C0NIME.EXE,C0NIMEO.EXE


 附件: 您所在的用户组无法下载或查看附件


 附件: 您所在的用户组无法下载或查看附件

解压密码:virus

文件说明符 : C:\WINDOWS\system32\C0NIME.EXE (数字0

属性 : A---
数字签名:否
PE文件:是
获取文件版本信息大小失败!
创建时间 : 2008-8-19 18:4:6
修改时间 : 2008-8-19 18:4:6
大小 : 170564 字节 166.580 KB
MD5 : d6363e40553c4ad2c0339c187e84f0f3
SHA1: F8FE0DA49D7DA655561AB602E94D14CB4E2EA029
CRC32: a75055c7

文件说明符 : C:\WINDOWS\system32\C0NIMEO.EXE (数字0
属性 : A---
数字签名:否
PE文件:是
获取文件版本信息大小失败!
创建时间 : 2008-8-20 8:40:51
修改时间 : 2008-8-20 8:40:46
大小 : 46088 字节 45.8 KB
MD5 : 6bee77700ea7fa3b90cf79b8907ece8d
SHA1: 461E7EE961CEB26FC9C4B38DF11BD2309B674B19
CRC32: 42df86dc

文件 C0NIME.EXE 接收于 2008.09.07 11:29:25 (CET)
反病毒引擎版本最后更新扫描结果
AhnLab-V32008.9.6.02008.09.06Win-Trojan/Agent.170564
AntiVir7.8.1.282008.09.05HEUR/Crypted
Authentium5.1.0.42008.09.06W32/Heuristic-210!Eldorado
Avast4.8.1195.02008.09.06Win32:Trojan-gen {Other}
AVG8.0.0.1612008.09.07SHeur.BYWB
BitDefender7.22008.09.07-
CAT-QuickHeal9.502008.09.06(Suspicious) - DNAScan
ClamAV0.93.12008.09.07-
DrWeb4.44.0.091702008.09.07DLOADER.Trojan
eSafe7.0.17.02008.09.03Suspicious File
eTrust-Vet31.6.60722008.09.05Win32/Maycon.A
Ewido4.02008.09.06-
F-Prot4.4.4.562008.09.06W32/Heuristic-210!Eldorado
F-Secure8.0.14332.02008.09.07W32/Suspicious_U.gen
Fortinet3.112.0.02008.09.07-
GData192008.09.07Win32:Trojan-gen
IkarusT3.1.1.34.02008.09.07Virus.Win32.Trojan
K7AntiVirus7.10.4432008.09.05-
Kaspersky7.0.0.1252008.09.07Heur.Trojan.Generic
McAfee53782008.09.05New Malware.aj
Microsoft1.39032008.09.07-
NOD32v234232008.09.06-
Norman5.80.022008.09.05W32/Packed_Upack.A
Panda9.0.0.42008.09.06Suspicious file
PCTools4.4.2.02008.09.06Packed/Upack
Prevx1V22008.09.07Malicious Software
Rising20.60.62.002008.09.07-
Sophos4.33.02008.09.07Mal/Emogen-P
Sunbelt3.1.1610.12008.09.05VIPRE.Suspicious
Symantec102008.09.07-
TheHacker6.3.0.8.0752008.09.06W32/Behav-Heuristic-060
TrendMicro8.700.0.10042008.09.05PAK_Generic.006
VBA323.12.8.52008.09.06-
ViRobot2008.9.5.13652008.09.06-
VirusBuster4.5.11.02008.09.06Packed/Upack
Webwasher-Gateway6.6.22008.09.05Heuristic.Crypted

附加信息
File size: 170564 bytes
MD5...: d6363e40553c4ad2c0339c187e84f0f3
SHA1..: f8fe0da49d7da655561ab602e94d14cb4e2ea029
SHA256: 7974a9f8f5f198d819e215a1eb9c72514e7db2905e25af03afda5897a9f45702
SHA512: ef90505a49576987a11a8c2efd7b691268f8196a94a1a3af59a6e8d26f232f33
c4f49342f3afabad5178c557d6387e95a95856e67514ee1d308d1bead756f1a7
PEiD..: -
TrID..: File type identification
DOS Executable Generic (100.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x801018
timedatestamp.....: 0x8011b0beL (invalid)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
PS 0x1000 0x7b000 0x1f0 5.41 f4a6b56d98913f21ac94b01490b713dc
W 0x7c000 0x31000 0x29844 7.99 df748e4d56003d30d72e249ee6542581
0xad000 0x1000 0x1f0 5.41 f4a6b56d98913f21ac94b01490b713dc

