analyse netsik virus total
Fichier netsik.sys reçu le 2009.04.18 03:00:13 (CET)
Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.101 2009.04.18 Rootkit.Win32.Agent!IK
AhnLab-V3 5.0.0.2 2009.04.17 Win-Trojan/Rootkit.30464
AntiVir 7.9.0.143 2009.04.17 TR/Crypt.XDR.Gen
Antiy-AVL 2.0.3.1 2009.04.17 Trojan/Win32.Agent
Authentium 5.1.2.4 2009.04.18 -
Avast 4.8.1335.0 2009.04.17 Win32:Cutwail
AVG 8.5.0.287 2009.04.17 Rootkit-Agent.CW
BitDefender 7.2 2009.04.18 Rootkit.Kobcka.C
CAT-QuickHeal 10.00 2009.04.17 Rootkit.Agent.ikz
ClamAV 0.94.1 2009.04.18 Trojan.Rootkit-1549
Comodo 1117 2009.04.17 TrojWare.Win32.Rootkit.Agent.~GE
DrWeb 4.44.0.09170 2009.04.17 Trojan.NtRootKit.2763
eSafe 7.0.17.0 2009.04.13 Win32.TRCrypt.Xdr
eTrust-Vet 31.6.6455 2009.04.14 Win32/Cutwail.XR
F-Prot 4.4.4.56 2009.04.17 -
F-Secure 8.0.14470.0 2009.04.17 Rootkit.Win32.Agent.ikz
Fortinet 3.117.0.0 2009.04.17 W32/Pushu.IKZ!tr
GData 19 2009.04.18 Rootkit.Kobcka.C
Ikarus T3.1.1.49.0 2009.04.18 Rootkit.Win32.Agent
K7AntiVirus 7.10.707 2009.04.17 Rootkit.Win32.Agent.ikz
Kaspersky 7.0.0.125 2009.04.18 Rootkit.Win32.Agent.ikz
McAfee 5587 2009.04.17 Generic Rootkit.w
McAfee+Artemis 5587 2009.04.17 Generic Rootkit.w
McAfee-GW-Edition 6.7.6 2009.04.18 Trojan.Crypt.XDR.Gen
Microsoft 1.4502 2009.04.17 VirTool:WinNT/Cutwail.gen!E
NOD32 4018 2009.04.18 Win32/TrojanDownloader.Wigon.BS
Norman 6.00.06 2009.04.17 Rootkit.AAJR
nProtect 2009.1.8.0 2009.04.17 Trojan/W32.Rootkit.30464.C
Panda 10.0.0.14 2009.04.17 Adware/GoodSearchNow
PCTools 4.4.2.0 2009.04.17 -
Prevx1 V2 2009.04.18 High Risk Rootkit
Rising 21.25.44.00 2009.04.17 RootKit.Win32.Agent.erf
Sophos 4.40.0 2009.04.18 Troj/Pushu-Gen
Sunbelt 3.2.1858.2 2009.04.17 Rootkit.Win32.Agent.gvv
Symantec 1.4.4.12 2009.04.18 Hacktool.Rootkit
TheHacker 6.3.4.0.309 2009.04.16 Trojan/Agent.ikz
TrendMicro 8.700.0.1004 2009.04.17 -
VBA32 3.12.10.2 2009.04.12 Rootkit.Win32.Agent.ikz
ViRobot 2009.4.17.1698 2009.04.17 Trojan.Win32.RT-Agent.30464.D
VirusBuster 4.6.5.0 2009.04.17 Rootkit.Agent.IYVB
Information additionnelle
File size: 30464 bytes
MD5...: ef69765ea006b5ffd1bfd95571992019
SHA1..: f98563244e876f98d059c23ca128979badf1d9b6
SHA256: f80296f63c5c5dc0003c3eb49920e0310117abeffbbd17c3fd380c1bc4e68733
SHA512: b16c4f10a99d7735e6b8993eba571436a64221443824d4df5995c0c72a6614af<br>9b93706fcbc6d39205cd6bcf3891de4157153c67109d3882c71c50d716144508
ssdeep: 768:jAqoVx/v7s+XgpzEmtXQJyE83PaLMqglF5vZY:jkVx7vXgKmadaaN<br>
PEiD..: -
