6091f8462733811243247323604dbc3c-----nsDk.dll.rar


 附件: 您所在的用户组无法下载或查看附件

O2 - IeAddOn(HkcuExSt) -  - {57CC5BE6-65FB-4533-B5C3-11DF00ACC50B} = C:\WINDOWS\system32\nsDk.dll

文件说明符 : C:\WINDOWS\system32\nsDk.dll
属性 : ----
数字签名:否
PE文件:是
获取文件版本信息大小失败!
创建时间 : 2008-4-14 20:0:0
修改时间 : 2008-4-14 20:0:0
大小 : 53248 字节 52.0 KB
MD5 : 6091f8462733811243247323604dbc3c
SHA1: 49C66E1D34CD47F2FBFD2F27258BC4402CCE77D0
CRC32: 7279b9b5

文件 nsDk.dll 接收于 2010.06.22 14:46:23 (UTC)
反病毒引擎版本最后更新扫描结果
a-squared5.0.0.302010.06.22Trojan.Win32.Jkfg!IK
AhnLab-V32010.06.22.022010.06.22Win-Trojan/Agent.53248.AIQ
AntiVir8.2.2.62010.06.22TR/Crypt.XPACK.Gen
Antiy-AVL2.0.3.72010.06.22-
Authentium5.2.0.52010.06.22W32/Koutodoor.J.gen!Eldorado
Avast4.8.1351.02010.06.22Win32:Caxnet
Avast55.0.332.02010.06.22Win32:Caxnet
AVG9.0.0.7872010.06.22Win32/Cryptor
BitDefender7.22010.06.22Gen:Variant.Koutodoor.3
CAT-QuickHeal10.002010.06.22-
ClamAV0.96.0.3-git2010.06.22-
Comodo51832010.06.22TrojWare.Win32.Zybr.B
DrWeb5.0.2.033002010.06.22Trojan.Siggen1.49071
eSafe7.0.17.02010.06.22-
eTrust-Vet36.1.76582010.06.22-
F-Prot4.6.1.1072010.06.21W32/Koutodoor.J.gen!Eldorado
F-Secure9.0.15370.02010.06.22Gen:Variant.Koutodoor.3
Fortinet4.1.133.02010.06.22-
GData212010.06.22Gen:Variant.Koutodoor.3
IkarusT3.1.1.84.02010.06.22Trojan.Win32.Jkfg
Jiangmin13.0.9002010.06.15Heur:Trojan/JunkCode
Kaspersky7.0.0.1252010.06.22Trojan.Win32.Jkfg.qs
McAfee5.400.0.11582010.06.22BackDoor-EPM.gen.a
McAfee-GW-Edition2010.12010.06.22BackDoor-EPM.gen.a
Microsoft1.59022010.06.22Trojan:Win32/Koutodoor.C!dll
NOD3252182010.06.22-
Norman6.05.102010.06.22-
nProtect2010-06-22.012010.06.22Gen:Variant.Koutodoor.3
Panda10.0.2.72010.06.21Trj/Jkfg.B
PCTools7.0.3.52010.06.22-
Prevx3.02010.06.22Medium Risk Malware
Rising22.53.01.042010.06.22-
Sophos4.54.02010.06.22Troj/BHO-PX
Sunbelt64832010.06.21-
Symantec20101.1.0.892010.06.22-
TheHacker6.5.2.0.3022010.06.22Trojan/Jkfg.qs
TrendMicro9.120.0.10042010.06.22-
TrendMicro-HouseCall9.120.0.10042010.06.22-
VBA323.12.12.52010.06.22Trojan.Win32.Jkfg.qs
ViRobot2010.6.21.38962010.06.22Trojan.Win32.Jkfg.53248
VirusBuster5.0.27.02010.06.22-

