Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File keymaker.exe received on 2008.04.28 02:22:43 (UTC)
Current status: finished
Result: 1/32 (3.12%)
Antivirus Version Last Update Result
AhnLab-V3 2008.4.25.2 2008.04.25 -
AntiVir 7.8.0.10 2008.04.27 -
Authentium 4.93.8 2008.04.27 -
Avast 4.8.1169.0 2008.04.28 -
AVG 7.5.0.516 2008.04.27 -
BitDefender 7.2 2008.04.28 -
CAT-QuickHeal 9.50 2008.04.26 -
ClamAV 0.92.1 2008.04.27 -
DrWeb 4.44.0.09170 2008.04.27 -
eSafe 7.0.15.0 2008.04.27 -
eTrust-Vet 31.3.5736 2008.04.26 -
Ewido 4.0 2008.04.27 -
F-Prot 4.4.2.54 2008.04.27 -
F-Secure 6.70.13260.0 2008.04.28 -
FileAdvisor 1 2008.04.28 -
Fortinet 3.14.0.0 2008.04.27 -
Ikarus T3.1.1.26 2008.04.28 -
Kaspersky 7.0.0.125 2008.04.28 -
McAfee 5282 2008.04.25 -
Microsoft 1.3408 2008.04.22 -
NOD32v2 3058 2008.04.27 -
Norman 5.80.02 2008.04.25 -
Panda 9.0.0.4 2008.04.27 -
Prevx1 V2 2008.04.28 Heuristic: Suspicious Self Modifying File
Rising 20.41.62.00 2008.04.27 -
Sophos 4.28.0 2008.04.28 -
Sunbelt 3.0.1056.0 2008.04.17 -
Symantec 10 2008.04.28 -
TheHacker 6.2.92.294 2008.04.26 -
VBA32 3.12.6.5 2008.04.26 -
VirusBuster 4.3.26:9 2008.04.27 -
Webwasher-Gateway 6.6.2 2008.04.27 -
Additional information
File size: 155648 bytes
MD5...: 458c9eb3ae5038602b732442e664e07b
SHA1..: 6018f82eafa06f668e6d703831908104216dc201
SHA256: d4d490dc08e8d64f4f6f62c02d7795dafd1312a4f5398142fc62a7cf06455c6d
SHA512: 131ff5936e3aa7aacdfe22d5ee633c8de9df1ffc9d7b5b61dce3e5f888bb4e7e
47ef3c844330e0fa9e0c28b298273dad1af68eb20d455a35cd0ccd44535ded31
PEiD..: Armadillo v1.71
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4093e8
timedatestamp.....: 0x4813862c (Sat Apr 26 19:44:44 2008)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x8580 0x8600 6.34 515978b577890afa628bd044ecc1215d
.rdata 0xa000 0xbfa 0xc00 5.21 21c8668dfbea497648c5084b3e375758
.data 0xb000 0x1ede4 0x600 3.90 6c0298fd93992fd858bb817f8afe9570
.rsrc 0x2a000 0x1c3f0 0x1c400 6.43 4ed4afa33c0393eb610bb2d2f12429f8

( 9 imports )
> KERNEL32.dll: HeapFree, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, DeleteCriticalSection, GetProcessHeap, GetStartupInfoA, GetModuleHandleA, CreateThread, WaitForSingleObject, CloseHandle, LocalFree, Sleep, lstrcpyA, FindResourceA, LoadResource, SizeofResource, GlobalAlloc, LockResource, GlobalLock, GlobalUnlock, LocalAlloc, GlobalFree, lstrlenA, HeapAlloc
> USER32.dll: CloseClipboard, MessageBoxA, CopyImage, EmptyClipboard, OpenClipboard, PostMessageA, SendMessageA, CreateWindowExA, DefWindowProcA, PostQuitMessage, DestroyWindow, SetLayeredWindowAttributes, EndPaint, GetSysColor, FillRect, BeginPaint, GetSysColorBrush, UpdateWindow, InvalidateRect, LoadIconA, LoadCursorA, RegisterClassExA, GetSystemMetrics, AdjustWindowRect, ShowWindow, GetMessageA, IsDialogMessageA, TranslateMessage, DispatchMessageA, GetDC, ReleaseDC, GetDlgItem, SetFocus, SetTimer, SendDlgItemMessageA, GetWindowTextLengthA, GetWindowTextA, SetDlgItemTextA, SetClipboardData
> GDI32.dll: SetTextColor, DeleteDC, BitBlt, CreateCompatibleBitmap, CreateCompatibleDC, TextOutA, RestoreDC, GetTextExtentPoint32A, SelectObject, SaveDC, CreateFontIndirectA, GetObjectA, SetBkMode, DeleteObject
> ole32.dll: CreateStreamOnHGlobal
> OLEAUT32.dll: -
> COMCTL32.dll: -
> WINMM.dll: waveOutPrepareHeader, waveOutClose, waveOutWrite, waveOutUnprepareHeader, waveOutOpen
> WSOCK32.dll: -, -
> MSVCRT.dll: __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _XcptFilter, _exit, strncmp, __2@YAPAXI@Z, strcat, strchr, strcpy, memset, memcpy, free, time, strlen, sprintf, _timezone, malloc, __set_app_type, _except_handler3, _controlfp, _putenv, __p__fmode

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=87D843BB006B4BD16000021B7118A6002FE470CF

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file