Mensaje
por viguerbo » 05 Oct 2008, 23:33
Bueno, lo he hecho.
Los resultados te los paso a continuación.
El archivo C:\DOCUME~1\VICTOR~1\DATOSD~1\LISTME~1\rule wait name.exe
Lleva dentro otros cuatro archivos que he sacado con el "virustotal"
Vá la información de cada uno de los 5 archivos. la separo con ----, para distinguirlas.
Muchas gracias de nuevo.
--------------------------------------------------------------------------------------------------------------------------
Análisis del archivo up_keep.exe recibido el 05.10.2008 22:53:29 (CET) Estado actual: análisis terminado Resultado: 1/36 (2.78%) Compactar Imprimir resultados Motor antivirus Versión Última actualización Resultado AhnLab-V3 2008.10.3.2 2008.10.03 - AntiVir 7.8.1.34 2008.10.04 - Authentium 5.1.0.4 2008.10.05 - Avast 4.8.1248.0 2008.10.04 - AVG 8.0.0.161 2008.10.05 - BitDefender 7.2 2008.10.05 - CAT-QuickHeal 9.50 2008.10.04 - ClamAV 0.93.1 2008.10.05 - DrWeb 4.44.0.09170 2008.10.05 - eSafe 7.0.17.0 2008.10.05 - eTrust-Vet 31.6.6129 2008.10.04 - Ewido 4.0 2008.10.05 - F-Prot 4.4.4.56 2008.10.05 - F-Secure 8.0.14332.0 2008.10.05 - Fortinet 3.113.0.0 2008.10.04 - GData 19 2008.10.05 - Ikarus T3.1.1.34.0 2008.10.05 Trojan- Downloader.Win32.Swizzor K7AntiVirus 7.10.484 2008.10.04 - Kaspersky 7.0.0.125 2008.10.05 - McAfee 5398 2008.10.04 - Microsoft 1.4005 2008.10.05 - NOD32 3495 2008.10.04 -
Norman 5.80.02 2008.10.03 - Panda 9.0.0.4 2008.10.05 - PCTools 4.4.2.0 2008.10.05 - Prevx1 V2 2008.10.05 - Rising 20.63.62.00 2008.09.28 - SecureWeb- Gateway 6.7.6 2008.10.05 - Sophos 4.34.0 2008.10.05 - Sunbelt 3.1.1668.1 2008.09.24 - Symantec 10 2008.10.05 - TheHacker 6.3.1.0.101 2008.10.04 - TrendMicro 8.700.0.1004 2008.10.03 - VBA32 3.12.8.6 2008.10.05 - ViRobot 2008.10.4.1406 2008.10.04 - VirusBuster 4.5.11.0 2008.10.05 - Información adicional Tamano archivo: 5377024 bytes MD5...: 8d0a7e8239f7c867955ef9aa21259b71 SHA1..: 8e068a831f9fc83c3621988f2f834f576b010f9a SHA256: 72d514e9b0627db332027de145d6484d3ce185aef57efab223f326b196ed74be SHA512: 283378c3075612501d193e0eca1b62a3ded2db3fd566b152e8b0b42db83e12f0 f8f444e67c22a117159a881668a74efd90429b0da64ac9aafb6f5227bd29b027 PEiD..: - TrID..: File type identification Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x401049 timedatestamp.....: 0x474cf762 (Wed Nov 28 05:06:42 2007) machinetype.......: 0x14c (I386) ( 4 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x493ef 0x49400 7.59 72de5ce1f7d791d560566271431d506c .rdata 0x4b000 0x1977c 0x12800 7.90 b1337b9c9007863b474eac0d6dd3d98c .data 0x65000 0x4bf8d4 0x4c0a00 8.00 65d2ab412dd5aee3970aacf67ed476e1 .rsrc 0x525000 0x4016 0x4200 4.27 44a6a838b12927171237cf1bf1945134 ( 5 imports ) > WININET.dll: InternetCheckConnectionW, InternetShowSecurityInfoByURLW, HttpQueryInfoA, HttpQueryInfoW, InternetCanonicalizeUrlA, InternetHangUp,
