Code:
SHA256: 779421e321ea6995a1eba0f953f80d44e98c37f8ee113a43b785bb6d3c71fcb8
SHA1: 45765224c86d7fe5424f866fb4f40e6743ac6054
MD5: c4f245801868b50316ca13b5305185c4
File size: 53.0 KB ( 54272 bytes )
File name: qddsowkf.exe
File type: Win32 EXE
Detection ratio: 23 / 38
Analysis date: 2012-09-16 16:17:31 UTC ( 0 Minuten ago )
0
1
More detailsAntivirus Result Update
AhnLab-V3 - 20120916
AntiVir TR/Rogue.kdv.725476 20120916
Antiy-AVL - 20120911
Avast Win32:Weelsof-A [Trj] 20120916
AVG Generic29.AWWS 20120916
BitDefender Trojan.Generic.KDV.725476 20120916
ByteHero - 20120914
CAT-QuickHeal - 20120916
ClamAV - 20120916
Commtouch - 20120916
Comodo UnclassifiedMalware 20120916
Emsisoft Trojan.Win32.Weelsof!IK 20120916
ESET-NOD32 a variant of Win32/Kryptik.ALPR 20120916
F-Prot - 20120916
F-Secure Trojan.Generic.KDV.725476 20120916
Fortinet - 20120830
GData Trojan.Generic.KDV.725476 20120916
Ikarus Trojan.Win32.Weelsof 20120916
Jiangmin Trojan/Weelsof.hx 20120916
K7AntiVirus - 20120915
Kaspersky Trojan.Win32.Weelsof.lw 20120916
McAfee Generic.dx!bfwr 20120916
McAfee-GW-Edition Generic.dx!bfwr 20120915
Microsoft Trojan:Win32/Weelsof.C 20120916
Norman W32/Kryptik.BRR 20120915
nProtect Trojan.Generic.KDV.725476 20120916
PCTools - 20120916
Rising - 20120914
Sophos Mal/Generic-L 20120916
SUPERAntiSpyware - 20120911
Symantec W32.Pilleuz 20120916
TheHacker - 20120915
TotalDefense - 20120916
TrendMicro TROJ_GEN.RCBC7ID 20120916
TrendMicro-HouseCall TROJ_GEN.RCBC7ID 20120916
VIPRE Trojan.Win32.Generic!BT 20120916
ViRobot Trojan.Win32.A.Weelsof.54272.B 20120916
VirusBuster - 20120916
Comments
Votes
Additional informationssdeep
1536:lRLh+9OUAVGPLxu+R/2QPUGfjU6yDF+Uuj:nL8OIdu+cGbtyw
TrID
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEiD packer identifier
Armadillo v1.71
ExifTool
MIMEType.................: application/octet-stream
Subsystem................: Windows GUI
MachineType..............: Intel 386 or later, and compatibles
TimeStamp................: 2012:09:10 14:44:17-07:00
FileType.................: Win32 EXE
PEType...................: PE32
CodeSize.................: 5632
LinkerVersion............: 10.0
EntryPoint...............: 0x2304
InitializedDataSize......: 133632
SubsystemVersion.........: 5.1
ImageVersion.............: 0.0
OSVersion................: 5.1
UninitializedDataSize....: 0
Portable Executable structural information
Compilation timedatestamp.....: 2012-09-10 21:44:17
Target machine................: 0x14C (Intel 386 or later processors and compatible processors)
Entry point address...........: 0x00002304
PE Sections...................:
Name Virtual Address Virtual Size Raw Size Entropy MD5
.text 4096 5432 5632 5.89 5aed7f36dc8b20d02ba7ccb695b6b390
.rdata 12288 4618 5120 5.01 d19cd0a4d218ce1222a116ed8c27856e
.data 20480 115340 29696 7.94 e36ac667d441c0a237bd596d7ba0d7e1
.rsrc 139264 12760 12800 5.95 7f3762b6463189b5c516d1a89f38379d
PE Imports....................:
[[SHLWAPI.dll]]
