サイトにアクセスするとダウンロードさせようとするファイル(adobe_flash.exe)をスキャンした結果

ファイル名 adobe_flash_1_.exe 受理 2008.08.10 12:03:01 (CET)
アンチウイルスバージョン更新日結果
AhnLab-V32008.8.9.02008.08.08-
AntiVir7.8.1.192008.08.09TR/Crypt.XPACK.Gen
Authentium5.1.0.42008.08.10-
Avast4.8.1195.02008.08.09-
AVG8.0.0.1562008.08.09I-Worm/Nuwar.V
BitDefender7.22008.08.10Trojan.Downloader.Exchanger.Gen.2
CAT-QuickHeal9.502008.08.08(Suspicious) - DNAScan
ClamAV0.93.12008.08.10Trojan.Downloader.Exchanger-14
DrWeb4.44.0.091702008.08.09Trojan.DownLoad.3248
eSafe7.0.17.02008.08.07Suspicious File
eTrust-Vet31.6.60192008.08.08-
Ewido4.02008.08.10-
F-Prot4.4.4.562008.08.10-
F-Secure7.60.13501.02008.08.10Trojan-Downloader:W32/Exchanger.AI
Fortinet3.14.0.02008.08.10W32/Agent.XPA!tr
GData2.0.7306.10232008.08.10Trojan-Downloader.Win32.Exchanger.lj
IkarusT3.1.1.34.02008.08.10Win32.SuspectCrc
K7AntiVirus7.10.4082008.08.09-
Kaspersky7.0.0.1252008.08.10Trojan-Downloader.Win32.Exchanger.lj
McAfee53572008.08.08-
Microsoft1.38072008.08.10Trojan:Win32/Tibs.gen!K
NOD32v233432008.08.10a variant of Win32/Agent.ETH
Norman5.80.022008.08.08-
Panda9.0.0.42008.08.10-
PCTools4.4.2.02008.08.09-
Prevx1V22008.08.10Malware Dropper
Rising20.56.41.002008.08.08-
Sophos4.32.02008.08.10Mal/EncPk-DA
Sunbelt3.1.1538.12008.08.09-
Symantec102008.08.10Downloader
TheHacker6.2.96.3952008.08.08-
TrendMicro8.700.0.10042008.08.08-
VBA323.12.8.32008.08.09-
ViRobot2008.8.8.13292008.08.08-
VirusBuster4.5.11.02008.08.09-
Webwasher-Gateway6.6.22008.08.10Trojan.Crypt.XPACK.Gen
 
追加情報
File size: 78848 bytes
MD5...: 0e41b670cbccce9051fb8d1188aebd0a
SHA1..: d9a952ef59c5ee30e63b9d3dd781a7477911c866
SHA256: a5528757cd736d7a801443d0d4490b0d6d7c54a09e014afc240c62fd45ddadf6
SHA512: 1654e3b70376b817c9428007d26b34474f081e3082acdcbd3759b136d0dbe4f0
a04ba3c8da0d9ee1b84689d3b3f437f9595f3a4c763fed578d67ae201acc6cc4
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4031ea
timedatestamp.....: 0x48907860 (Wed Jul 30 14:19:12 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xdf67 0xc200 8.00 1669d4c46f67c2607e453e100d48dddb
.rdata 0xf000 0x364e 0x2200 7.98 8415cf3708abe87d207cae6a2f2860be
.data 0x13000 0x6000 0x4000 5.15 6721b9bd1e84b671acfbb5d3cbc4bdb1

( 4 imports )
> MSVCRT.DLL: _itow, iswcntrl, isxdigit
> ADVAPI32.DLL: LsaOpenSecret, RegUnLoadKeyW, UnlockServiceDatabase, RevertToSelf, LsaClose
> WININET.DLL: InternetDialW, InternetGetCookieW, ShowCertificate, InternetSetCookieW, UrlZonesDetach
> USER32.DLL: GetForegroundWindow, GetMenuStringW, GetScrollPos, LoadKeyboardLayoutW, SetDoubleClickTime, SendInput

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=8F3D24A4003F66983457019EED05CB00A97B99D5