virustotal.com check: 0 VT Community user(s) with a total of 0
reputation credit(s) say(s) this sample is goodware. 0 VT Community
user(s) with a total of 0 reputation credit(s) say(s) this sample is
malware. File name: Elli0tt.exe Submission date: 2010-08-31 18:01:08 (UTC) Current status: queued queued analysing finished Result: 12/ 43 (27.9%) VT Community not reviewed Safety score: - Antivirus Version Last Update Result AhnLab-V3 2010.08.31.01 2010.08.31 - AntiVir 8.2.4.46 2010.08.31 TR/Crypt.XPACK.Gen Antiy-AVL 2.0.3.7 2010.08.31 - Authentium 5.2.0.5 2010.08.31 W32/Virut.AI!Generic Avast 4.8.1351.0 2010.08.31 - Avast5 5.0.594.0 2010.08.31 - AVG 9.0.0.851 2010.08.31 - BitDefender 7.2 2010.08.31 - CAT-QuickHeal 11.00 2010.08.31 - ClamAV 0.96.2.0-git 2010.08.31 Trojan.Notifier-5 Comodo 5924 2010.08.31 - DrWeb 5.0.2.03300 2010.08.31 - Emsisoft 5.0.0.37 2010.08.31 Trojan.Crypt!IK eSafe 7.0.17.0 2010.08.30 - eTrust-Vet 36.1.7828 2010.08.31 - F-Prot 4.6.1.107 2010.08.31 W32/Virut.AI!Generic F-Secure 9.0.15370.0 2010.08.31 - Fortinet 4.1.143.0 2010.08.31 - GData 21 2010.08.31 - Ikarus T3.1.1.88.0 2010.08.31 Trojan.Crypt Jiangmin 13.0.900 2010.08.30 - K7AntiVirus 9.63.2396 2010.08.30 Backdoor Kaspersky 7.0.0.125 2010.08.31 - McAfee 5.400.0.1158 2010.08.31 - McAfee-GW-Edition 2010.1B 2010.08.31 Heuristic.LooksLike.Win32.SuspiciousPE.F Microsoft 1.6103 2010.08.31 - NOD32 5412 2010.08.31 - Norman 6.05.11 2010.08.31 - nProtect 2010-08-31.01 2010.08.31 - Panda 10.0.2.7 2010.08.31 - PCTools 7.0.3.5 2010.08.31 Trojan.ADH Prevx 3.0 2010.08.31 - Rising 22.63.01.04 2010.08.31 - Sophos 4.56.0 2010.08.31 Sus/UnkPacker Sunbelt 6818 2010.08.31 - SUPERAntiSpyware 4.40.0.1006 2010.08.31 - Symantec 20101.1.1.7 2010.08.31 Trojan.ADH TheHacker 6.5.2.1.359 2010.08.31 - TrendMicro 9.120.0.1004 2010.08.31 Possible_Virus TrendMicro-HouseCall 9.120.0.1004 2010.08.31 - VBA32 3.12.14.0 2010.08.31 - ViRobot 2010.8.31.4017 2010.08.31 - VirusBuster 5.0.27.0 2010.08.31 - Additional information Show all MD5 : 02d9f387d0b35b0c2750f753dc707dc4 SHA1 : 840bae14382896e4e4bd5f15a4d4eb5552264b9d SHA256: 58074c6d86c4f9e2052d89f680a95f761e34a0a1be32391584913add84ddddbf ssdeep: 24576:eT4cZLBNGejlHdGHDtHMI4qzJzzl+4QmcgY:BAFdsHDREazz4E4 File size : 888832 bytes First seen: 2010-08-31 18:01:08 Last seen : 2010-08-31 18:01:08 TrID: Win64 Executable Generic (72.0%) Windows Screen Saver (11.0%) Win32 Executable Generic (7.1%) Win32 Dynamic Link Library (generic) (6.3%) Generic Win/DOS Executable (1.6%) sigcheck: publisher....: copyright....: product......: description..: Or4ng3 KusH original name: Or4ng3 KusH.dll internal name: Or4ng3 KusH file version.: 1, 0, 0, 0 comments.....: __QQ_1035345158 signers......: - signing date.: - verified.....: Unsigned packers (Kaspersky): Splasher PEInfo: PE structure information
[[ basic data ]] entrypointaddress: 0xD000 timedatestamp....: 0x4A19EF64 (Mon May 25 01:07:48 2009) machinetype......: 0x14c (I386) [[ 7 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 .text, 0x1000, 0x2734, 0x3000, 3.64, 2a9893566ef0ea694cb06976f8a7862a .rdata, 0x4000, 0x14E, 0x1000, 0.09, 11cdd767aceda2e59e27d1fc703a7508 .data, 0x5000, 0x1520, 0x1000, 1.57, 0c905525d68c5b18f95c89ed03e360c6 .idata, 0x7000, 0x9D6, 0x1000, 2.50, 9dec19e569f9f587b5354fa63b5c3567 .rsrc, 0x8000, 0x342C, 0x4000, 3.90, 1cda4a3a1ee48f12461c149b40dc307b .reloc, 0xC000, 0x3C9, 0x1000, 1.73, 43b493957e1a26a3a4fec10f9e322181 splasher, 0xD000, 0xCC000, 0xCB091, 7.96, 7f6a48992d10b406f62dae8a2edccac6 [[ 5 import(s) ]]
KERNEL32.dll: ReadProcessMemory, GlobalAlloc, OpenProcess, CloseHandle,
SetThreadContext, SuspendThread, Sleep, ResumeThread,
WriteProcessMemory, VirtualProtectEx, GetThreadContext,
GetExitCodeThread, GlobalFree, CreateRemoteThread, ExitProcess,
LoadLibraryA, FindFirstFileA, GetWindowsDirectoryA, SetFileAttributesA,
TerminateProcess, CreateProcessA, SetCurrentDirectoryA, DeleteFileA,
GetModuleFileNameA, GetModuleHandleA, GetStartupInfoA, GetProcAddress,
WaitForSingleObject, GetVersion USER32.dll: MessageBoxA comdlg32.dll: GetOpenFileNameA, GetSaveFileNameA ADVAPI32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey
MSVCRT.dll: _onexit, _stricmp, __dllonexit, _strcmpi, strcpy, memset,
tolower, strcat, strlen, strstr, fprintf, fgets, fopen, fclose, _exit,
_XcptFilter, exit, _acmdln, __getmainargs, _initterm, __setusermatherr,
_adjust_fdiv, __p__commode, __p__fmode, __set_app_type,
_except_handler3, _controlfp VT Community 0 This file has never been reviewed by any VT Community member. Be the first one to comment on it!
|