윈본 파일 확장자는 rer 이며

제가 rer0해서 zip압축 하였습니다 첨부 txt하단 zip패스워드 참조 ^^;

 

 

검사 파일: localhost55.exe 전송 시각: 2010.03.01 23:03:29 (UTC)
안티바이러스 엔진 버전 정의 날짜 검사 결과
a-squared 4.5.0.50 2010.03.01 DroppedWin32!IK
AntiVir 8.2.1.176 2010.03.01 TR/Agent.5599232
Authentium 5.2.0.5 2010.03.01 W32/Mapler.A.gen!Eldorado
BitDefender 7.2 2010.03.01 Trojan.Generic.1641662
CAT-QuickHeal 10.00 2010.03.01 Trojan.Agent.IRC
ClamAV 0.96.0.0-git 2010.03.01 Trojan.Spy-36902
Comodo 4091 2010.02.28 TrojWare.Win32.TrojanSpy.Agent.~CDA
eSafe 7.0.17.0 2010.03.01 Win32.Mapler.ak
eTrust-Vet 35.2.7334 2010.03.01 Win32/Gamepass.LRS
F-Prot 4.5.1.85 2010.03.01 W32/Mapler.A.gen!Eldorado
F-Secure 9.0.15370.0 2010.03.01 Trojan.Generic.1641662
Fortinet 4.0.14.0 2010.02.28 W32/Mapler.AK!tr.pws
GData 19 2010.03.01 Trojan.Generic.1641662
Ikarus T3.1.1.80.0 2010.03.01 DroppedWin32
Jiangmin 13.0.900 2010.03.01 Trojan/PSW.Mapler.ah
K7AntiVirus 7.10.986 2010.03.01 Trojan-PSW.Win32.Mapler.ak
McAfee 5907 2010.03.01 PWS-OnlineGames.eg
McAfee+Artemis 5907 2010.03.01 PWS-OnlineGames.eg
McAfee-GW-Edition 6.8.5 2010.03.01 Trojan.Agent.5599232
Microsoft 1.5502 2010.03.01 PWS:Win32/Prast!rts
Norman 6.04.08 2010.03.01 W32/Malware.CYCF
nProtect 2009.1.8.0 2010.03.01 Trojan-PWS/W32.WebGame.5599232
Panda 10.0.2.2 2010.03.01 Trj/Lineage.BZE
PCTools 7.0.3.5 2010.02.28 Trojan-PSW.Lineage
Rising 22.37.00.04 2010.03.01 Trojan.Spy.Win32.GameOnline.t
Sophos 4.50.0 2010.03.01 Troj/PSW-GW
Sunbelt 5716 2010.03.01 Trojan.Win32.Generic!BT
Symantec 20091.2.0.41 2010.03.01 Infostealer.Lineage
TheHacker 6.5.1.7.217 2010.03.01 Trojan/PSW.Mapler.ak
TrendMicro 9.120.0.1004 2010.03.01 TROJ_Generic.DIT
VBA32 3.12.12.2 2010.03.01 Trojan.DownLoad.4265
VirusBuster 5.0.27.0 2010.03.01 TrojanSpy.Agent.JPYK
 
추가 정보
File size: 5599232 bytes
MD5...: 67a633b12db09358679f122698058744
SHA1..: 2975ddde583bc65039b673adc57b55ec024913c6
SHA256: 349e7a42bd449f7c1d771629cf1e4900a0affefbce3225ff1958ad3f4a422c22
ssdeep: 49152:7HeTlP2+GMzF0UaK1Nl5YN4gZCCQCM0Cla1PrIHGiPe8FLfM9tvnq1ucKM
re0b7d:7mNGA0o7YZQCM0nkpDLXZPbdXiOxd
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x3b81cf
timedatestamp.....: 0x48315e31 (Mon May 19 11:02:09 2008)
machinetype.......: 0x14c (I386)

( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
0x1000 0x415000 0x415000 6.55 70afa6e77c9a5326886d23c5629c774b
0x416000 0x6a000 0x6a000 4.49 cb28bd89fbb8b091731308c115be6d23
0x480000 0x1c000 0x1c000 3.51 3e0e4e840c3abb8ca93ecde0aa266fee
.rsrc 0x49c000 0xa4000 0xa4000 7.08 a1264d0e218e5ef982c79fb902884303
.data 0x540000 0x12000 0x12000 7.69 85ff7d5cf48faf5495ac2646b6f46aad
.adata 0x552000 0x1000 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.tls 0x553000 0x2000 0x2000 0.26 f12e38951003ed035b604c96fb5efdee
.mackt 0x555000 0x2000 0x2000 4.35 7534081c6e06328c30d3796f6bc6927c

