Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File card.exe received on 2009.07.18 02:16:52 (UTC)
Current status: finished
Result: 31/41 (75.61%)
Antivirus Version Last Update Result
a-squared 4.5.0.24 2009.07.17 Backdoor.Win32.IRCFlood!IK
AhnLab-V3 5.0.0.2 2009.07.17 mIRC/Zapchast
AntiVir 7.9.0.220 2009.07.17 BDS/Agent.1260.A
Antiy-AVL 2.0.3.7 2009.07.17 Backdoor/IRC.Zapchast
Authentium 5.1.2.4 2009.07.18 REG/Zapchast.H
Avast 4.8.1335.0 2009.07.17 VBS:Malware-gen
AVG 8.5.0.387 2009.07.17 Zapchast
BitDefender 7.2 2009.07.18 Backdoor.Zapchast.PF
CAT-QuickHeal 10.00 2009.07.17 -
ClamAV 0.94.1 2009.07.18 Trojan.IRC.Zapchast-16
Comodo 1686 2009.07.18 UnclassifiedMalware
DrWeb 5.0.0.12182 2009.07.18 -
eSafe 7.0.17.0 2009.07.16 Win32.mIRC-based
eTrust-Vet 31.6.6623 2009.07.18 -
F-Prot 4.4.4.56 2009.07.17 REG/Zapchast.H
F-Secure 8.0.14470.0 2009.07.17 Backdoor.IRC.Zapchast.zwrc
Fortinet 3.120.0.0 2009.07.17 W32/Zapchast.ZWRC!tr
GData 19 2009.07.18 Backdoor.Zapchast.PF
Ikarus T3.1.1.64.0 2009.07.17 Backdoor.Win32.IRCFlood
Jiangmin 11.0.800 2009.07.17 -
K7AntiVirus 7.10.794 2009.07.16 Non-Virus:Client-IRC.Win32.mIRC.603
Kaspersky 7.0.0.125 2009.07.18 Backdoor.IRC.Zapchast.zwrc
McAfee 5679 2009.07.17 potentially unwanted program IRC/Client
McAfee+Artemis 5679 2009.07.17 potentially unwanted program IRC/Client
McAfee-GW-Edition 6.8.5 2009.07.18 Heuristic.BehavesLike.Exploit.CodeExec.PGPG
Microsoft 1.4803 2009.07.17 Backdoor:Win32/IRCFlood
NOD32 4255 2009.07.17 REG/RunKeys.NAA
Norman 6.01.09 2009.07.17 -
nProtect 2009.1.8.0 2009.07.17 -
Panda 10.0.0.14 2009.07.17 BAT/Autorun.TA
PCTools 4.4.2.0 2009.07.17 Backdoor.IRC.Zapchast.zwrc
Prevx 3.0 2009.07.18 Medium Risk Malware Dropper
Rising 21.38.44.00 2009.07.17 -
Sophos 4.43.0 2009.07.17 Mal/Zapchas-C
Sunbelt 3.2.1858.2 2009.07.17 -
Symantec 1.4.4.12 2009.07.18 Trojan.Dropper
TheHacker 6.3.4.3.370 2009.07.17 -
TrendMicro 8.950.0.1094 2009.07.17 REG_ZAPCHAST.ED
VBA32 3.12.10.8 2009.07.17 BackDoor.IRC.based
ViRobot 2009.7.17.1841 2009.07.17 -
VirusBuster 4.6.5.0 2009.07.16 Trojan.mIRC-Based.AM
Additional information
File size: 929925 bytes
MD5   : e54558c0e1e0f1c9fcb3bcfd44e4feba
SHA1  : 121493d024664e6c66d88d58df735db984f90465
SHA256: 35e2f10864cf67b38f0340ec10310a11395b542adb95f2757eea61a3125fb283
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1000
timedatestamp.....: 0x48761587 (Thu Jul 10 15:58:31 2008)
machinetype.......: 0x14C (Intel I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x14000 0x13A00 6.48 ebf4c137a2eb0481c4b170c9176f76c4
.data 0x15000 0x7000 0xA00 4.95 6887356a20174670f968f47b207fbe2a
.idata 0x1C000 0x1000 0x1000 5.13 d2f29f80afffc1db4815959825f67883
.rsrc 0x1D000 0x1AEE4 0x1B000 3.64 f835686288b1a2b3524d6fd094d4447e

