Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File install.exe1443.safe received on 08.17.2008 18:47:24 (CET)
Current status: finished
Result: 15/36 (41.67%)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.15.0 2008.08.15 -
AntiVir 7.8.1.19 2008.08.16 -
Authentium 5.1.0.4 2008.08.17 -
Avast 4.8.1195.0 2008.08.17 -
AVG 8.0.0.161 2008.08.17 I-Worm/Nuwar.W
BitDefender 7.2 2008.08.17 Trojan.Downloader.Exchanger.Gen.2
CAT-QuickHeal 9.50 2008.08.16 (Suspicious) - DNAScan
ClamAV 0.93.1 2008.08.16 -
DrWeb 4.44.0.09170 2008.08.17 Trojan.Packed.606
eSafe 7.0.17.0 2008.08.17 Suspicious File
eTrust-Vet 31.6.6035 2008.08.15 -
Ewido 4.0 2008.08.17 -
F-Prot 4.4.4.56 2008.08.17 -
F-Secure 7.60.13501.0 2008.08.17 -
Fortinet 3.14.0.0 2008.08.17 W32/PolyExchanger.A!tr
GData 2.0.7306.1023 2008.08.17 -
Ikarus T3.1.1.34.0 2008.08.17 Trojan-Downloader.Exchanger.Gen.2
K7AntiVirus 7.10.417 2008.08.15 -
Kaspersky 7.0.0.125 2008.08.17 -
McAfee 5362 2008.08.15 -
Microsoft 1.3807 2008.08.17 TrojanDropper:Win32/Nuwar.gen!ldt
NOD32v2 3362 2008.08.17 a variant of Win32/Agent.ETH
Norman 5.80.02 2008.08.15 Tibs.gen220
Panda 9.0.0.4 2008.08.17 -
PCTools 4.4.2.0 2008.08.17 -
Prevx1 V2 2008.08.17 -
Rising 20.57.62.00 2008.08.17 -
Sophos 4.32.0 2008.08.17 Mal/EncPk-DA
Sunbelt 3.1.1546.1 2008.08.15 -
Symantec 10 2008.08.17 Trojan.Pandex
TheHacker 6.3.0.3.052 2008.08.17 -
TrendMicro 8.700.0.1004 2008.08.16 -
VBA32 3.12.8.3 2008.08.17 suspected of MalwareScope.Worm.Nuwar-Glowa.1 (paranoid heuristics)
ViRobot 2008.8.16.1338 2008.08.16 -
VirusBuster 4.5.11.0 2008.08.17 Trojan.DL.Exchanger.CV
Webwasher-Gateway 6.6.2 2008.08.17 Worm.Win32.Malware.gen (suspicious)
Additional information
File size: 74752 bytes
MD5...: 84dc5bd45775504f395569fe51b5f6f6
SHA1..: 2cc17a61d0396a4458dae341bf9a2be0d8e83a22
SHA256: dafb3974dac98a11e737359ff9443177e130abea338b202698373365bcd136a2
SHA512: 5d0cd43c662e93f7b7c9101c3367d2d03554b31de52931aba86203cba6927c0a
019ddc0ce6a5b6d546af17674cbd8d20313aee6ceff937c58eab524b5a11e215
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x40761e
timedatestamp.....: 0x487d1ddb (Tue Jul 15 21:59:55 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xdfef 0xc200 8.00 93cc22cc980f883dd5b546b3e333d0f9
.rdata 0xf000 0x3e60 0x2200 7.98 49e9be49a572689d62393952933429e0
.data 0x13000 0x5000 0x3000 4.18 87200d0bdc9a7a898bf992f2dd2b24bc

( 4 imports )
> MSVCRT.DLL: memcmp, iswcntrl, strcmp
> USER32.DLL: GetScrollPos, LoadKeyboardLayoutW, GetForegroundWindow, GetMenuStringW, SetDoubleClickTime, SendInput
> WININET.DLL: ShowCertificate, InternetDialW, InternetGetCookieW, InternetSetCookieW, UrlZonesDetach
> ADVAPI32.DLL: LsaOpenSecret, RegUnLoadKeyW, UnlockServiceDatabase, RevertToSelf, LsaClose

( 0 exports )

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file