( 14 imports )
> advapi32.dll: CryptImportKey, CryptGetHashParam, RegCloseKey, RegSetValueExA, RegQueryValueExA, RegOpenKeyExA, CryptDeriveKey, CryptDecrypt, CryptCreateHash, CryptHashData, CryptVerifySignatureA, CryptDestroyHash, RegEnumValueA, CryptReleaseContext, CryptDestroyKey, CryptEncrypt, CryptAcquireContextA, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, GetUserNameA, RegCreateKeyExA, RegDeleteValueA
> dinput8.dll: DirectInput8Create
> gdi32.dll: BitBlt, SelectObject, CreateCompatibleDC, DeleteDC, GetStockObject, GetObjectA
> kernel32.dll: OpenProcess, GetModuleFileNameA, LocalLock, ReadProcessMemory, CloseHandle, GetCurrentThreadId, FormatMessageA, lstrlen, LocalAlloc, GetVersionExA, IsBadWritePtr, SetUnhandledExceptionFilter, lstrcmpi, LoadLibraryA, GetProcAddress, FreeLibrary, InterlockedExchange, CreateDirectoryA, FindFirstFileA, DeleteFileA, FindNextFileA, FindClose, GetLastError, CompareFileTime, lstrcpy, FileTimeToSystemTime, GetVersion, SetFilePointer, GetLocalTime, SystemTimeToFileTime, IsDBCSLeadByte, MultiByteToWideChar, LocalFree, SetEnvironmentVariableA, CompareStringW, CompareStringA, GetLocaleInfoW, SetConsoleCtrlHandler, FlushFileBuffers, GetUserDefaultLCID, EnumSystemLocalesA, GetLocaleInfoA, IsValidCodePage, IsValidLocale, GetStringTypeW, GetStringTypeA, IsBadCodePtr, GetFileType, LockResource, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, FreeEnvironmentStringsA, UnhandledExceptionFilter, LCMapStringW, LCMapStringA, GetOEMCP, GetACP, GetCPInfo, HeapCreate, HeapDestroy, GetEnvironmentVariableA, GetCurrentThread, SetLastError, TlsFree, TlsAlloc, FatalAppExitA, HeapSize, HeapReAlloc, GetSystemTime, GetTimeZoneInformation, GetFileAttributesA, GetCommandLineA, GetStartupInfoA, ExitThread, TlsGetValue, InterlockedIncrement, InterlockedDecrement, GetVolumeInformationA, GetWindowsDirectoryA, Thread32Next, Thread32First, Process32Next, Process32First, CreateToolhelp32Snapshot, WideCharToMultiByte, TerminateProcess, SetEvent, InitializeCriticalSection, DeleteCriticalSection, SetEndOfFile, WriteFile, ResumeThread, ResetEvent, SetThreadPriority, GetModuleHandleA, GetExitCodeProcess, WaitForMultipleObjects, CreateProcessA, ReadFile, GetFileSize, CreateEventA, WaitForSingleObject, OpenEventA, GetTickCount, CreateFileA, lstrcat, GetCurrentProcessId, LeaveCriticalSection, EnterCriticalSection, OpenMutexA, CreateThread, TerminateThread, CreateMutexA, ReleaseMutex, GetComputerNameA, lstrcmp, ExitProcess, QueryPerformanceCounter, IsBadReadPtr, GetSystemDirectoryA, GetModuleFileNameW, VirtualProtect, UnmapViewOfFile, MapViewOfFile, OpenFileMappingA, CopyFileA, GetCurrentDirectoryA, VirtualQuery, VirtualAlloc, VirtualFree, LoadLibraryExA, GetTempFileNameA, GetTempPathA, HeapFree, GetProcessHeap, HeapAlloc, GetFileInformationByHandle, DuplicateHandle, GetCurrentProcess, SetStdHandle, CreatePipe, GetStdHandle, PeekNamedPipe, Sleep, lstrlenW, RtlUnwind, RaiseException, FileTimeToLocalFileTime, TlsSetValue
> netapi32.dll: Netbios
> oleaut32.dll: SysAllocString, CreateErrorInfo, SysFreeString, SetErrorInfo, VariantInit, VariantChangeType, VariantCopy, SafeArrayDestroy, SafeArrayCreate, VariantClear, GetErrorInfo
> shell32.dll: SHGetSpecialFolderPathA
> user32.dll: wvsprintfA, PtInRect, wsprintfA, BringWindowToTop, AttachThreadInput, GetWindowThreadProcessId, SetRectEmpty, EnumThreadWindows, MessageBoxA, GetWindowTextA, SetRect, MapVirtualKeyA, DialogBoxParamA, FrameRect, LoadBitmapA, IsWindowEnabled, FindWindowA, CreateWindowExA, GetDlgItem, EnableWindow
> wininet.dll: InternetCloseHandle, FtpOpenFileA, InternetConnectA, InternetOpenA, FtpGetFileSize, FtpGetFileA
> winmm.dll: timeKillEvent, timeSetEvent, timeGetTime
> ws2_32.dll: htonl, WSASend, send, sendto, WSACleanup, WSAStartup, getpeername, socket, inet_addr, gethostbyname, WSAGetLastError, closesocket, htons
> ijl15.dll: ijlFree, ijlWrite, ijlInit
> npkcrypt.dll: NPKSetDrvPath, NPKOpenDriver, NPKGetAppCompatFlag, NPKLoadAtStartup, NPKRegisterCryptWindowMsg, NPKCloseDriver, NPKSetAppCompatFlag
> ole32.dll: CoCreateGuid