---------------------------------------------------------------------------------------------------------------------
Análisis del archivo zfazwunu.exe recibido el 05.10.2008 23:07:55 (CET) Estado actual: análisis terminado Resultado: 4/36 (11.12%) Compactar Imprimir resultados Motor antivirus Versión Última actualización Resultado AhnLab-V3 2008.10.3.2 2008.10.03 - AntiVir 7.8.1.34 2008.10.04 - Authentium 5.1.0.4 2008.10.05 W32/Swizzor-based.2!Maximus Avast 4.8.1248.0 2008.10.04 - AVG 8.0.0.161 2008.10.05 - BitDefender 7.2 2008.10.05 - CAT-QuickHeal 9.50 2008.10.04 Win32.Trojan.C2Lop.A.4 ClamAV 0.93.1 2008.10.05 - DrWeb 4.44.0.09170 2008.10.05 - eSafe 7.0.17.0 2008.10.05 - eTrust-Vet 31.6.6129 2008.10.04 - Ewido 4.0 2008.10.05 - F-Prot 4.4.4.56 2008.10.05 W32/Swizzor-based.2!Maximus F-Secure 8.0.14332.0 2008.10.05 - Fortinet 3.113.0.0 2008.10.04 - GData 19 2008.10.05 - Ikarus T3.1.1.34.0 2008.10.05 Trojan- Downloader.Win32.Swizzor K7AntiVirus 7.10.484 2008.10.04 - Kaspersky 7.0.0.125 2008.10.05 - McAfee 5398 2008.10.04 - Microsoft 1.4005 2008.10.05 - NOD32 3495 2008.10.04 -
Norman 5.80.02 2008.10.03 - Panda 9.0.0.4 2008.10.05 - PCTools 4.4.2.0 2008.10.05 - Prevx1 V2 2008.10.05 - Rising 20.63.62.00 2008.09.28 - SecureWeb- Gateway 6.7.6 2008.10.05 - Sophos 4.34.0 2008.10.05 - Sunbelt 3.1.1675.1 2008.09.27 - Symantec 10 2008.10.05 - TheHacker 6.3.1.0.101 2008.10.04 - TrendMicro 8.700.0.1004 2008.10.03 - VBA32 3.12.8.6 2008.10.05 - ViRobot 2008.10.4.1406 2008.10.04 - VirusBuster 4.5.11.0 2008.10.05 - Información adicional Tamano archivo: 508928 bytes MD5...: e52a38b27402c8af99057fc370c8adb0 SHA1..: f4d5999818851ed750a78e3437fa66034a852231 SHA256: 512ca9bec404116ddd16529204fab642d5a58ff8009075af49563b8a499e5971 SHA512: 0c73a390a59d2913daa32025c7ebce236eed2c5ae3bad631349378a995243a66 c2d28b15aa593e015e60cb00c6ffe6693b187ef4187a62ffcaf73e70a2747046 PEiD..: - TrID..: File type identification Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x401049 timedatestamp.....: 0x474cf762 (Wed Nov 28 05:06:42 2007) machinetype.......: 0x14c (I386) ( 4 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x493ef 0x49400 7.59 72de5ce1f7d791d560566271431d506c .rdata 0x4b000 0x1977c 0x12800 7.90 b1337b9c9007863b474eac0d6dd3d98c .data 0x65000 0x1c01c 0x1c200 7.35 ea80db146ba8e28524f5ac0075bb4d06 .rsrc 0x82000 0x4016 0x4200 4.27 76e2a67cc69605f9594160c671d4f1a9 ( 5 imports ) > WININET.dll: InternetCheckConnectionW, InternetShowSecurityInfoByURLW, HttpQueryInfoA, HttpQueryInfoW, InternetCanonicalizeUrlA, InternetHangUp,
