Mensaje
por juancar373 » 19 Ago 2008, 21:59
Hola de nuevo. Disculpad por colgar los informes, no sabia que debia copiarlos. He hecho el escaner del archivo que me indicas, aqui esta el resumen:
Análisis del archivo gqswkwa.exe recibido el 15.08.2008 17:46:30 (CET)
Estado actual: análisis terminado
Resultado: 0/35 (0.00%)
Compactar Imprimir resultados
Motor antivirus Versión Última actualización Resultado
AhnLab-V3 2008.8.15.0 2008.08.14 -
AntiVir 7.8.1.19 2008.08.15 -
Authentium 5.1.0.4 2008.08.15 -
Avast 4.8.1195.0 2008.08.15 -
AVG 8.0.0.161 2008.08.15 -
BitDefender 7.2 2008.08.15 -
CAT-QuickHeal 9.50 2008.08.14 -
ClamAV 0.93.1 2008.08.15 -
DrWeb 4.44.0.09170 2008.08.15 -
eSafe 7.0.17.0 2008.08.14 -
eTrust-Vet 31.6.6034 2008.08.15 -
Ewido 4.0 2008.08.15 -
F-Prot 4.4.4.56 2008.08.15 -
Fortinet 3.14.0.0 2008.08.15 -
GData 2.0.7306.1023 2008.08.15 -
Ikarus T3.1.1.34.0 2008.08.15 -
K7AntiVirus 7.10.417 2008.08.15 -
Kaspersky 7.0.0.125 2008.08.15 -
McAfee 5361 2008.08.14 -
Microsoft 1.3807 2008.08.15 -
NOD32v2 3359 2008.08.15 -
Norman 5.80.02 2008.08.15 -
Panda 9.0.0.4 2008.08.15 -
PCTools 4.4.2.0 2008.08.15 -
Prevx1 V2 2008.08.15 -
Rising 20.57.42.00 2008.08.15 -
Sophos 4.32.0 2008.08.15 -
Sunbelt 3.1.1546.1 2008.08.15 -
Symantec 10 2008.08.15 -
TheHacker 6.3.0.3.046 2008.08.13 -
TrendMicro 8.700.0.1004 2008.08.15 -
VBA32 3.12.8.3 2008.08.15 -
ViRobot 2008.8.14.1337 2008.08.14 -
VirusBuster 4.5.11.0 2008.08.15 -
Webwasher-Gateway 6.6.2 2008.08.15 -
Información adicional
File size: 319488 bytes
MD5...: 8b098ef4be5d0dc512954de69e45baaa
SHA1..: 08afdee6ba73244a320a9c7b194d7b2f744f988a
SHA256: 4d0a3f6de5699a151eacc43189aeaae6abaa34701b52a15a72b618d159261747
SHA512: 0ee652474d21d1252f5304a05e1bb4310e35cf0a5f161cf06d181a38c8ac48fb
e999745fa62bee6b434b6c86a70b5406a26b7d0c63227ba4b0ab09359414690b
PEiD..: Armadillo v1.71
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x402830
timedatestamp.....: 0x41b58307 (Tue Dec 07 10:16:39 2004)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x19bc 0x2000 5.81 98310c3069f645b34cf9523a89b128db
.rdata 0x3000 0x117a 0x2000 3.41 34848b7d634746a3058442ddd6b64ba7
.data 0x5000 0x48b5c 0x49000 7.32 8ba5e06f15ef12faf08d5fba4bd12e1a
( 11 imports )
> KERNEL32.dll: GetVersionExA, VirtualAlloc, VirtualProtect, ReadFileScatter, GetSystemTimeAsFileTime, AllocConsole, CompareStringA, UnmapViewOfFile, GetEnvironmentStringsW, _lopen, RaiseException, GetDiskFreeSpaceW, GetModuleHandleA, GetStartupInfoA
> USER32.dll: MapWindowPoints, wvsprintfA, WinHelpW, IntersectRect, CheckMenuRadioItem, GetWindowThreadProcessId, RegisterClassExW, MonitorFromPoint, UnregisterClassW, GetKeyboardLayoutList, SetProcessWindowStation, SetCaretPos, GetScrollBarInfo, MapVirtualKeyA, GetShellWindow, ArrangeIconicWindows, EqualRect, FindWindowExW, DrawMenuBar, InvertRect, TrackPopupMenu, GetScrollRange, ClipCursor, EnumDesktopWindows, SendMessageTimeoutW, DialogBoxParamA, GetClassInfoW, keybd_event, IsCharUpperW, GetWindowLongA, GetMenuState, UnregisterHotKey, EnumDisplaySettingsExA, CreateDesktopA, TileWindows, ScrollWindowEx, GetClipboardSequenceNumber, SendMessageTimeoutA, InvalidateRgn, CreateCaret, SetProcessDefaultLayout, GetClassInfoA, LoadKeyboardLayoutW, LoadBitmapA, SetClassLongW, DestroyIcon, DrawTextA, InternalGetWindowText, CloseDesktop, UpdateWindow, GetWindowLongW, SetMenuItemBitmaps, SetScrollPos, GetKeyNameTextW, SetWindowWord, InsertMenuItemW, GetMenuInfo, ValidateRgn, SetMessageQueue, DrawFocusRect
> GDI32.dll: CreatePolyPolygonRgn, StrokePath, UpdateColors, ExtEscape, SetBitmapDimensionEx, GetRegionData, DPtoLP, CreatePolygonRgn, GetOutlineTextMetricsW, StartPage, CreateFontA, GetCharWidth32W, OffsetRgn
> comdlg32.dll: ChooseColorA, GetSaveFileNameA, ChooseFontA
> ADVAPI32.dll: CryptReleaseContext, CryptSetProvParam, RegEnumKeyExA, GetSecurityInfo, CryptHashData, GetPrivateObjectSecurity, CreateProcessAsUserA, AllocateLocallyUniqueId, RegDeleteKeyW, GetSecurityDescriptorDacl, RegEnumValueA, RegCreateKeyExA, CreateServiceW, SetSecurityDescriptorOwner, GetAce, DeleteAce, MakeAbsoluteSD, SetNamedSecurityInfoW, EnumServicesStatusA, ImpersonateSelf, SetTokenInformation, SetFileSecurityA, GetSidLengthRequired, UnlockServiceDatabase, RegQueryValueA
> SHELL32.dll: SHGetSpecialFolderLocation, ExtractIconA, FindExecutableW
> ole32.dll: CoInitializeEx, CoLockObjectExternal, CreateOleAdviseHolder, CoTreatAsClass, StringFromGUID2, OleSetMenuDescriptor, RevokeDragDrop
> OLEAUT32.dll: -, -, -, -, -
> COMCTL32.dll: CreatePropertySheetPageA, ImageList_Add, ImageList_EndDrag
> SHLWAPI.dll: SHSetValueA, SHEnumValueW, PathIsDirectoryW, PathGetCharTypeW, StrChrW, PathIsDirectoryEmptyW, StrCatBuffA, StrRChrW, StrTrimW, StrStrW, StrStrA
> MSVCRT.dll: _acmdln, exit, _XcptFilter, _exit, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp, __getmainargs
( 0 exports )
Parece que no lo encuentra como virus... ¿Alguna idea?