Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File dirlock.exe received on 2009.07.15 03:26:50 (UTC)
Current status: finished
Result: 17/41 (41.46%)
Antivirus Version Last Update Result
a-squared 4.5.0.22 2009.07.15 Trojan-Spy.Win32.SpyEx!IK
AhnLab-V3 5.0.0.2 2009.07.14 -
AntiVir 7.9.0.215 2009.07.14 TR/Spy.90112.70
Antiy-AVL 2.0.3.7 2009.07.15 -
Authentium 5.1.2.4 2009.07.14 -
Avast 4.8.1335.0 2009.07.14 Win32:Rootkit-gen
AVG 8.5.0.387 2009.07.14 Generic14.BEP
BitDefender 7.2 2009.07.15 Gen:Trojan.Heur.50649BBEAE
CAT-QuickHeal 10.00 2009.07.14 -
ClamAV 0.94.1 2009.07.15 -
Comodo 1654 2009.07.15 -
DrWeb 5.0.0.12182 2009.07.14 -
eSafe 7.0.17.0 2009.07.14 Win32.Genetik
eTrust-Vet 31.6.6615 2009.07.14 -
F-Prot 4.4.4.56 2009.07.14 -
F-Secure 8.0.14470.0 2009.07.15 -
Fortinet 3.120.0.0 2009.07.15 PossibleThreat
GData 19 2009.07.15 Gen:Trojan.Heur.50649BBEAE
Ikarus T3.1.1.64.0 2009.07.15 Trojan-Spy.Win32.SpyEx
Jiangmin 11.0.706 2009.07.14 -
K7AntiVirus 7.10.792 2009.07.14 -
Kaspersky 7.0.0.125 2009.07.15 -
McAfee 5676 2009.07.14 -
McAfee+Artemis 5676 2009.07.14 Artemis!00D6B243FC1E
McAfee-GW-Edition 6.8.5 2009.07.14 Heuristic.LooksLike.eeGW Trojan.L
Microsoft 1.4803 2009.07.14 -
NOD32 4244 2009.07.15 probably a variant of Win32/Genetik
Norman 6.01.09 2009.07.14 W32/Obfuscated.H!genr
nProtect 2009.1.8.0 2009.07.15 -
Panda 10.0.0.14 2009.07.14 -
PCTools 4.4.2.0 2009.07.14 -
Prevx 3.0 2009.07.15 Medium Risk Malware
Rising 21.38.14.00 2009.07.14 -
Sophos 4.43.0 2009.07.15 -
Sunbelt 3.2.1858.2 2009.07.15 Gen-Trojan.Heur
Symantec 1.4.4.12 2009.07.15 W32.SillyFDC
TheHacker 6.3.4.3.367 2009.07.14 -
TrendMicro 8.950.0.1094 2009.07.14 PAK_Generic.001
VBA32 3.12.10.8 2009.07.15 -
ViRobot 2009.7.14.1835 2009.07.15 -
VirusBuster 4.6.5.0 2009.07.14 -
Additional information
File size: 90112 bytes
MD5   : 00d6b243fc1ec236b1413b00736bd469
SHA1  : a3fbc5483f65838e8e704922cafb0655d54d2753
SHA256: 1792898f7a2e2110b5668247d0fbadcf9197bc334197743f9d8e92716f79c598
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x23D0
timedatestamp.....: 0x4A02C232 (Thu May 7 13:12:50 2009)
machinetype.......: 0x14C (Intel I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x10F80 0x11000 5.67 4334e915b5d9cb6f229b57eab74a0976
.data 0x12000 0x660 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rsrc 0x13000 0x25EC 0x3000 4.37 f83655d78fb05980ee167230b6d7e397

( 1 imports )

> msvbvm60.dll: _CIcos, _adj_fptan, __vbaVarMove, __vbaVarVargNofree, -, __vbaFreeVar, __vbaStrVarMove, __vbaLenBstr, __vbaEnd, __vbaFreeVarList, _adj_fdiv_m64, -, __vbaNextEachVar, __vbaFreeObjList, _adj_fprem1, -, -, __vbaStrCat, -, -, __vbaSetSystemError, __vbaHresultCheckObj, _adj_fdiv_m32, -, __vbaAryDestruct, __vbaExitProc, -, -, __vbaOnError, _adj_fdiv_m16i, _adj_fdivr_m16i, -, __vbaBoolVar, __vbaBoolVarNull, _CIsin, __vbaVargVarMove, -, __vbaChkstk, __vbaFileClose, EVENT_SINK_AddRef, __vbaStrCmp, -, __vbaAryConstruct2, __vbaVarTstEq, __vbaObjVar, DllFunctionCall, __vbaVarLateMemSt, __vbaRedimPreserve, _adj_fpatan, __vbaRedim, EVENT_SINK_Release, -, _CIsqrt, __vbaVarAnd, EVENT_SINK_QueryInterface, __vbaExceptHandler, __vbaPrintFile, __vbaStrToUnicode, _adj_fprem, _adj_fdivr_m64, -, -, -, -, __vbaFPException, -, __vbaStrVarVal, __vbaVarCat, __vbaDateVar, -, -, _CIlog, __vbaFileOpen, __vbaInStr, -, __vbaNew2, __vbaVarLateMemCallLdRf, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, -, __vbaFreeStrList, -, _adj_fdivr_m32, __vbaPowerR8, _adj_fdiv_r, -, -, __vbaVarSetVar, __vbaI4Var, __vbaVarCmpEq, __vbaVarAdd, __vbaLateMemCall, __vbaVarDup, -, __vbaStrToAnsi, -, __vbaFpI4, __vbaVarLateMemCallLd, -, __vbaVarSetObjAddref, _CIatan, __vbaStrMove, __vbaForEachVar, -, -, _allmul, __vbaVarLateMemCallSt, _CItan, -, __vbaFPInt, __vbaAryUnlock, _CIexp, __vbaMidStmtBstr, -, __vbaFreeObj, __vbaFreeStr

( 0 exports )
TrID  : File type identification
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
ssdeep: 1536:DU7YIlGhUzb4ch4H3sI8quRRUUmESFCsJ6uyUT9JB20jN6AltN/8aN2sdQR:DUMIkCqrunSTVbNEaNHQR
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=99712D0300F3C72960DF01718A1B210066018434
PEiD  : -
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file