------------------------------------------------------------------------------------------------------------
Análisis del archivo uvyozlkg.exe recibido el 05.10.2008 23:05:55 (CET) Estado actual: análisis terminado Resultado: 6/36 (16.67%) Compactar Imprimir resultados Motor antivirus Versión Última actualización Resultado AhnLab-V3 2008.10.3.2 2008.10.03 - AntiVir 7.8.1.34 2008.10.04 - Authentium 5.1.0.4 2008.10.05 W32/Swizzor-based.2!Maximus Avast 4.8.1248.0 2008.10.04 - AVG 8.0.0.161 2008.10.05 - BitDefender 7.2 2008.10.05 - CAT-QuickHeal 9.50 2008.10.04 Win32.Trojan.C2Lop.F.4 ClamAV 0.93.1 2008.10.05 - DrWeb 4.44.0.09170 2008.10.05 - eSafe 7.0.17.0 2008.10.05 - eTrust-Vet 31.6.6129 2008.10.04 - Ewido 4.0 2008.10.05 - F-Prot 4.4.4.56 2008.10.05 W32/Swizzor-based.2!Maximus F-Secure 8.0.14332.0 2008.10.05 Trojan.Win32.Obfuscated.gen Fortinet 3.113.0.0 2008.10.04 - GData 19 2008.10.05 - Ikarus T3.1.1.34.0 2008.10.05 Virus.Trojan.Win32.Obfuscated K7AntiVirus 7.10.484 2008.10.04 - Kaspersky 7.0.0.125 2008.10.05 Trojan.Win32.Obfuscated.gen McAfee 5398 2008.10.04 - Microsoft 1.4005 2008.10.05 - NOD32 3495 2008.10.04 - Norman 5.80.02 2008.10.03 -
Panda 9.0.0.4 2008.10.05 - PCTools 4.4.2.0 2008.10.05 - Prevx1 V2 2008.10.05 - Rising 20.63.62.00 2008.09.28 - SecureWeb- Gateway 6.7.6 2008.10.05 - Sophos 4.34.0 2008.10.05 - Sunbelt 3.1.1675.1 2008.09.27 - Symantec 10 2008.10.05 - TheHacker 6.3.1.0.101 2008.10.04 - TrendMicro 8.700.0.1004 2008.10.03 - VBA32 3.12.8.6 2008.10.05 - ViRobot 2008.10.4.1406 2008.10.04 - VirusBuster 4.5.11.0 2008.10.05 - Información adicional Tamano archivo: 531456 bytes MD5...: 62622ddbcc9d65c15f8b1f70e17ba7c7 SHA1..: bf2a79b78e53d39581e22aa8dc8fab63ad30f4a2 SHA256: 60089f62523f3cd71e037ab4f02aa01d5173d79cf357b20727bdeebc8428385c SHA512: ec4295591cd27b3f56bfe6c1010553108d0077b0aab9e4f494cc257e3f37f415 1aacfa5000039c9c92770f0f173be274a00a9dc2e333162fbab6c38b9c43a430 PEiD..: - TrID..: File type identification Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x401049 timedatestamp.....: 0x46cef2d9 (Fri Aug 24 15:01:45 2007) machinetype.......: 0x14c (I386) ( 4 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x527e1 0x52800 7.51 207d5e237896519b4d187adcb82a0c79 .rdata 0x54000 0x125ec 0x10400 7.86 db9b75515ca12b7d4eb01be40a9f92e0 .data 0x67000 0x1d09c 0x1d200 7.26 eac36a063bc7eaaeb0007338d0faec66 .rsrc 0x85000 0x1826 0x1a00 5.04 ec01922aaf1608f5b238b15084d5f470 ( 5 imports ) > USER32.dll: DialogBoxIndirectParamA, CreateMDIWindowA, CreateAcceleratorTableA, DragDetect, AppendMenuA, PostQuitMessage, wvsprintfA, RemovePropA, EnableWindow, SetDlgItemTextW,
----------------------------------------------------------------------------------------------------
