Файл uTorrent.exe получен 2010.06.19 07:50:03 (UTC)
Антивирус Версия Обновление Результат
Kaspersky 7.0.0.125 2010.06.19 Trojan.Win32.Midgare.aofm
Дополнительная информация
File size: 323376 bytes
MD5...: e197cb959c6885c97b824a32e2b03d38
SHA1..: ba9be26f222a9664028d33624d1a2091030479a3
SHA256: 9aa43c166d025ca70013aa0504a6de18a5441086fe26f555aa ea16db0a8b3b63
ssdeep: 6144:EaEK25d/6NAvbZTUAHq6vxVp7cmarLicNCcdzi5apteaTRDZwd5pAgoSU: u<BR>/1vbuAdxVpImkLizcTem2d5pNoSU<BR>
PEiD..: -
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0xca120<BR>timedatestamp.....: 0x4c196f0f (Thu Jun 17 00:40:47 2010)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>UPX0 0x1000 0x80000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR>UPX1 0x81000 0x4a000 0x49e00 8.00 2deb956f0b2e44c0779479646f12c0b8<BR>.rsrc 0xcb000 0x4000 0x3800 4.49 870ce41450b28daedb9bbdc5573c24ea<BR><BR>( 9 imports ) <BR>> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess<BR>> ADVAPI32.dll: FreeSid<BR>> COMCTL32.dll: -<BR>> comdlg32.dll: GetSaveFileNameW<BR>> GDI32.dll: LineTo<BR>> MSVCRT.dll: exit<BR>> SHELL32.dll: DragFinish<BR>> USER32.dll: GetDC<BR>> WS2_32.dll: -<BR><BR>( 0 exports ) <BR>
RDS...: NSRL Reference Data Set<BR>-
pdfid.: -
trid..: UPX compressed Win32 Executable (39.5%)<BR>Win32 EXE Yoda's Crypter (34.3%)<BR>Win32 Executable Generic (11.0%)<BR>Win32 Dynamic Link Library (generic) (9.8%)<BR>Generic Win/DOS Executable (2.5%)
packers (Kaspersky): UPX
packers (F-Prot): UPX_LZMA
sigcheck:<BR>publisher....: BitTorrent, Inc.<BR>copyright....: (c)2010 BitTorrent, Inc. All Rights Reserved.<BR>product......: _Torrent<BR>description..: _Torrent<BR>original name: uTorrent.exe<BR>internal name: uTorrent.exe<BR>file version.: 2.0.2.20165<BR>comments.....: n/a<BR>signers......: BitTorrent Inc<BR> VeriSign Class 3 Code Signing 2004 CA<BR> Class 3 Public Primary Certification Authority<BR>signing date.: 2:41 AM 6/17/2010<BR>verified.....: -<BR>