UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 GTB6 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
File::
c:\windows\system32\drivers\npembp.sys
c:\windows\system32\drivers\joqbqbl.sys
c:\windows\system32\drivers\ohnyam.sys
c:\windows\system32\drivers\wlsbcd.sys
c:\windows\system32\drivers\ugoqlsav.sys
c:\windows\system32\drivers\qnmmzbu.sys
c:\windows\system32\drivers\gtrhei.sys
c:\windows\system32\drivers\gomkurlc.sys
c:\windows\system32\drivers\zgtdthl.sys
c:\windows\system32\drivers\flysqqu.sys
c:\documents and settings\user\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
c:\documents and settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
c:\documents and settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
c:\documents and settings\user\ps_drv.sys
Driver::
npembp
joqbqbl
ohnyam
wlsbcd
ugoqlsav
qnmmzbu
gtrhei
gomkurlc
zgtdthl
flysqqu
jlifwy
GAGPDrv
ps_drv
Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet011\Services\flysqqu]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"=-
"NeroFilterCheck"=-
"QuickTime Task"=-
"SSBkgdUpdate"=-
"IndexSearch"=-
"SunJavaUpdateSched"=-
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 GTB6 (.NET CLR 3.5.30729)
Plik dbghelp.dll otrzymany 2009.07.26 21:15:49 (UTC)
Obecny status: zakończono
Wynik: 0/41 (0.00%)
Zwięzły Zwięzły
Drukuj wyniki Drukuj wyniki
Antywirus Wersja Ostatnia aktualizacja Wynik
a-squared 4.5.0.24 2009.07.26 -
AhnLab-V3 5.0.0.2 2009.07.26 -
AntiVir 7.9.0.228 2009.07.24 -
Antiy-AVL 2.0.3.7 2009.07.24 -
Authentium 5.1.2.4 2009.07.26 -
Avast 4.8.1335.0 2009.07.26 -
AVG 8.5.0.387 2009.07.26 -
BitDefender 7.2 2009.07.26 -
CAT-QuickHeal 10.00 2009.07.25 -
ClamAV 0.94.1 2009.07.26 -
Comodo 1775 2009.07.26 -
DrWeb 5.0.0.12182 2009.07.26 -
eSafe 7.0.17.0 2009.07.26 -
eTrust-Vet 31.6.6640 2009.07.25 -
F-Prot 4.4.4.56 2009.07.26 -
F-Secure 8.0.14470.0 2009.07.26 -
Fortinet 3.120.0.0 2009.07.26 -
GData 19 2009.07.26 -
Ikarus T3.1.1.64.0 2009.07.26 -
Jiangmin 11.0.800 2009.07.26 -
K7AntiVirus 7.10.802 2009.07.25 -
Kaspersky 7.0.0.125 2009.07.26 -
McAfee 5689 2009.07.26 -
McAfee+Artemis 5689 2009.07.26 -
McAfee-GW-Edition 6.8.5 2009.07.26 -
Microsoft 1.4903 2009.07.26 -
NOD32 4280 2009.07.26 -
Norman 6.01.09 2009.07.24 -
nProtect 2009.1.8.0 2009.07.26 -
Panda 10.0.0.14 2009.07.26 -
PCTools 4.4.2.0 2009.07.26 -
Prevx 3.0 2009.07.26 -
Rising 21.39.62.00 2009.07.26 -
Sophos 4.44.0 2009.07.26 -
Sunbelt 3.2.1858.2 2009.07.26 -
Symantec 1.4.4.12 2009.07.26 -
TheHacker 6.3.4.3.374 2009.07.26 -
TrendMicro 8.950.0.1094 2009.07.25 -
VBA32 3.12.10.9 2009.07.26 -
ViRobot 2009.7.25.1853 2009.07.25 -
VirusBuster 4.6.5.0 2009.07.26 -
Dodatkowe informacje
File size: 640000 bytes
MD5 : 81d1ce12e830059b2990514bf66bfb5d
SHA1 : 4bce60904db6b2f8a45fef4037a581bf7ba84b9c
SHA256: af8ef883d3ce0dc6ef3597167cb17334ca27440d4b7729cea7569f77a298f200
