ST.exe : 是可疑的 Backdoor.PcClient.24
D:\virusanalysis\sniffer\svchpsz.exe : 是可疑的 Malware.Agent.115 (paranoid heuristics)
D:\virusanalysis\sniffer\unpackedm1.ExE : 是可疑的 Malware.Agent.115 (paranoid heuristics)
D:\virusanalysis\sniffer\unpackedm5.ExE : 是可疑的 Malware.Agent.115 (paranoid heuristics)
D:\virusanalysis\sniffer\unpackedsvchpsz.ExE : 是可疑的 Malware.Agent.115 (paranoid heuristics)
也不理想,m3,m4,svchpst,boot.exe,都没有报出。