Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File viewtubesoftware.40020.exe received on 2009.02.09 15:16:36 (UTC)
Current status: finished
Result: 8/39 (20.51%)
Antivirus Version Last Update Result
a-squared 4.0.0.93 2009.02.09 -
AhnLab-V3 5.0.0.2 2009.02.09 -
AntiVir 7.9.0.76 2009.02.09 HEUR/Malware
Authentium 5.1.0.4 2009.02.08 -
Avast 4.8.1335.0 2009.02.09 -
AVG 8.0.0.229 2009.02.09 -
BitDefender 7.2 2009.02.09 -
CAT-QuickHeal 10.00 2009.02.09 -
ClamAV 0.94.1 2009.02.09 -
Comodo 972 2009.02.09 -
DrWeb 4.44.0.09170 2009.02.09 -
eSafe 7.0.17.0 2009.02.09 Suspicious File
eTrust-Vet 31.6.6346 2009.02.07 -
F-Prot 4.4.4.56 2009.02.08 -
F-Secure 8.0.14470.0 2009.02.09 -
Fortinet 3.117.0.0 2009.02.09 -
GData 19 2009.02.09 -
Ikarus T3.1.1.45.0 2009.02.09 -
K7AntiVirus 7.10.623 2009.02.07 -
Kaspersky 7.0.0.125 2009.02.09 Trojan-Dropper.Win32.Agent.agtl
McAfee 5520 2009.02.08 -
McAfee+Artemis 5520 2009.02.08 Generic!Artemis
Microsoft 1.4306 2009.02.09 TrojanDownloader:Win32/Renos.BAH
NOD32 3838 2009.02.09 -
Norman 6.00.02 2009.02.09 -
nProtect 2009.1.8.0 2009.02.09 -
Panda 9.5.1.2 2009.02.09 Suspicious file
PCTools 4.4.2.0 2009.02.09 -
Prevx1 V2 2009.02.09 Cloaked Malware
Rising 21.15.50.00 2009.02.07 -
SecureWeb-Gateway 6.7.6 2009.02.09 Heuristic.Malware
Sophos 4.38.0 2009.02.09 -
Sunbelt 3.2.1847.2 2009.02.07 -
Symantec 10 2009.02.09 -
TheHacker 6.3.1.5.250 2009.02.09 -
TrendMicro 8.700.0.1004 2009.02.09 -
VBA32 3.12.8.12 2009.02.08 -
ViRobot 2009.2.9.1596 2009.02.09 -
VirusBuster 4.5.11.0 2009.02.09 -
Additional information
File size: 71680 bytes
MD5...: ef26250b946a63112659c94eed016e0d
SHA1..: 902fd30cd4a7465c9f5271971604d273ed74a60c
SHA256: 92590ab36dd2cd93ac8b89ae6143a45f98f6b1e1fc3218a2e79e0e2c8e78ca2f
SHA512: c7b310b0698a8d189be5ae26d30187d8bb7cd547213e209d8a76cf3c1bd98f14
28f870b83cf24c400fc073028ca983901c70961df67ae1b90c0cc6ceaa6436e5
ssdeep: 1536:aF3XLfN+EAlNG0nzdXhHlhndMXEM3uYM3CB9KwB0QR4cLO:G3bfwG05xFhd
VM3nM3o1B1jO
PEiD..: Armadillo v1.71
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x36e4
timedatestamp.....: 0x498fe813 (Mon Feb 09 08:23:47 2009)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x28ad 0x2a00 6.39 1fd29c0b2b45955a81402691256eca13
.rdata 0x4000 0xcfe 0xe00 5.01 1188bb50483fad8401e9d24b0ad096b9
.data 0x5000 0x8400 0x7800 7.94 c0c5b6c87a8beaf0d24bdb38db37d82c
.rsrc 0xe000 0x6328 0x6400 5.46 031d062e937c13ba94709de205e76fcc

( 10 imports )
> KERNEL32.dll: MultiByteToWideChar, lstrlenA, GetModuleFileNameA, lstrcpyA, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, lstrcatA, GetTempPathA, ExitProcess, TerminateProcess, SetProcessPriorityBoost, SetThreadPriority, GetCurrentThread, SetPriorityClass, GetCurrentProcess, GetShortPathNameA, CopyFileA, GetVersionExA, CreateProcessA, WaitForSingleObject, CreateMutexA, GetStartupInfoA, GetModuleHandleA, IsBadWritePtr, WriteFile, Sleep, GetVolumeInformationA, CloseHandle, CreateFileA, DeviceIoControl, GetEnvironmentVariableA
> USER32.dll: wsprintfA, LoadIconA, SetWindowPos, MessageBoxA, SetTimer, DispatchMessageA, TranslateMessage, IsWindow, IsDialogMessageA, GetMessageA, ShowWindow, CreateDialogParamA
> ADVAPI32.dll: RegSetValueExA, RegQueryValueExA, RegOpenKeyExA, RegCloseKey
> SHELL32.dll: ShellExecuteExA, SHGetSpecialFolderPathA, Shell_NotifyIconA, ShellExecuteA, SHChangeNotify
> ole32.dll: CoCreateInstance, CoInitialize
> OLEAUT32.dll: -
> MSVCP60.dll: __Grow@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAE_NI_N@Z, __Eos@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEXI@Z, _append@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, __C@_1___Nullstr@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@CAPBDXZ@4DB, _npos@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@2IB, _append@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@ABV12@II@Z, __1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ, __Tidy@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEX_N@Z
> SHLWAPI.dll: PathGetDriveNumberA
> MSVCRT.dll: __getmainargs, _acmdln, exit, _XcptFilter, _exit, _onexit, _initterm, free, _except_handler3, strstr, atoi, strncat, __CxxFrameHandler, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _controlfp, __dllonexit, strncpy, sprintf, _strdup
> WININET.dll: InternetCloseHandle, InternetReadFile, HttpQueryInfoA, InternetOpenUrlA, InternetOpenA

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=5A40570E0090072E18CF01DCDE77960082E14123

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file