Cevap: 1508 Knight Online Win. Çin Dosyaları
Virüs var bu dosyalarda,
Dosyalar packli olduğundan da virüs gibi görünebilir ama
Virustotal. MD5: d0ceb76ece0d4186066b7fca52972639 Artemis!D0CEB76ECE0D Gen:Trojan.Heur.Ns0a4WWtQOlP Gen:Trojan.Heur.Ns0a4WWtQOlP
Antivirüs Versiyon Son Güncelleştirme Sonuç
a-squared 4.5.0.50 2021.05.10 Gen.Trojan!IK
AhnLab-V3 2021.05.16.00 2021.05.15 Malware/Win32.Generic
AntiVir 8.2.1.242 2021.05.14 TR/Spy.2736128
Antiy-AVL 2.0.3.7 2021.05.14 -
Authentium 5.2.0.5 2021.05.15 -
Avast 4.8.1351.0 2021.05.15 Win32:Spyware-gen
Avast5 5.0.332.0 2021.05.15 Win32:Spyware-gen
AVG 9.0.0.787 2021.05.15 -
BitDefender 7.2 2021.05.16 Gen:Trojan.Heur.Ns0a4WWtQOlP
CAT-QuickHeal 10.00 2021.05.15 -
ClamAV 0.96.0.3-git 2021.05.15 -
Comodo 4853 2021.05.16 Heur.Pck.Themida
DrWeb 5.0.2.03300 2021.05.16 Trojan.Packed.650
eSafe 7.0.17.0 2021.05.13 -
eTrust-Vet 35.2.7490 2021.05.15 -
F-Prot 4.5.1.85 2021.05.15 -
F-Secure 9.0.15370.0 2021.05.15 Gen:Trojan.Heur.Ns0a4WWtQOlP
Fortinet 4.1.133.0 2021.05.15 W32/Packed.2D18!tr
GData 21 2021.05.16 Gen:Trojan.Heur.Ns0a4WWtQOlP
Ikarus T3.1.1.84.0 2021.05.15 Gen.Trojan
Jiangmin 13.0.900 2021.05.15 -
Kaspersky 7.0.0.125 2021.05.16 -
McAfee 5.400.0.1158 2021.05.16 New Malware.jn
McAfee-GW-Edition 2021.1 2021.05.16 Artemis!D0CEB76ECE0D
Microsoft 1.5703 2021.05.14 -
NOD32 5117 2021.05.15 -
Norman 6.04.12 2021.05.15 -
nProtect 2021-05-15.01 2021.05.15 -
Panda 10.0.2.7 2021.05.15 -
PCTools 7.0.3.5 2021.05.16 Packed/Themida
Rising 22.47.04.03 2021.05.14 -
Sophos 4.53.0 2021.05.16 Mal/Behav-285
Sunbelt 6308 2021.05.16 -
Symantec 20101.1.0.89 2021.05.16 -
TheHacker 6.5.2.0.280 2021.05.14 -
TrendMicro 9.120.0.1004 2021.05.15 -
TrendMicro-HouseCall 9.120.0.1004 2021.05.16 -
VBA32 3.12.12.5 2021.05.14 -
ViRobot 2021.5.15.2318 2021.05.15 -
VirusBuster 5.0.27.0 2021.05.15 Packed/Themida
Ýlave Bilgiler
File size: 2736128 bytes
MD5 : d0ceb76ece0d4186066b7fca52972639
SHA1 : c60d54d0bbd627a88331d478eec5289da86d2449
SHA256: b02b358a5b8cb5b0bdccb029ca7ff3b295e5669bc378e8cd0488ad76f440166c
PEInfo: PE Structure information<br> <br> ( base data )<br> entrypointaddress.: 0x56F014<br> timedatestamp.....: 0x45B05C63 (Fri Jan 19 06:51:31 2021)<br> machinetype.......: 0x14C (Intel I386)<br> <br> ( 4 sections )<br> name viradd virsiz rawdsiz ntrpy md5<br> 0x1000 0x564000 0xF0000 7.98 2128f0e0d39c5abd28d73a17c3b7b4d0<br>.rsrc 0x565000 0x888C 0x4000 5.14 21f2a719b905a0852cc71942d4aae0a0<br>.idata 0x56E000 0x1000 0x1000 0.24 15b95eea0ce567276ec31d1f2af1e641<br>fdgdf 0x56F000 0x3C5000 0x1A6000 7.84 86929d59b5353eabf30d955e5d02a8c0<br> <br> ( 2 imports )<br> <br>> comctl32.dll: InitCommonControls<br>> kernel32.dll: CreateFileA, ExitProcess<br> <br> ( 0 exports )<br>
TrID : File type identification<br>Win32 Executable Generic (42.3%)<br>Win32 Dynamic Link Library (generic) (37.6%)<br>Generic Win/DOS Executable (9.9%)<br>DOS Executable Generic (9.9%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
Symantec reputation: Suspicious.Insight Suspicious.Insight | Symantec
ssdeep: 49152:5oQXJrU4yLDUqIk4Ss4kowRA/QVpXuRxgwj7UxyZO1JxAqIRvWxGzQ8Oh70h4eJ:3ZQ4yLDUEtbEeQ/XuRj8xpT2RvZQ8KG
sigcheck: publisher....: n/a<br>copyright....: Copyright (C) 2000<br>product......: Server __ ____<br>description..: Server MFC __ ____<br>original name: Server.EXE<br>internal name: Server<br>file version.: 1, 0, 0, 1<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
PEiD : -
packers (F-Prot): Themida
RDS : NSRL Reference Data Set<br>-