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x307E4
timedatestamp.....: 0x48038E20 (Mon Apr 14 19:02:24 2008)
machinetype.......: 0x14C (Intel I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x8E266 0x8E400 6.61 c2653d8c94c3ebd93302254be741a54d
.data 0x90000 0x4A70 0x3600 1.87 78b7fe2c87804fd18f0b94cc06b11e81
.rsrc 0x95000 0x3E8 0x400 3.40 6fb737cde71905cbe930464bcb922217
.reloc 0x96000 0xA070 0xA200 5.40 62dabdd4c17f7257123d82c971c6d091
( 5 imports )
> advapi32.dll: CryptAcquireContextA, CryptGenRandom, CryptReleaseContext, RegOpenKeyExA, RegQueryValueExA, RegQueryValueExW, RegEnumKeyExW, RegQueryInfoKeyW, RegOpenKeyExW, RegCloseKey, SetSecurityDescriptorDacl, InitializeSecurityDescriptor
> kernel32.dll: GetFileType, Sleep, DeviceIoControl, ExpandEnvironmentStringsW, InitializeCriticalSectionAndSpinCount, CopyFileA, SetFileAttributesA, CopyFileW, GetFileAttributesW, SetFileAttributesW, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, InterlockedIncrement, InterlockedDecrement, CreateFileMappingW, LCMapStringW, GetDriveTypeW, GetCurrentProcess, UnmapViewOfFile, GetEnvironmentVariableA, SetLastError, CloseHandle, CreateFileA, GetLastError, SetFilePointer, FindClose, FindNextFileA, FindFirstFileA, CreateDirectoryA, GetFullPathNameA, LocalAlloc, LocalFree, lstrcpyA, GetDriveTypeA, TlsGetValue, TlsAlloc, TlsFree, HeapReAlloc, HeapAlloc, HeapFree, IsDBCSLeadByte, GetProcAddress, GetModuleHandleA, lstrlenA, HeapDestroy, HeapCreate, DisableThreadLibraryCalls, GetVersionExA, MapViewOfFile, CreateFileMappingA, FreeLibrary, GetFileSize, LoadLibraryA, DuplicateHandle, ExpandEnvironmentStringsA, MultiByteToWideChar, WideCharToMultiByte, GetCurrentProcessId, VirtualFree, SetErrorMode, GetFileAttributesA, ReadProcessMemory, VirtualProtect, VirtualAlloc, DeleteFileW, WriteFile, CreateFileW, OutputDebugStringA, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetSystemInfo, GetVersionExW, GetProcessHeap, SuspendThread, ResumeThread, GetThreadContext, VirtualQueryEx, LoadLibraryW, TerminateThread, SetEndOfFile, GetThreadSelectorEntry, MapViewOfFileEx, FlushViewOfFile, TlsSetValue, CreateThread
> msvcrt.dll: __dllonexit, _wcsicmp, wcsncpy, wcscmp, wcsncmp, __CxxFrameHandler, _wsplitpath, _wcsnicmp, towlower, __unDName, fclose, wcstol, _CxxThrowException, bsearch, _snwprintf, fread, fseek, _wfopen, fopen, _osver, _mbsnbcpy, fflush, _iob, _wmakepath, wcsrchr, wcscpy, _wcsdup, ftell, _wgetenv, _mbsicmp, _access, _fullpath, _fsopen, _wfsopen, _sopen, _wsopen, _wfullpath, _read, _write, _onexit, _chsize, _close, _get_osfhandle, _open_osfhandle, _winminor, _winmajor, _mbscmp, _memicmp, wcsncat, _terminate@@YAXXZ, __1type_info@@UAE@XZ, _adjust_fdiv, _initterm, time, memmove, _ftol, swprintf, calloc, wcscat, _ltoa, _itoa, printf, _vsnprintf, strncat, tolower, _strcmpi, _makepath, _purecall, malloc, free, _strlwr, isspace, ctime, strstr, __2@YAPAXI@Z, __3@YAXPAX@Z, qsort, strncmp, _strnicmp, isxdigit, wcslen, sprintf, strrchr, strncpy, _except_handler3, _splitpath, _stricmp, strchr, _lseeki64, wprintf