TrID..: File type identification<br>Win32 Executable Generic (58.4%)<br>Clipper DOS Executable (13.8%)<br>Generic Win/DOS Executable (13.7%)<br>DOS Executable Generic (13.7%)<br>VXD Driver (0.2%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x736<br>timedatestamp.....: 0x49ba95a6 (Fri Mar 13 17:19:34 2009)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x480 0x10ac 0x1100 6.20 ab2190b2e9770b92bdfd022f872bb155<br>.rdata 0x1580 0x1cc 0x200 3.72 44716ceae94e2caf8617f16dbf39844a<br>.data 0x1780 0x56b0 0x5700 6.16 4aed4a9272c319013a5bd7a87b232de5<br>INIT 0x6e80 0x496 0x500 4.96 a309b57ef6c97414f4b51a5c4844989c<br>.reloc 0x7380 0x36e 0x380 3.09 565115503e89ba7c329ab2f29a7b4681<br><br>( 2 imports ) <br>> ntoskrnl.exe: NtBuildNumber, RtlInitUnicodeString, memset, PsLookupProcessByProcessId, IofCompleteRequest, ExFreePoolWithTag, ZwClose, ZwWriteFile, ZwCreateFile, ExAllocatePool, DbgPrint, _except_handler3, memcpy, PsSetCreateProcessNotifyRoutine, IoCreateSymbolicLink, IoCreateDevice, ZwQuerySystemInformation, ObReferenceObjectByHandle, ZwOpenThread, ObfReferenceObject, ObfDereferenceObject, IoFreeMdl, KeInsertQueueApc, KeInitializeApc, KeUnstackDetachProcess, MmMapLockedPagesSpecifyCache, KeStackAttachProcess, MmProbeAndLockPages, wcsncmp, ObOpenObjectByName, wcsstr, RtlAppendUnicodeStringToString, RtlAppendUnicodeToString, ZwQueryDirectoryObject, ZwOpenDirectoryObject, KeReleaseMutex, KeWaitForSingleObject, ExAllocatePoolWithTag, MmIsAddressValid, IoRegisterFsRegistrationChange, KeInitializeMutex, IoAllocateMdl<br>> HAL.dll: KfLowerIrql, KfRaiseIrql<br><br>( 0 exports ) <br>
RDS...: NSRL Reference Data Set<br>-
Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=54EC5FCA0080794077370025A637ED00ADB5AB2D' target='_blank'>
http://info.prevx.com/...
Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.101 2009.04.18 Rootkit.Win32.Agent!IK
AhnLab-V3 5.0.0.2 2009.04.17 Win-Trojan/Rootkit.30464
AntiVir 7.9.0.143 2009.04.17 TR/Crypt.XDR.Gen
Antiy-AVL 2.0.3.1 2009.04.17 Trojan/Win32.Agent
Authentium 5.1.2.4 2009.04.18 -
Avast 4.8.1335.0 2009.04.17 Win32:Cutwail
AVG 8.5.0.287 2009.04.17 Rootkit-Agent.CW
BitDefender 7.2 2009.04.18 Rootkit.Kobcka.C
CAT-QuickHeal 10.00 2009.04.17 Rootkit.Agent.ikz
ClamAV 0.94.1 2009.04.18 Trojan.Rootkit-1549
Comodo 1117 2009.04.17 TrojWare.Win32.Rootkit.Agent.~GE
DrWeb 4.44.0.09170 2009.04.17 Trojan.NtRootKit.2763
eSafe 7.0.17.0 2009.04.13 Win32.TRCrypt.Xdr
eTrust-Vet 31.6.6455 2009.04.14 Win32/Cutwail.XR
F-Prot 4.4.4.56 2009.04.17 -
F-Secure 8.0.14470.0 2009.04.17 Rootkit.Win32.Agent.ikz
Fortinet 3.117.0.0 2009.04.17 W32/Pushu.IKZ!tr
GData 19 2009.04.18 Rootkit.Kobcka.C
Ikarus T3.1.1.49.0 2009.04.18 Rootkit.Win32.Agent
K7AntiVirus 7.10.707 2009.04.17 Rootkit.Win32.Agent.ikz
Kaspersky 7.0.0.125 2009.04.18 Rootkit.Win32.Agent.ikz
McAfee 5587 2009.04.17 Generic Rootkit.w
McAfee+Artemis 5587 2009.04.17 Generic Rootkit.w
McAfee-GW-Edition 6.7.6 2009.04.18 Trojan.Crypt.XDR.Gen
Microsoft 1.4502 2009.04.17 VirTool:WinNT/Cutwail.gen!E
NOD32 4018 2009.04.18 Win32/TrojanDownloader.Wigon.BS
Norman 6.00.06 2009.04.17 Rootkit.AAJR
nProtect 2009.1.8.0 2009.04.17 Trojan/W32.Rootkit.30464.C