( 0 imports )

( 0 exports )
ThreatExpert info: http://www.threatexpert.com/repo ... ad2c0339c187e84f0f3
packers (Kaspersky): PE_Patch, UPack
Prevx info: http://info.prevx.com/aboutprogr ... 2FB61C7CC0055AAA4D5
packers (F-Prot): UPack
packers (Authentium): UPack


文件 C0NIMEO.EXE 接收于 2008.09.07 11:20:58 (CET)
反病毒引擎版本最后更新扫描结果
AhnLab-V32008.9.6.02008.09.06-
AntiVir7.8.1.282008.09.05TR/Hijacker.Gen
Authentium5.1.0.42008.09.06W32/Injector.A.gen!Eldorado
Avast4.8.1195.02008.09.06-
AVG8.0.0.1612008.09.07-
BitDefender7.22008.09.07Trojan.Generic.654928
CAT-QuickHeal9.502008.09.06(Suspicious) - DNAScan
ClamAV0.93.12008.09.07-
DrWeb4.44.0.091702008.09.07DLOADER.Trojan
eSafe7.0.17.02008.09.03Suspicious File
eTrust-Vet31.6.60722008.09.05-
Ewido4.02008.09.06-
F-Prot4.4.4.562008.09.06W32/Injector.A.gen!Eldorado
F-Secure8.0.14332.02008.09.07W32/Suspicious_U.gen
Fortinet3.112.0.02008.09.07-
GData192008.09.07-
IkarusT3.1.1.34.02008.09.07-
K7AntiVirus7.10.4432008.09.05-
Kaspersky7.0.0.1252008.09.07-
McAfee53782008.09.05New Malware.aj
Microsoft1.39032008.09.07Trojan:Win32/SystemHijack.gen
NOD32v234232008.09.06probably unknown NewHeur_PE virus
Norman5.80.022008.09.05W32/Packed_Upack.A
Panda9.0.0.42008.09.06Suspicious file
PCTools4.4.2.02008.09.06Packed/Upack
Prevx1V22008.09.07-
Rising20.60.62.002008.09.07-
Sophos4.33.02008.09.07Mal/Delf-M
Sunbelt3.1.1610.12008.09.05VIPRE.Suspicious
Symantec102008.09.07-
TheHacker6.3.0.8.0752008.09.06W32/Behav-Heuristic-060
TrendMicro8.700.0.10042008.09.05PAK_Generic.006
VBA323.12.8.52008.09.06suspected of Win32 Shadow AutoStart Install
ViRobot2008.9.5.13652008.09.06-
VirusBuster4.5.11.02008.09.06Packed/Upack
Webwasher-Gateway6.6.22008.09.05Trojan.Hijacker.Gen


附加信息
File size: 46088 bytes
MD5...: 6bee77700ea7fa3b90cf79b8907ece8d
SHA1..: 461e7ee961ceb26fc9c4b38df11bd2309b674b19
SHA256: a52e8b2e3d31618408631f3fd5a383c5e235585c42fa1d22c1b5d7ec83d4f34d
SHA512: 69762afc41caa1605a2b8d55d0fb43ee76c7940c3150d1e3bd86bf7c2e94ebd5
f952ff0c2db7ae8a6a393adc705eacd9a4a9b6f095ac857e68fc7e8dcce87699
PEiD..: -
TrID..: File type identification
DOS Executable Generic (100.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x801018
timedatestamp.....: 0x8011b0beL (invalid)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
PS 0x1000 0x22000 0x1f0 5.35 e265149300271c7f7661266454d7375e
0x23000 0x13000 0xb208 7.99 6f68d3b04506093b9fe57c4ab21dd049
Y_ 0x36000 0x1000 0x1f0 5.35 e265149300271c7f7661266454d7375e

( 0 imports )

( 0 exports )
packers (Kaspersky): PE_Patch, UPack


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Maxthon)
http://blog.csdn.net/purpleendurer

宠辱不惊,笑看堂前花开花落; 去留无意,漫随天外云卷云舒。