Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File setup.exe received on 2009.09.23 18:41:56 (UTC)
Current status: finished
Result: 14/41 (34.15%)
Antivirus Version Last Update Result
a-squared 4.5.0.24 2009.09.23 -
AhnLab-V3 5.0.0.2 2009.09.23 -
AntiVir 7.9.1.23 2009.09.23 -
Antiy-AVL 2.0.3.7 2009.09.23 Packed/Win32.Klone.gen
Authentium 5.1.2.4 2009.09.23 -
Avast 4.8.1351.0 2009.09.23 -
AVG 8.5.0.412 2009.09.23 -
BitDefender 7.2 2009.09.23 Trojan.Generic.2445951
CAT-QuickHeal 10.00 2009.09.23 -
ClamAV 0.94.1 2009.09.23 -
Comodo 2416 2009.09.23 -
DrWeb 5.0.0.12182 2009.09.23 Trojan.Fakealert.4386
eSafe 7.0.17.0 2009.09.23 -
eTrust-Vet 31.6.6756 2009.09.23 -
F-Prot 4.5.1.85 2009.09.23 -
F-Secure 8.0.14470.0 2009.09.23 -
Fortinet 3.120.0.0 2009.09.23 W32/FakeAV
GData 19 2009.09.23 Trojan.Generic.2445951
Ikarus T3.1.1.72.0 2009.09.23 Fraudtool.Win32.FakeAV
Jiangmin 11.0.800 2009.09.23 -
K7AntiVirus 7.10.852 2009.09.23 Trojan.Win32.Malware.3
Kaspersky 7.0.0.125 2009.09.23 -
McAfee 5750 2009.09.23 FakeAlert-AntiVirusPro
McAfee+Artemis 5750 2009.09.23 FakeAlert-AntiVirusPro
McAfee-GW-Edition 6.8.5 2009.09.23 -
Microsoft 1.5005 2009.09.23 -
NOD32 4451 2009.09.23 Win32/NoAdware
Norman 6.01.09 2009.09.23 FakeAlert.ALXZ
nProtect 2009.1.8.0 2009.09.23 -
Panda 10.0.2.2 2009.09.23 Suspicious file
PCTools 4.4.2.0 2009.09.23 -
Prevx 3.0 2009.09.23 -
Rising 21.48.24.00 2009.09.23 -
Sophos 4.45.0 2009.09.23 Troj/FakeVir-OL
Sunbelt 3.2.1858.2 2009.09.23 -
Symantec 1.4.4.12 2009.09.23 -
TheHacker 6.5.0.2.015 2009.09.22 -
TrendMicro 8.950.0.1094 2009.09.23 TROJ_FAKEAV.ZCG
VBA32 3.12.10.10 2009.09.23 -
ViRobot 2009.9.23.1950 2009.09.23 -
VirusBuster 4.6.5.0 2009.09.23 -
Additional information
File size: 2431232 bytes
MD5   : f740de8052f0e8e89624414066ce4ed3
SHA1  : 5b1564abf337e437ebfd04a24a9430cd937fb9a4
SHA256: 1bc37518e080723b39a21d295a1f8042a0679c452287648ebce1b43bb6c03617
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x991C
timedatestamp.....: 0x2A425E19 (Sat Jun 20 00:22:17 1992)
machinetype.......: 0x14C (Intel I386)

( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0x9040 0x9200 6.54 3fc23a57f6f12a4277db04cb09d7c497
DATA 0xB000 0x248 0x400 2.70 ac282c636b8dc9d80279982f8dde9f24
BSS 0xC000 0xE34 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0xD000 0x950 0xA00 4.43 bb5485bf968b970e5ea81292af2acdba
.tls 0xE000 0x8 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 0xF000 0x18 0x200 0.20 9ba824905bf9c7922b6fc87a38b74366
.reloc 0x10000 0x8A4 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0x11000 0x2800 0x2800 4.46 2c72c75f1804072ab22619eec1869b7b

( 5 imports )

> advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges
> comctl32.dll: InitCommonControls
> kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, WideCharToMultiByte, TlsSetValue, TlsGetValue, MultiByteToWideChar, GetModuleHandleA, GetLastError, GetCommandLineA, WriteFile, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetSystemTime, GetFileType, ExitProcess, CreateFileA, CloseHandle, WriteFile, VirtualQuery, VirtualProtect, VirtualFree, VirtualAlloc, Sleep, SizeofResource, SetLastError, SetFilePointer, SetErrorMode, SetEndOfFile, RemoveDirectoryA, ReadFile, LockResource, LoadResource, LoadLibraryA, IsDBCSLeadByte, GetWindowsDirectoryA, GetVersionExA, GetUserDefaultLangID, GetSystemInfo, GetSystemDefaultLCID, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetFullPathNameA, GetFileSize, GetFileAttributesA, GetExitCodeProcess, GetEnvironmentVariableA, GetCurrentProcess, GetCommandLineA, GetACP, InterlockedExchange, FormatMessageA, FindResourceA, DeleteFileA, CreateProcessA, CreateFileA, CreateDirectoryA, CloseHandle
> oleaut32.dll: VariantChangeTypeEx, VariantCopyInd, VariantClear, SysStringLen, SysAllocStringLen
> user32.dll: MessageBoxA, TranslateMessage, SetWindowLongA, PeekMessageA, MsgWaitForMultipleObjects, MessageBoxA, LoadStringA, ExitWindowsEx, DispatchMessageA, DestroyWindow, CreateWindowExA, CallWindowProcA, CharPrevA

( 0 exports )
TrID  : File type identification
Win32 Executable Generic (38.4%)
Win32 Dynamic Link Library (generic) (34.1%)
Win16/32 Executable Delphi generic (9.3%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=f740de8052f0e8e89624414066ce4ed3
ssdeep: 49152:f2OSpPZSErKaboioflh0ZOiwWgk8LSc4AOnMn3FasANksA9wSW2Flax94:+OSDprUiwQ8sJMsNkIAlaI
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=14A6205A004CA6051965254453270B00977A796B
PEiD  : -
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file