( 8 imports )

> advapi32.dll: AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA, SetFileSecurityA, SetFileSecurityW
> comctl32.dll: -
> comdlg32.dll: CommDlgExtendedError, GetOpenFileNameA, GetSaveFileNameA
> gdi32.dll: DeleteObject
> kernel32.dll: CloseHandle, CompareStringA, CreateDirectoryA, CreateDirectoryW, CreateFileA, CreateFileW, DeleteFileA, DeleteFileW, DosDateTimeToFileTime, ExitProcess, ExpandEnvironmentStringsA, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, FindFirstFileA, FindFirstFileW, FindNextFileA, FindNextFileW, FindResourceA, FreeLibrary, GetCPInfo, GetCommandLineA, GetCurrentDirectoryA, GetCurrentProcess, GetDateFormatA, GetFileAttributesA, GetFileAttributesW, GetFileType, GetFullPathNameA, GetLastError, GetLocaleInfoA, GetModuleFileNameA, GetModuleHandleA, GetNumberFormatA, GetProcAddress, GetProcessHeap, GetStdHandle, GetSystemTime, GetTempPathA, GetTickCount, GetTimeFormatA, GetVersionExA, GlobalAlloc, HeapAlloc, HeapFree, HeapReAlloc, IsDBCSLeadByte, LoadLibraryA, LocalFileTimeToFileTime, MoveFileA, MoveFileExA, MultiByteToWideChar, ReadFile, SetCurrentDirectoryA, SetEndOfFile, SetEnvironmentVariableA, SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFileTime, SetLastError, Sleep, SystemTimeToFileTime, WaitForSingleObject, WideCharToMultiByte, WriteFile, lstrcmpiA, lstrlenA
> ole32.dll: CLSIDFromString, CoCreateInstance, CreateStreamOnHGlobal, OleInitialize, OleUninitialize
> shell32.dll: SHBrowseForFolderA, SHChangeNotify, SHFileOperationA, SHGetFileInfoA, SHGetMalloc, SHGetSpecialFolderLocation, ShellExecuteExA, SHGetPathFromIDListA
> user32.dll: CharToOemA, CharToOemBuffA, CharUpperA, CopyRect, CreateWindowExA, DefWindowProcA, DestroyIcon, DestroyWindow, DialogBoxParamA, DispatchMessageA, EnableWindow, EndDialog, FindWindowExA, GetClassNameA, GetClientRect, GetDlgItem, GetDlgItemTextA, GetMessageA, GetParent, GetSysColor, GetSystemMetrics, GetWindow, GetWindowLongA, GetWindowRect, GetWindowTextA, IsWindow, IsWindowVisible, LoadBitmapA, LoadCursorA, LoadIconA, LoadStringA, MapWindowPoints, MessageBoxA, OemToCharA, OemToCharBuffA, PeekMessageA, PostMessageA, RegisterClassExA, SendDlgItemMessageA, SendMessageA, SetDlgItemTextA, SetFocus, SetMenu, SetWindowLongA, SetWindowPos, SetWindowTextA, ShowWindow, TranslateMessage, UpdateWindow, WaitForInputIdle, wsprintfA, wvsprintfA

( 0 exports )
TrID  : File type identification
WinRAR Self Extracting archive (96.2%)
Win32 Executable Generic (1.5%)
Win32 Dynamic Link Library (generic) (1.4%)
Generic Win/DOS Executable (0.3%)
DOS Executable Generic (0.3%)
ssdeep: 24576:TwTkmZ4Nj9KRpRoUWmmKKR+Pz3VZcwZ60PX0wS7fLICnJwDr:TwT5SNj4fWm/KUPDVZnZfPtELbK
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=31DCBE3285FDCEC530670E00EDA919003848D319
PEiD  : -
packers (F-Prot): RAR, Unicode
packers (Authentium): RAR, Unicode, RAR, RAR, RAR
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file