Análisis del archivo rule_wait_name.exe recibido el 05.10.2008 23:03:51 (CET) Estado actual: análisis terminado Resultado: 7/35 (20%) Compactar Imprimir resultados Motor antivirus Versión Última actualización Resultado AhnLab-V3 2008.10.3.2 2008.10.03 - AntiVir 7.8.1.34 2008.10.04 - Authentium 5.1.0.4 2008.10.05 W32/Swizzor-based.2!Maximus Avast 4.8.1248.0 2008.10.04 - AVG 8.0.0.161 2008.10.05 - BitDefender 7.2 2008.10.05 - CAT-QuickHeal 9.50 2008.10.04 Win32.TrojanDownloader.Swizzor.4 ClamAV 0.93.1 2008.10.05 - DrWeb 4.44.0.09170 2008.10.05 - eSafe 7.0.17.0 2008.10.05 - eTrust-Vet 31.6.6129 2008.10.04 - Ewido 4.0 2008.10.05 - F-Prot 4.4.4.56 2008.10.05 W32/Swizzor-based.2!Maximus F-Secure 8.0.14332.0 2008.10.05 Trojan.Win32.Obfuscated.gen Fortinet 3.113.0.0 2008.10.04 - GData 19 2008.10.05 - Ikarus T3.1.1.34.0 2008.10.05 Trojan.Obfuscated K7AntiVirus 7.10.484 2008.10.04 - Kaspersky 7.0.0.125 2008.10.05 Trojan.Win32.Obfuscated.gen McAfee 5398 2008.10.04 - Microsoft 1.4005 2008.10.05 - Norman 5.80.02 2008.10.03 - Panda 9.0.0.4 2008.10.05 -
PCTools 4.4.2.0 2008.10.05 - Prevx1 V2 2008.10.05 - Rising 20.63.62.00 2008.09.28 - SecureWeb- Gateway 6.7.6 2008.10.05 - Sophos 4.34.0 2008.10.05 - Sunbelt 3.1.1675.1 2008.09.27 - Symantec 10 2008.10.05 - TheHacker 6.3.1.0.101 2008.10.04 - TrendMicro 8.700.0.1004 2008.10.03 - VBA32 3.12.8.6 2008.10.05 OScope.Trojan.BagsWay.C ViRobot 2008.10.4.1406 2008.10.04 - VirusBuster 4.5.11.0 2008.10.05 - Información adicional Tamano archivo: 460800 bytes MD5...: c6f602e4770a57ad9e058dd2d28f6776 SHA1..: b481486aa9676e6af399c5d20e7356d708ab6b9e SHA256: 3a3555dcc1de407237d17ddb6b9b211b5853a4e295153d2bcdc897e4a4d665b5 SHA512: 82d82ce71822e967fede857db4a4ac550fdc3113b1388aaf109a418bf81087bf 9154ca2a269cae9b59ac4967a85a82e0fdf709932ea14c07421f2e7149b66590 PEiD..: Armadillo v1.71 TrID..: File type identification Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x41412d timedatestamp.....: 0x46c9789b (Mon Aug 20 11:18:51 2007) machinetype.......: 0x14c (I386) ( 4 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x45e36 0x46000 7.58 68e8e3f2ddc1918e4319f13c9be836af .rdata 0x47000 0xeaf0 0xb800 7.94 664a004b32e0875b461470aacfda20f9 .data 0x56000 0x194e8 0x19600 7.27 8b70fef9d61a210f762780c03c6e1720 .rsrc 0x70000 0x54bc 0x5600 4.19 eadf533516c6684c788bcb83560d01f0 ( 4 imports ) > comctl32.dll: CreatePropertySheetPageW, _TrackMouseEvent, ImageList_Destroy, InitCommonControlsEx, ImageList_GetImageRect > USER32.dll: CharToOemW, OpenDesktopW, EnumDisplayDevicesA, SetWindowsHookW, RegisterClassA, SetScrollPos, CreateWindowExA, RemovePropW, MessageBoxW, ShowWindow, RegisterClassExA, SetWindowRgn,
------------------------------------------------------------------------------------------------
