
Originally Posted by
Ad litteram
ok, and thanks for risking your computer for us =)
and next time edit your post instead of double posting XD
sorry about the dbl post
anyways heres the virus scan, looks like theres no reason to even test it
deff has a backdoor, and no hack should have to write to the system registry which this ones does
Antivirus Version Last Update Result
a-squared 4.5.0.18 2009.07.02 -
AhnLab-V3 5.0.0.2 2009.07.02 -
AntiVir 7.9.0.204 2009.07.02 -
Antiy-AVL 2.0.3.1 2009.07.02 -
Authentium 5.1.2.4 2009.07.02 W32/Downldr2.HZF
Avast 4.8.1335.0 2009.07.01 Win32:Trojan-gen {Other}
AVG 8.5.0.386 2009.07.02 -
BitDefender 7.2 2009.07.02 -
CAT-QuickHeal 10.00 2009.07.02 -
ClamAV 0.94.1 2009.07.02 Trojan.Spy-4973
Comodo 1538 2009.07.02 TrojWare.Win32.TrojanDropper.Agent.GYU
DrWeb 5.0.0.12182 2009.07.02 Trojan.MulDrop.11541
eSafe 7.0.17.0 2009.07.02 -
eTrust-Vet 31.6.6593 2009.07.02 Win32/Harnig.FK
F-Prot 4.4.4.56 2009.07.01 W32/Downldr2.HZF
F-Secure 8.0.14470.0 2009.07.02 -
Fortinet 3.117.0.0 2009.07.02 W32/Agent.SUI!tr
GData 19 2009.07.02 Win32:Trojan-gen {Other}
Ikarus T3.1.1.64.0 2009.07.02 -
Jiangmin 11.0.706 2009.07.02 Backdoor/RBot.wno
K7AntiVirus 7.10.782 2009.07.02 -
Kaspersky 7.0.0.125 2009.07.02 -
McAfee 5664 2009.07.02 -
McAfee+Artemis 5664 2009.07.02 -
McAfee-GW-Edition 6.8.5 2009.07.02 Heuristic.BehavesLike.Win32.Dropper.J
Microsoft 1.4803 2009.07.02 -
NOD32 4210 2009.07.02 -
Norman 6.01.09 2009.07.02 -
nProtect 2009.1.8.0 2009.07.02 -
Panda 10.0.0.14 2009.07.02 -
PCTools 4.4.2.0 2009.07.02 -
Prevx 3.0 2009.07.02 -
Rising 21.36.34.00 2009.07.02 Backdoor.Win32.Mosucker.bh
Sophos 4.43.0 2009.07.02 Mal/Generic-A
Sunbelt 3.2.1858.2 2009.07.01 -
Symantec 1.4.4.12 2009.07.02 -
TheHacker 6.3.4.3.359 2009.07.02 -
TrendMicro 8.950.0.1094 2009.07.02 -
VBA32 3.12.10.7 2009.07.02 -
ViRobot 2009.7.2.1816 2009.07.02 Backdoor.Win32.MoSucker.270199
VirusBuster 4.6.5.0 2009.07.02 -
Additional information
File size: 2759642 bytes
MD5...: 7f1270b9a347f91846826c4262b28e0a
SHA1..: dbdec8bc9488694c108aa718504f97ce9b8890c0
SHA256: 027c2fc3a7f42c0b4ae78955932d2714056033afe5a152e04b 851fdeca04d63f
ssdeep: 49152:tcQAAWmFalrz/bk3Jho5b3zJ4gazVWN4L7/L+FhELM9ACe:eab8YZwhTi7
D+Fhb1e
PEiD..: -
TrID..: File type identification
Win32 EXE PECompact compressed (generic) (41.8%)
Win32 Executable MS Visual C++ (generic) (37.9%)
Win32 Executable Generic (8.5%)
Win32 Dynamic Link Library (generic) (7.6%)
Generic Win/DOS Executable (2.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x7efd
timedatestamp.....: 0x45e47ce3 (Tue Feb 27 18:48:03 2007)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x133fc 0x13400 6.65 03f01c7c922b8b54b9074199c0b027bf
.rdata 0x15000 0x42aa 0x4400 5.51 1780d97e54d50955d6f0af80a0f6d6da
.data 0x1a000 0x34c4 0x1400 2.24 1865136f693a26953c71c34c68b07611
.rsrc 0x1e000 0x1d44 0x1e00 5.08 8e7c4d84ae5002647c6820a3e6159d09
( 5 imports )
> urlmon.dll: URLDownloadToFileA
> KERNEL32.dll: GetCommandLineA, Sleep, GetFileAttributesA, CreateProcessA, lstrcatA, GetEnvironmentVariableA, GetShortPathNameA, CreateDirectoryA, GetStartupInfoA, FindFirstFileA, GetLongPathNameA, RemoveDirectoryA, CopyFileA, SetFileAttributesA, FindClose, WaitForSingleObject, GetModuleFileNameA, FindNextFileA, GetModuleHandleA, GetTempPathA, DeleteFileA, lstrcpyA, CompareStringA, SetEndOfFile, GetTimeZoneInformation, FlushFileBuffers, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetCurrentProcess, MoveFileExA, ExitProcess, CloseHandle, GetLastError, ReadFile, CreateFileA, CompareStringW, MoveFileA, RtlUnwind, GetLocaleInfoA, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetProcAddress, FileTimeToSystemTime, FileTimeToLocalFileTime, GetDriveTypeA, HeapFree, HeapAlloc, GetVersionExA, GetProcessHeap, RaiseException, SetEnvironmentVariableA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, InterlockedDecrement, HeapSize, EnterCriticalSection, LeaveCriticalSection, GetCPInfo, GetACP, GetOEMCP, LCMapStringA, WideCharToMultiByte, MultiByteToWideChar, LCMapStringW, WriteFile, GetConsoleCP, GetConsoleMode, SetFilePointer, GetStdHandle, DeleteCriticalSection, LoadLibraryA, InitializeCriticalSection, GetFullPathNameA, GetCurrentDirectoryA, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, GetStringTypeA, GetStringTypeW
> USER32.dll: GetMessageA, PostQuitMessage, ExitWindowsEx, MessageBoxA, EndDialog, BlockInput, GetDlgItemTextA, DialogBoxParamA
> ADVAPI32.dll: AdjustTokenPrivileges, RegDeleteValueA, RegOpenKeyExA, RegCreateKeyExA, LookupPrivilegeValueA, RegDeleteKeyA, RegSetValueExA, OpenProcessToken, RegCloseKey
> SHELL32.dll: SHGetFolderPathA, SHCreateDirectoryExA, ShellExecuteA
( 0 exports )
PDFiD.: -
RDS...: NSRL Reference Data Set
LINK
Virustotal. MD5: 7f1270b9a347f91846826c4262b28e0a Heuristic.BehavesLike.Win32.Dropper.J W32/Downldr2.HZF Win32:Trojan-gen {Other}