PathFindExtensionA, PathRenameExtensionW, StrCmpNIW, PathCommonPrefixW, PathIsUNCW, PathFindExtensionW, PathCanonicalizeW, PathIsRelativeW, PathIsDirectoryW, PathRemoveBackslashW, StrToIntExW, PathIsRootW, PathAddBackslashA, PathIsURLW, PathFileExistsW, PathAddBackslashW, SHGetValueW, StrCmpIW, SHDeleteValueW, PathStripToRootW, PathCombineW, PathRelativePathToW, PathRemoveExtensionW, PathStripPathW, StrStrIA, PathAppendA, PathIsFileSpecW, PathRemoveFileSpecW, SHCreateStreamOnFileW, StrStrIW, PathAppendW, SHDeleteKeyW, AssocQueryStringW, PathRemoveFileSpecA, StrToIntW, StrCmpW, StrCmpNW, PathFindFileNameW, PathFindFileNameA, StrStrW, PathRemoveBlanksW, PathFileExistsA
[[GDI32.dll]]
CreateDCA, CreatePolygonRgn, CreateSolidBrush, CreateRectRgn, CreateFontIndirectW
[[KERNEL32.dll]]
GetLastError, InitializeCriticalSectionAndSpinCount, CreateJobObjectA, FindNextVolumeA, GetModuleFileNameW, SetEvent, QueryPerformanceCounter, RegisterWaitForSingleObject, DefineDosDeviceA, ReadConsoleInputW, TlsAlloc, GetVersionExA, FlushFileBuffers, SetUnhandledExceptionFilter, SetConsoleScreenBufferSize, FreeLibrary, GetStdHandle, SetupComm, GetCurrentProcess, GetProcessIoCounters, GetCurrentProcessId, GetCalendarInfoW, GetConsoleTitleW, WideCharToMultiByte, EnumSystemLocalesW, TlsGetValue, MultiByteToWideChar, GetStartupInfoW, GetCPInfo, GetCommandLineA, GetProcAddress, TerminateJobObject, GetComputerNameExA, GetVolumeNameForVolumeMountPointA, RaiseException, GetFileSizeEx, CreateThread, _lcreat, SetSystemPowerState, CreateDirectoryExA, WriteFile, InterlockedIncrement, CloseHandle, GetSystemTimeAsFileTime, ClearCommError, GetACP, HeapReAlloc, GetModuleHandleW, SetThreadExecutionState, ReadConsoleA, PurgeComm, TerminateProcess, LocalSize, FindFirstVolumeA, UnhandledExceptionFilter, CreateFileW, SetConsoleWindowInfo, InterlockedDecrement, Sleep, GetFileType, TlsSetValue, GetTickCount, GetCurrentThreadId, GetProcessHeap, GetFileSize, GetModuleHandleA, EnumUILanguagesW
[[MSVCRT.dll]]
_except_handler3, __p__fmode, __wgetmainargs, _exit, __p__commode, __setusermatherr, __dllonexit, _onexit, exit, _XcptFilter, _initterm, _controlfp, _wcmdln, strlen, _adjust_fdiv, __set_app_type
[[SETUPAPI.dll]]
SetupQueryInfOriginalFileInformationA
[[USER32.dll]]
DefWindowProcW, DestroyMenu, SetWindowPos, SendMessageW, InflateRect, SetCapture, MoveWindow, PostMessageW, SetActiveWindow, GetCursorPos, ReleaseDC, GetMenuStringW, CheckMenuItem, DestroyIcon, UnregisterClassA, RegisterClassW, LoadStringW, SetWindowTextW, AllowSetForegroundWindow, GetSubMenu, GetWindowTextLengthA, LoadIconA, TrackPopupMenu, GetActiveWindow, GetClientRect, CreateWindowExW, GetWindowLongW, PtInRect, GetMenu, OpenClipboard
PE Resources..................:
Resource type Number of resources
RT_ICON 4
RT_GROUP_ICON 1
Resource language Number of resources
ENGLISH US 5
F-Secure Deepguard
Suspicious:W32/Malware!Online
First seen by VirusTotal
2012-09-10 14:20:22 UTC ( 6 Tage, 1 Stunde ago )
Last seen by VirusTotal
2012-09-16 16:17:31 UTC ( 2 Minuten ago )
File names (max. 25)
0.15591863339954004.exe
ABE92E650076FA9CD4C7004A0FC1D700064D0918.exe
cyfqwftr.exe
ptetngmg.vir
cuppsmbx.exe
dcagqexq.exe.vir
ptetngmg.vir
c4f245801868b50316ca13b5305
ms.exe.old
qddsowkf.exe
jbupbpza.exe
Der
Lesezeichen