Análisis del archivo Noun_bolt_mix_help.exe recibido el 05.10.2008 22:57:32
Estado actual: análisis terminado Resultado: 5/36 (13.89%) Compactar Imprimir resultados Motor antivirus Versión Última actualización Resultado AhnLab-V3 2008.10.3.2 2008.10.03 - AntiVir 7.8.1.34 2008.10.04 - Authentium 5.1.0.4 2008.10.05 W32/Swizzor-based.2! Maximus Avast 4.8.1248.0 2008.10.04 - AVG 8.0.0.161 2008.10.05 - BitDefender 7.2 2008.10.05 - CAT-QuickHeal 9.50 2008.10.04 Win32.Trojan.C2Lop.E.4 ClamAV 0.93.1 2008.10.05 - DrWeb 4.44.0.09170 2008.10.05 - eSafe 7.0.17.0 2008.10.05 - eTrust-Vet 31.6.6129 2008.10.04 - Ewido 4.0 2008.10.05 - F-Prot 4.4.4.56 2008.10.05 W32/Swizzor-based.2! Maximus F-Secure 8.0.14332.0 2008.10.05 - Fortinet 3.113.0.0 2008.10.04 - GData 19 2008.10.05 - Ikarus T3.1.1.34.0 2008.10.05 Trojan.Obfuscated K7AntiVirus 7.10.484 2008.10.04 - Kaspersky 7.0.0.125 2008.10.05 - McAfee 5398 2008.10.04 - Microsoft 1.4005 2008.10.05 - NOD32 3495 2008.10.04 -
Norman 5.80.02 2008.10.03 - Panda 9.0.0.4 2008.10.05 - PCTools 4.4.2.0 2008.10.05 - Prevx1 V2 2008.10.05 - Rising 20.63.62.00 2008.09.28 - SecureWeb- Gateway 6.7.6 2008.10.05 - Sophos 4.34.0 2008.10.05 - Sunbelt 3.1.1675.1 2008.09.27 - Symantec 10 2008.10.05 - TheHacker 6.3.1.0.101 2008.10.04 - TrendMicro 8.700.0.1004 2008.10.03 - VBA32 3.12.8.6 2008.10.05 OScope.Trojan.BagsWay.C ViRobot 2008.10.4.1406 2008.10.04 - VirusBuster 4.5.11.0 2008.10.05 - Información adicional Tamano archivo: 311808 bytes MD5...: 19fe5846e25e22c8e93e6e1e72b249bf SHA1..: 970ae7aed0bb32ede20dd9d426814ae866e58bde SHA256: fb6907265e704dc24942051e2ee822e2d58c13774d1c85daac1a2b5e53a85885 SHA512: 419c3fece6ad3abe06515975f1cd58b0ac96e1d7b0093f0bb13172b884db33c9 9da98e91d884b574993bd14a9f5a806ba2a0ff727eb8b09f29eb511407718829 PEiD..: Armadillo v1.71 TrID..: File type identification Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x401000 timedatestamp.....: 0x4727366f (Tue Oct 30 13:49:35 2007) machinetype.......: 0x14c (I386) ( 4 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x2d57c 0x2d600 7.21 383ec1fdddfedd8eb2970d0fe18a73e6 .rdata 0x2f000 0x5900 0x3400 7.35 6557a9666102164265a2659643a1cefe .data 0x35000 0x15571 0x15600 7.21 303b9c2db914226c9defa2066b253da7 .rsrc 0x4b000 0x5c2c 0x5e00 4.81 6b1aa9cda7a9de51c6046936c04a0c43 ( 6 imports ) > comctl32.dll: ImageList_LoadImageW, InitCommonControlsEx, ImageList_SetDragCursorImage, ImageList_AddMasked,
---------------------------------------------------------------------------------------------
Lo tengo guardado en formato Microsoft Office Document Imaging. No se me ha permitido enviarlos como adjuntos.
Quedo en vuestras manos para lo que creaís conveniente.
Victor Guerra.