Panda 10.0.0.14 2009.04.17 Adware/GoodSearchNow
PCTools 4.4.2.0 2009.04.17 -
Prevx1 V2 2009.04.18 High Risk Rootkit
Rising 21.25.44.00 2009.04.17 RootKit.Win32.Agent.erf
Sophos 4.40.0 2009.04.18 Troj/Pushu-Gen
Sunbelt 3.2.1858.2 2009.04.17 Rootkit.Win32.Agent.gvv
Symantec 1.4.4.12 2009.04.18 Hacktool.Rootkit
TheHacker 6.3.4.0.309 2009.04.16 Trojan/Agent.ikz
TrendMicro 8.700.0.1004 2009.04.17 -
VBA32 3.12.10.2 2009.04.12 Rootkit.Win32.Agent.ikz
ViRobot 2009.4.17.1698 2009.04.17 Trojan.Win32.RT-Agent.30464.D
VirusBuster 4.6.5.0 2009.04.17 Rootkit.Agent.IYVB
Information additionnelle
File size: 30464 bytes
MD5...: ef69765ea006b5ffd1bfd95571992019
SHA1..: f98563244e876f98d059c23ca128979badf1d9b6
SHA256: f80296f63c5c5dc0003c3eb49920e0310117abeffbbd17c3fd380c1bc4e68733
SHA512: b16c4f10a99d7735e6b8993eba571436a64221443824d4df5995c0c72a6614af<br>9b93706fcbc6d39205cd6bcf3891de4157153c67109d3882c71c50d716144508
ssdeep: 768:jAqoVx/v7s+XgpzEmtXQJyE83PaLMqglF5vZY:jkVx7vXgKmadaaN<br>
PEiD..: -
TrID..: File type identification<br>Win32 Executable Generic (58.4%)<br>Clipper DOS Executable (13.8%)<br>Generic Win/DOS Executable (13.7%)<br>DOS Executable Generic (13.7%)<br>VXD Driver (0.2%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x736<br>timedatestamp.....: 0x49ba95a6 (Fri Mar 13 17:19:34 2009)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x480 0x10ac 0x1100 6.20 ab2190b2e9770b92bdfd022f872bb155<br>.rdata 0x1580 0x1cc 0x200 3.72 44716ceae94e2caf8617f16dbf39844a<br>.data 0x1780 0x56b0 0x5700 6.16 4aed4a9272c319013a5bd7a87b232de5<br>INIT 0x6e80 0x496 0x500 4.96 a309b57ef6c97414f4b51a5c4844989c<br>.reloc 0x7380 0x36e 0x380 3.09 565115503e89ba7c329ab2f29a7b4681<br><br>( 2 imports ) <br>> ntoskrnl.exe: NtBuildNumber, RtlInitUnicodeString, memset, PsLookupProcessByProcessId, IofCompleteRequest, ExFreePoolWithTag, ZwClose, ZwWriteFile, ZwCreateFile, ExAllocatePool, DbgPrint, _except_handler3, memcpy, PsSetCreateProcessNotifyRoutine, IoCreateSymbolicLink, IoCreateDevice, ZwQuerySystemInformation, ObReferenceObjectByHandle, ZwOpenThread, ObfReferenceObject, ObfDereferenceObject, IoFreeMdl, KeInsertQueueApc, KeInitializeApc, KeUnstackDetachProcess, MmMapLockedPagesSpecifyCache, KeStackAttachProcess, MmProbeAndLockPages, wcsncmp, ObOpenObjectByName, wcsstr, RtlAppendUnicodeStringToString, RtlAppendUnicodeToString, ZwQueryDirectoryObject, ZwOpenDirectoryObject, KeReleaseMutex, KeWaitForSingleObject, ExAllocatePoolWithTag, MmIsAddressValid, IoRegisterFsRegistrationChange, KeInitializeMutex, IoAllocateMdl<br>> HAL.dll: KfLowerIrql, KfRaiseIrql<br><br>( 0 exports ) <br>
RDS...: NSRL Reference Data Set<br>-
Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=54EC5FCA0080794077370025A637ED00ADB5AB2D' target='_blank'>
http://info.prevx.com/...