Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File DropUpLoad.exe received on 07.19.2008 05:46:17 (CET)
Current status: finished
Result: 3/33 (9.09%)
Antivirus Version Last Update Result
AhnLab-V3 2008.7.17.0 2008.07.18 -
AntiVir 7.8.1.11 2008.07.18 -
Authentium 5.1.0.4 2008.07.19 -
Avast 4.8.1195.0 2008.07.18 Win32:KdCrypt
AVG 8.0.0.130 2008.07.18 -
BitDefender 7.2 2008.07.19 -
CAT-QuickHeal 9.50 2008.07.18 -
ClamAV 0.93.1 2008.07.19 -
DrWeb 4.44.0.09170 2008.07.18 -
eSafe 7.0.17.0 2008.07.17 Suspicious File
eTrust-Vet 31.6.5966 2008.07.18 -
Ewido 4.0 2008.07.18 -
F-Prot 4.4.4.56 2008.07.18 -
F-Secure 7.60.13501.0 2008.07.19 -
Fortinet 3.14.0.0 2008.07.19 -
GData 2.0.7306.1023 2008.07.19 -
Ikarus T3.1.1.34.0 2008.07.19 -
Kaspersky 7.0.0.125 2008.07.19 -
McAfee 5342 2008.07.18 -
Microsoft 1.3704 2008.07.19 -
NOD32v2 3281 2008.07.18 -
Norman 5.80.02 2008.07.18 -
Panda 9.0.0.4 2008.07.18 -
Prevx1 V2 2008.07.19 -
Rising 20.53.42.00 2008.07.18 -
Sophos 4.31.0 2008.07.19 -
Sunbelt 3.1.1536.1 2008.07.18 -
Symantec 10 2008.07.19 -
TheHacker 6.2.96.384 2008.07.19 -
TrendMicro 8.700.0.1004 2008.07.18 -
VBA32 3.12.8.1 2008.07.18 -
VirusBuster 4.5.11.0 2008.07.18 -
Webwasher-Gateway 6.6.2 2008.07.19 Virus.Win32.FileInfector.gen!94 (suspicious)
Additional information
File size: 290304 bytes
MD5...: 76662363e769bd457f05916da79f351b
SHA1..: 77afbac6ecead4e22124c5273959bf58987e7bf3
SHA256: 44859a4bd434c135f36b9d330f15349260c600e6cbf230a6693d22899d7c7342
SHA512: 48fe27a50946de5731d4fe53f0546321a48ec7d6d2a1f44401128d103cfa94ed
70a2b3936aaee828db174272103d27a1acf73144300694b969f761ceade7090f
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x401000
timedatestamp.....: 0x485e081c (Sun Jun 22 08:06:52 2008)
machinetype.......: 0x14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.code 0x1000 0x1143e 0x11600 5.85 1c8ae1546bba4390d673001053e0c7cb
.text 0x13000 0xe480 0xe600 6.24 18ecae6d16d84ff6d7d6b09516ee41b7
.rdata 0x22000 0x1a 0x200 0.19 f966f0dd593c4543094099234e118bf1
.data 0x23000 0x2b41c 0x25800 5.51 74edd6242ad371cd18efb7f06d5a0247
.rsrc 0x4f000 0x102c 0x1200 3.56 eb76098d8d1f040d7d6450bfa60ef153
.flat 0x51000 0x194 0x200 4.90 17d36606b3b6865b7bfee63368d7ed6a