> rpcrt4.dll: UuidCreate
> version.dll: GetFileVersionInfoW, VerQueryValueA, GetFileVersionInfoA, GetFileVersionInfoSizeW, GetFileVersionInfoSizeA
( 1 exports )
> DbgHelpCreateUserDump, DbgHelpCreateUserDumpW, EnumerateLoadedModules, EnumerateLoadedModules64, ExtensionApiVersion, FindDebugInfoFile, FindDebugInfoFileEx, FindExecutableImage, FindExecutableImageEx, FindFileInPath, FindFileInSearchPath, GetTimestampForLoadedLibrary, ImageDirectoryEntryToData, ImageDirectoryEntryToDataEx, ImageNtHeader, ImageRvaToSection, ImageRvaToVa, ImagehlpApiVersion, ImagehlpApiVersionEx, MakeSureDirectoryPathExists, MapDebugInformation, MiniDumpReadDumpStream, MiniDumpWriteDump, SearchTreeForFile, StackWalk, StackWalk64, SymCleanup, SymEnumSourceFiles, SymEnumSym, SymEnumSymbols, SymEnumTypes, SymEnumerateModules, SymEnumerateModules64, SymEnumerateSymbols, SymEnumerateSymbols64, SymEnumerateSymbolsW, SymEnumerateSymbolsW64, SymFindFileInPath, SymFromAddr, SymFromName, SymFunctionTableAccess, SymFunctionTableAccess64, SymGetFileLineOffsets64, SymGetLineFromAddr, SymGetLineFromAddr64, SymGetLineFromName, SymGetLineFromName64, SymGetLineNext, SymGetLineNext64, SymGetLinePrev, SymGetLinePrev64, SymGetModuleBase, SymGetModuleBase64, SymGetModuleInfo, SymGetModuleInfo64, SymGetModuleInfoW, SymGetModuleInfoW64, SymGetOptions, SymGetSearchPath, SymGetSymFromAddr, SymGetSymFromAddr64, SymGetSymFromName, SymGetSymFromName64, SymGetSymNext, SymGetSymNext64, SymGetSymPrev, SymGetSymPrev64, SymGetTypeFromName, SymGetTypeInfo, SymInitialize, SymLoadModule, SymLoadModule64, SymLoadModuleEx, SymMatchFileName, SymMatchString, SymRegisterCallback, SymRegisterCallback64, SymRegisterFunctionEntryCallback, SymRegisterFunctionEntryCallback64, SymSetContext, SymSetOptions, SymSetSearchPath, SymSetSymWithAddr64, SymUnDName, SymUnDName64, SymUnloadModule, SymUnloadModule64, UnDecorateSymbolName, UnmapDebugInformation, WinDbgExtensionDllInit, dbghelp, dh, lm, lmi, omap, srcfiles, sym, vc7fpo
TrID : File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
ssdeep: 12288:+8GD4aI/TJV9/TF15dKOIycbLtiBsp0yzDAfZmw2AG:+F8z7JV9/J1TKOIycbLtiBsp0Vmw2AG
PEiD : -
RDS : NSRL Reference Data Set
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
File::
c:\windows\system32\drivers\mchts.sys
Driver::
mchts
gzaxmbm
Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet011\Services\mchts]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 GTB6 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 GTB6 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 GTB6 (.NET CLR 3.5.30729)
Zarejestrowani użytkownicy: Bing [Bot]