附加信息
File size: 53248 bytes
MD5...: 6091f8462733811243247323604dbc3c
SHA1..: 49c66e1d34cd47f2fbfd2f27258bc4402cce77d0
SHA256: 4ecf2a4c63eaee3a7d551c70662bcd82de7577621222dbdf4ea3bff0a2f67450
ssdeep: 1536:aAEuW40wl3K9AOChYpGda/Mtr2TtgH2n:abL4Vl3K9AjSsa/MR2JgH2<BR>
PEiD..: -
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x7f81<BR>timedatestamp.....: 0x4c113b5b (Thu Jun 10 19:22:03 2010)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 5 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x7030 0x8000 6.32 2cbc9168829178fc2ba8d0287db52c30<BR>.rdata 0x9000 0xbc4 0x1000 4.25 09289effa121510f3c3da79bc524f48a<BR>.data 0xa000 0xfcc 0x1000 5.55 60b38a046a9b098458c94d110e77eaec<BR>.rsrc 0xb000 0x650 0x1000 1.51 a32641df552fa0b2fa66cd29371e7a62<BR>.reloc 0xc000 0x6a8 0x1000 3.21 be4f84f1307be431cb3d3cacf3b09fa6<BR><BR>( 7 imports ) <BR>> KERNEL32.dll: GetLocalTime, WritePrivateProfileStringA, GetModuleFileNameA, GetWindowsDirectoryA, GetSystemDirectoryA, GetProcAddress, DeleteFileA, LeaveCriticalSection, EnterCriticalSection, GetLastError, CreateEventA, MoveFileA, SetFileAttributesA, MultiByteToWideChar, FindNextFileA, FindFirstFileA, GetCommandLineW, DisableThreadLibraryCalls, Process32First, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, HeapAlloc, GetSystemInfo, GetVersionExA, HeapCreate, HeapDestroy, lstrlenW, lstrlenA, GetShortPathNameA, GetModuleHandleA, Sleep, CreateThread, WideCharToMultiByte, Process32Next, CloseHandle, LoadLibraryA, FreeLibrary, InitializeCriticalSection, GetCurrentProcessId<BR>> USER32.dll: GetMessageA, TranslateMessage, DispatchMessageA, CallNextHookEx, SetWindowTextA, SendMessageA, RegisterClassExA, IsWindow, ShowWindow, FindWindowExA, KillTimer, SetTimer, PostMessageA, DefWindowProcA, CreateWindowExA<BR>> ADVAPI32.dll: RegSetValueExA, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey<BR>> SHELL32.dll: CommandLineToArgvW<BR>> ole32.dll: CoInitialize, CoCreateInstance<BR>> OLEAUT32.dll: -, -, -, -, -<BR>> MSVCRT.dll: _strlwr, memcmp, memcpy, _purecall, strchr, fopen, fwrite, free, _initterm, malloc, _adjust_fdiv, _stricmp, rand, fclose, strrchr, strcmp, __2@YAPAXI@Z, memset, _access, strstr, strlen, sprintf, __3@YAXPAX@Z, strcpy, strcat<BR><BR>( 4 exports ) <BR>DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer<BR>
RDS...: NSRL Reference Data Set<BR>-
pdfid.: -
trid..: Win32 Executable Generic (42.3%)<BR>Win32 Dynamic Link Library (generic) (37.6%)<BR>Generic Win/DOS Executable (9.9%)<BR>DOS Executable Generic (9.9%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
Symantec Reputation Network: Suspicious.Insight http://www.symantec.com/security ... 2010-021223-0550-99
sigcheck:<BR>publisher....: n/a<BR>copyright....: n/a<BR>product......: n/a<BR>description..: n/a<BR>original name: n/a<BR>internal name: n/a<BR>file version.: n/a<BR>comments.....: n/a<BR>signers......: -<BR>signing date.: -<BR>verified.....: Unsigned<BR>
<a href='http://info.prevx.com/aboutprogramtext.asp?PX5=644B84E100073E4DD05F001D8D517300EE9F0810' target='_blank'>http://info.prevx.com/aboutprogr ... D517300EE9F0810&;lt;/a>


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; QQDownload 1.7; Maxthon)
http://blog.csdn.net/purpleendurer

宠辱不惊,笑看堂前花开花落; 去留无意,漫随天外云卷云舒。