( 11 imports )
> CRTDLL.dll: memset, memcpy, realloc, free, wcscpy, towupper, towlower, wcslen, _wcsnicmp, wcsncmp, wcsncpy, _wcsdup, swprintf, swscanf, wcscat, strlen, strcpy, strcat, memcmp, atoi, sprintf, _stricmp, fopen, fseek, fclose, memmove, wcscmp, localtime, mktime, _itow, gmtime
> KERNEL32.dll: GetModuleHandleW, HeapCreate, HeapDestroy, ExitProcess, GetLastError, FormatMessageW, GetCurrentDirectoryW, GetModuleFileNameW, GlobalAlloc, GlobalLock, GlobalUnlock, CreateFileW, GetFileSize, ReadFile, CloseHandle, HeapFree, HeapAlloc, VirtualAlloc, VirtualFree, VirtualProtect, LoadLibraryA, GetProcAddress, IsBadReadPtr, FreeLibrary, GetProcessHeap, EnterCriticalSection, WaitForSingleObject, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, CreateThread, TerminateThread, LoadLibraryW, GetCurrentThreadId, GetCurrentProcessId, GetCommandLineW, GetCurrentProcess, DuplicateHandle, CreatePipe, GetStdHandle, CreateProcessW, SetFilePointer, SetEndOfFile, WriteFile, MultiByteToWideChar, WideCharToMultiByte, Sleep, GetTickCount, HeapReAlloc, GlobalFree, MulDiv, GetDriveTypeW, FindFirstFileW, FindClose, CreateDirectoryW, SystemTimeToFileTime, LocalFileTimeToFileTime, SetFileTime, FileTimeToSystemTime, DeleteFileW, MoveFileW, FindNextFileW, SetFileAttributesW, RemoveDirectoryW, CopyFileW, GetLocalTime, WaitForMultipleObjects, ResetEvent, SetEvent, TlsGetValue, TlsSetValue, GetCurrentThread, TlsAlloc, CreateEventA
> GDI32.dll: GetDeviceCaps, GetObjectType, DeleteObject, CreateCompatibleDC, SetDIBits, DeleteDC, GetObjectW, SelectObject, GetStockObject, SetStretchBltMode, SetBrushOrgEx, StretchBlt, CreateDCW, CreateCompatibleBitmap, CreateDIBSection, SetTextColor, SetBkColor, CreatePen, MoveToEx, LineTo, CreateSolidBrush, CreateFontW, SetTextAlign, SetPixelV, Rectangle, SetROP2, SetBkMode
> OLEAUT32.dll: OleLoadPicture
> ole32.dll: CreateStreamOnHGlobal, CoTaskMemFree, RevokeDragDrop
> WSOCK32.dll: closesocket, WSACleanup, WSAStartup, send, htons, sendto, ioctlsocket, recvfrom, accept, ntohs, recv, socket, inet_addr, gethostbyname, connect, gethostname, bind, listen, WSAGetLastError
> WININET.dll: InternetGetLastResponseInfoW, InternetOpenW, InternetOpenUrlW, InternetReadFile, InternetCloseHandle, InternetConnectW, HttpOpenRequestW, HttpAddRequestHeadersW, HttpSendRequestW, InternetQueryOptionW
> comdlg32.dll: GetSaveFileNameW, GetOpenFileNameW
> COMCTL32.dll: InitCommonControls, InitCommonControlsEx, ImageList_Create, ImageList_AddMasked, ImageList_Destroy, ImageList_Add, ImageList_ReplaceIcon, ImageList_Remove
> USER32.dll: GetSystemMetrics, SetClassLongW, SendMessageW, EnableWindow, SetWindowLongW, SetFocus, UnhookWindowsHookEx, GetDesktopWindow, GetDC, ReleaseDC, CreateWindowExW, GetAsyncKeyState, DestroyWindow, GetWindowRect, GetCursorPos, PtInRect, MessageBoxW, GetWindowThreadProcessId, IsWindowVisible, IsWindowEnabled, GetForegroundWindow, EnumWindows, SetMenu, DestroyMenu, CreatePopupMenu, AppendMenuW, SetForegroundWindow, TrackPopupMenu, DestroyIcon, CreateIconFromResourceEx, CreateIconFromResource, GetIconInfo, FillRect, GetSysColor, GetSysColorBrush, SetWindowTextW, GetWindowLongW, SetCapture, CallWindowProcW, ReleaseCapture, ScreenToClient, RedrawWindow, SetWindowPos, InvalidateRect, UpdateWindow, BeginPaint, DrawStateW, EndPaint, ValidateRect, SendMessageA, GetWindowTextLengthW, GetWindowTextW, PostMessageW, GetWindow, GetPropW, SetPropW, RemovePropW, GetParent, GetClientRect, MapWindowPoints, SetActiveWindow, UnregisterClassW, DestroyAcceleratorTable, LoadIconW, LoadCursorW, RegisterClassW, AdjustWindowRect, GetActiveWindow, ShowWindow, CreateAcceleratorTableW, PeekMessageW, MsgWaitForMultipleObjects, GetMessageW, TranslateAcceleratorW, TranslateMessage, DispatchMessageW, SetCursorPos, LoadImageW, SetCursor, SystemParametersInfoW, GetKeyState, MoveWindow, EnumChildWindows, DefWindowProcW, GetFocus, IsChild, GetClassNameW
> SHELL32.DLL: DragAcceptFiles, ShellExecuteW, DragQueryFileW, DragFinish, ShellExecuteExW

( 0 exports )

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file