Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File winpsvc.exe received on 2009.10.02 08:58:58 (UTC)
Current status: finished
Result: 31/41 (75.61%)
Antivirus Version Last Update Result
a-squared 4.5.0.24 2009.10.02 Trojan.Win32.Refroso!IK
AhnLab-V3 5.0.0.2 2009.10.01 -
AntiVir 7.9.1.27 2009.10.01 TR/Refroso.kqt
Antiy-AVL 2.0.3.7 2009.10.02 Trojan/Win32.Refroso.gen
Authentium 5.1.2.4 2009.10.02 W32/Trojan2.ITRZ
Avast 4.8.1351.0 2009.10.02 -
AVG 8.5.0.412 2009.10.01 BackDoor.Generic11.AUQK
BitDefender 7.2 2009.10.02 Trojan.Generic.2483050
CAT-QuickHeal 10.00 2009.10.01 TrojanDropper.Agent.bequ
ClamAV 0.94.1 2009.10.02 -
Comodo 2489 2009.10.02 -
DrWeb 5.0.0.12182 2009.10.02 BackDoor.IRC.Letmein.13
eSafe 7.0.17.0 2009.10.01 Win32.Horse
eTrust-Vet 31.6.6773 2009.10.02 -
F-Prot 4.5.1.85 2009.10.01 W32/Trojan2.ITRZ
F-Secure 8.0.14470.0 2009.10.02 Trojan.Win32.Refroso.kqt
Fortinet 3.120.0.0 2009.10.02 W32/Refroso.KQT!tr
GData 19 2009.10.02 Trojan.Generic.2483050
Ikarus T3.1.1.72.0 2009.10.02 Trojan.Win32.Refroso
Jiangmin 11.0.800 2009.09.27 Trojan/Refroso.yz
K7AntiVirus 7.10.858 2009.10.01 Trojan.Win32.Malware.1
Kaspersky 7.0.0.125 2009.10.02 Trojan.Win32.Refroso.kqt
McAfee 5758 2009.10.01 BackDoor-EEC.gen
McAfee+Artemis 5758 2009.10.01 BackDoor-EEC.gen
McAfee-GW-Edition 6.8.5 2009.10.02 Trojan.Refroso.kqt
Microsoft 1.5101 2009.10.02 -
NOD32 4475 2009.10.02 Win32/Agent.QDP
Norman 6.01.09 2009.10.01 W32/Smalldoor.IGSY
nProtect 2009.1.8.0 2009.10.02 -
Panda 10.0.2.2 2009.10.01 Bck/Hupigon.LMJ
PCTools 4.4.2.0 2009.10.01 -
Prevx 3.0 2009.10.02 High Risk Cloaked Malware
Rising 21.49.22.00 2009.09.30 -
Sophos 4.45.0 2009.10.02 Mal/EncPk-JU
Sunbelt 3.2.1858.2 2009.10.01 Trojan.Win32.Generic!BT
Symantec 1.4.4.12 2009.10.02 Trojan Horse
TheHacker 6.5.0.2.026 2009.10.02 -
TrendMicro 8.950.0.1094 2009.10.02 TROJ_REFROSO.AR
VBA32 3.12.10.11 2009.09.30 P2P-Worm.Win32.Palevo.jth
ViRobot 2009.10.2.1968 2009.10.02 Trojan.Win32.Refroso.49152.B
VirusBuster 4.6.5.0 2009.10.01 Trojan.Refroso.AHB
Additional information
File size: 49152 bytes
MD5   : f8130f163e8224c0904aff7fa76efea8
SHA1  : 59f8cb02db1b3d7861799eb6ad3340c30191fd9a
SHA256: 386a5f2ea3e38a889a55d7ab543803c4e444eb638df84236971ed2b3e2a1ac0d
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x6D36
timedatestamp.....: 0x4AB7EDFC (Mon Sep 21 23:19:56 2009)
machinetype.......: 0x14C (Intel I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x5EC0 0x6000 5.56 5727f939a239e4aaef57de7a66035b8c
.rdata 0x7000 0x5C2 0x600 4.72 7e62c3c9a94002075191a758de9d104f
.data 0x8000 0x8BC 0x800 5.78 5a1b6d8b740577d794ee20a405b59c61
.rsrc 0x9000 0x4CD8 0x4E00 7.82 1e42f548a431a552cb64776cec24d20b

( 5 imports )

> gdi32.dll: GetStockObject, SetBkMode
> kernel32.dll: GetProcAddress, CreateThread, GetTickCount, GetStartupInfoA, Sleep, LoadLibraryA, GetModuleHandleA, GetWindowsDirectoryA
> msvcrt.dll: __set_app_type, __p__fmode, __p__commode, _controlfp, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _XcptFilter, _exit, _except_handler3, strlen, memmove, memset, malloc, _stricmp, _adjust_fdiv, memcpy, strcpy, __2@YAPAXI@Z, sprintf
> ole32.dll: CoInitialize
> user32.dll: DispatchMessageA, MessageBoxA, LoadIconA, LoadCursorA, RegisterClassExA, CreateWindowExA, ShowWindow, UpdateWindow, GetMessageA, TranslateMessage, EndPaint, DefWindowProcA, DestroyWindow, SetWindowPos, PostQuitMessage, SetWindowPlacement, GetMenuState, EnableMenuItem, FillRect

( 0 exports )
TrID  : File type identification
Win32 Executable Generic (38.1%)
Win32 Dynamic Link Library (generic) (33.9%)
Win32 Executable MS Visual FoxPro 7 (10.0%)
Generic Win/DOS Executable (8.9%)
DOS Executable Generic (8.9%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=f8130f163e8224c0904aff7fa76efea8
ssdeep: 768:CP2UDsMsXgo+dRbVkQ/9Wkkb9HZC8e2ZQFubyD+nwW1YTUS:O2UIDXCVkolkblfe2iubyDkwYYTUS
sigcheck: publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=533E1DE3000905F4C07900BA1A1C0900D445431F
PEiD  : -
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file