Hi guy's im a new members here can anyone help me?
I download the latest AgBot from rev6 and i make a quick scan with "Virus total" LOOK what i found:
Fişier nuConnector77.exe primit la data de 2009.03.15 11:25:10 (CET)
Status actual: īncheiat
Rezultat: 24/39 (61.54%)
Rezultate compacte Imprimă rezultatele
Antivirus Versiune Ultima actualizare Rezultat
a-squared 4.0.0.101 2009.03.15 Backdoor.Win32.Hupigon!IK
AhnLab-V3 5.0.0.2 2009.03.15 Win-Trojan/Hupigon.242688.M
AntiVir 7.9.0.114 2009.03.13 BDS/Hupigon.fpvc
Authentium 5.1.0.4 2009.03.14 W32/Heuristic-324!********
Avast 4.8.1335.0 2009.03.14 -
AVG 8.0.0.237 2009.03.14 BackDoor.Hupigon4.BDDK
BitDefender 7.2 2009.03.15 Backdoor.Hupigon.139811
CAT-QuickHeal 10.00 2009.03.14 Backdoor.Hupigon.fpuu
ClamAV 0.94.1 2009.03.15 -
Comodo 1057 2009.03.15 Unclassified Malware
DrWeb 4.44.0.09170 2009.03.15 -
eSafe 7.0.17.0 2009.03.12 -
eTrust-Vet 31.6.6388 2009.03.09 -
F-Prot 4.4.4.56 2009.03.14 W32/Heuristic-324!********
F-Secure 8.0.14470.0 2009.03.15 Backdoor.Win32.Hupigon.fpvc
Fortinet 3.117.0.0 2009.03.15 -
GData 19 2009.03.15 Backdoor.Hupigon.139811
Ikarus T3.1.1.45.0 2009.03.14 Backdoor.Win32.Hupigon
K7AntiVirus 7.10.671 2009.03.14 Backdoor.Win32.Hupigon
Kaspersky 7.0.0.125 2009.03.15 Backdoor.Win32.Hupigon.fpvc
McAfee 5553 2009.03.14 BackDoor-AWQ.b
McAfee+Artemis 5553 2009.03.14 BackDoor-AWQ.b
McAfee-GW-Edition 6.7.6 2009.03.13 Trojan.Backdoor.Hupigon.fpvc
Microsoft 1.4405 2009.03.15 -
NOD32 3937 2009.03.15 probably a variant of Win32/Hupigon
Norman 6.00.06 2009.03.13 W32/Hupigon.EXLN
nProtect 2009.1.8.0 2009.03.15 Backdoor/W32.Hupigon.242688.C
Panda 10.0.0.10 2009.03.14 Bck/Hupigon.AZG
PCTools 4.4.2.0 2009.03.14 -
Prevx1 V2 2009.03.15 -
Rising 21.20.62.00 2009.03.15 -
Sophos 4.39.0 2009.03.15 -
Sunbelt 3.2.1858.2 2009.03.15 -
Symantec 1.4.4.12 2009.03.15 Backdoor.Graybird
TheHacker 6.3.3.0.282 2009.03.15 -
TrendMicro 8.700.0.1004 2009.03.13 -
VBA32 3.12.10.1 2009.03.15 Backdoor.Win32.Hupigon.fpuv
ViRobot 2009.3.13.1648 2009.03.13 Backdoor.Win32.Hupigon.242688.H
VirusBuster 4.6.5.0 2009.03.14 -
Informaţii suplimentare
File size: 242688 bytes
MD5...: 49b4998ee6634da137bb1b76a44eba3c
SHA1..: d88927263ca4bc860c4a1b9806ef2661a21d5026
SHA256: 94d78d823a1e8b2b3557ef2b1bcf5b73dc1ee770aacd5fb5d5 0e446dd4a91124
SHA512: 95c6cd3511baf36c2f21ee9a5d4e7d34b81d7c266fd672f603 33e8151df25e06
6973dcc6b9c506bc1182da54b15aa8fcc0a7420ab9ae6e7c7f c2446dac45c6bb
ssdeep: 6144:s+jNjVGPhOHPZhpmushUvm536tLFgIsRC+DIdOg:s+jjG P2bpchUegtLuod
PEiD..: ASPack v2.12
TrID..: File type identification
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x67001
timedatestamp.....: 0x48db313d (Thu Sep 25 06:35:41 2008)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1c000 0xc000 8.00 a14f3c371ead488961d9e63c9449ce8d
.rdata 0x1d000 0x4000 0x1400 7.87 e130350b88fa05a36d9faa2949438100
.data 0x21000 0x46000 0x2ca00 7.97 b6f6a33195639b0c44c695d5c05954a6
.NeDra 0x67000 0x1000 0x1000 6.05 b9a9e71f680f2f193225fefe551312ab
.adata 0x68000 0x1000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
( 1 imports )
> kernel32.dll: GetProcAddress, GetModuleHandleA, LoadLibraryA
( 0 exports )
packers (Kaspersky): ASPack
CWSandbox info:
packers (Authentium): Aspack
packers (F-Prot): Aspack
THIS FILE IS INFECTED WITH SOMETHING>>A TROJAN>>>
It's normal...or not??