( 3 exports )
ZtlTaskMemAllocImp, ZtlTaskMemFreeImp, ZtlTaskMemReallocImp
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
sigcheck:
publisher....: Wizet
copyright....: Copyright _ 2003
product......: Wizet MapleStory
description..: MapleStory
original name: MapleStory.exe
internal name: MapleStory
file version.: 1, 0, 0, 1
comments.....:
signers......: -
signing date.: -
verified.....: Unsigned

 

 

↑ 는 rer풀고 안에 exe파일 rer안에껀 건들지 않았습니다

바토 이거는 회원분들 궁금할것같아

pws면 패스웨드 훔치는거 그건데 ;; ㅋㅋ

 

암튼 수고 좀 해주십시오 다음번 부터는 메일로 발송이 됩니다

생긴거는 메이플스토리 플섭 같이 생겻더군요 -_-

'2' 댓글

[레벨:7]운영자

2010.03.03
12:11:41
(*.202.190.95)

감사합니다.^^;

[레벨:3]heat예비군

2010.03.04
13:55:02
(*.79.106.41)

하우리는 업글 되었다고하나

안랩같은경우는 한셋트 오고 개당 진단해서 정상인건빼고 악의적인건 추가하기땜에 진단 보류가 되더군요 ㄷㄷ

위 상기 바이러스는 테스트 결과

핵실드가 엔프로택터로 연결되어 있고 메이플 클라언트 핵실드는  실제로는 안랩 핵실드를 사용합니다

이미 엔프로택터에서는 진단하고 있구요

문서 첨부 제한 : 0Byte/ 2.00MB
파일 제한 크기 : 2.00MB (허용 확장자 : *.*)
옵션 :
:
:
:
:
List of Articles
번호 제목 글쓴이 날짜 조회 수
공지 악성코드 신고하기 게시판 이용방법 [1] [레벨:7]운영자 2008-12-23 6310
49 트로이잔 백도어 pws 에이젠트 신고 합니다 [1] file [레벨:3]heat예비군 2010-04-10 1686
48 트로이잔크랙커 신고 합니다 [1] file [레벨:3]heat예비군 2010-03-24 1445
47 메일 확인 요청부탁드립니다 [6] [레벨:3]heat예비군 2010-03-04 1611
» 트로이잔 스파이 pws 신고 합니다 [2] file [레벨:3]heat예비군 2010-03-02 1639
45 exploit 신고요 file [레벨:3]heat예비군 2010-02-26 1544
44 서든월핵바이러스 트로이잔 드럽퍼 2010-02-20일자 [1] file [레벨:3]heat예비군 2010-02-21 1962
43 faizal.js [2] [레벨:0]너만고양이 2010-02-19 3167
42 [서든바이러스 ) 신고 1-2 (분활1-3)마지막 [1] file [레벨:3]heat예비군 2010-02-19 1595
41 [서든바이러스 ) 신고 1-2 (분활1-2) file [레벨:3]heat예비군 2010-02-19 1648
40 [서든바이러스 ) 신고 1-2 (분활1-1) file [레벨:3]heat예비군 2010-02-19 1666

악성코드 신고