Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File lol.exe received on 2009.07.09 14:40:59 (UTC)
Current status: finished
Result: 5/41 (12.20%)
Antivirus Version Last Update Result
a-squared 4.5.0.18 2009.07.09 -
AhnLab-V3 5.0.0.2 2009.07.09 -
AntiVir 7.9.0.204 2009.07.09 -
Antiy-AVL 2.0.3.1 2009.07.09 -
Authentium 5.1.2.4 2009.07.08 -
Avast 4.8.1335.0 2009.07.08 -
AVG 8.5.0.386 2009.07.09 -
BitDefender 7.2 2009.07.09 -
CAT-QuickHeal 10.00 2009.07.09 -
ClamAV 0.94.1 2009.07.09 -
Comodo 1593 2009.07.09 -
DrWeb 5.0.0.12182 2009.07.09 -
eSafe 7.0.17.0 2009.07.09 Suspicious File
eTrust-Vet 31.6.6606 2009.07.09 -
F-Prot 4.4.4.56 2009.07.08 -
F-Secure 8.0.14470.0 2009.07.09 -
Fortinet 3.117.0.0 2009.07.03 -
GData 19 2009.07.09 -
Ikarus T3.1.1.64.0 2009.07.09 -
Jiangmin 11.0.706 2009.07.09 -
K7AntiVirus 7.10.788 2009.07.09 -
Kaspersky 7.0.0.125 2009.07.09 -
McAfee 5670 2009.07.08 DNSChanger.ad
McAfee+Artemis 5670 2009.07.08 DNSChanger.ad
McAfee-GW-Edition 6.8.5 2009.07.09 Heuristic.LooksLike.Win32.Sality.B
Microsoft 1.4803 2009.07.09 VirTool:Win32/Obfuscator.ET
NOD32 4228 2009.07.09 -
Norman 6.01.09 2009.07.09 -
nProtect 2009.1.8.0 2009.07.09 -
Panda 10.0.0.14 2009.07.08 -
PCTools 4.4.2.0 2009.07.09 -
Prevx 3.0 2009.07.09 -
Rising 21.37.34.00 2009.07.09 -
Sophos 4.43.0 2009.07.09 -
Sunbelt 3.2.1858.2 2009.07.09 -
Symantec 1.4.4.12 2009.07.09 -
TheHacker 6.3.4.3.363 2009.07.08 -
TrendMicro 8.950.0.1094 2009.07.09 -
VBA32 3.12.10.7 2009.07.09 -
ViRobot 2009.7.9.1827 2009.07.09 -
VirusBuster 4.6.5.0 2009.07.08 -
Additional information
File size: 86528 bytes
MD5   : ee8171ed76ae49a9c68dd5d33ce74931
SHA1  : 2ef3f1611292314f53ecaf716adcb39f5e3ca2db
SHA256: 3ca539787a012c669a99e87150c4e891ae9891e118ee5f87d12e90203c6f07f7
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1C8D
timedatestamp.....: 0x4A4CAD5B (Thu Jul 2 14:51:39 2009)
machinetype.......: 0x14C (Intel I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x11E0 0x1200 6.39 9dd76a440c6185f4c8b79b475eca4df5
.rdata 0x3000 0x50E 0x600 4.64 78d7c25f99205613261cc2e09a197de7
.data 0x4000 0x12DFE 0x12E00 8.00 4645eceb4b82ca806fdbb6f5dd2c45ee
.rsrc 0x17000 0x5FA 0x600 5.70 29ddbc23b33f6481996bff93ccbf4b91
.reloc 0x18000 0x1E 0x200 0.39 900d0c718569fc677f03140d638504ac

( 4 imports )

> kernel32.dll: GetEnvironmentVariableA, OpenProfileUserMapping, GetCommandLineA, OpenEventA, GetModuleHandleA, CreateFileW, CallNamedPipeA, GetLastError, AssignProcessToJobObject, GetFileSize, GetLogicalDriveStringsA, EraseTape, CreateDirectoryA, GetPrivateProfileStringA, SetEnvironmentVariableA, GetCurrentProcess, RtlFillMemory, CreateEventA
> msvcrt.dll: _wstrdate, ___Gbad_typeid@@UAEPAXI@Z, _j1, _ltow, _wtempnam, _wfopen, memcpy, _ismbbkana, _putch, __lconv_init, _wtoi, __0__non_rtti_object@@QAE@PBD@Z
> opengl32.dll: glTexCoord1fv, glStencilMask, glGetIntegerv, glEvalCoord1fv, glTexEnviv, glNormal3sv, glRasterPos3f, glBlendFunc, glTexParameteriv, glMap1d, glReadBuffer, glStencilFunc
> winmm.dll: mixerGetNumDevs, waveOutGetPitch, mixerGetLineInfoW, tid32Message, mciSendStringA, PlaySoundA, timeGetDevCaps, midiInGetErrorTextA, midiInMessage, midiOutGetDevCapsW, mmioFlush, waveOutReset

( 0 exports )
TrID  : File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=ee8171ed76ae49a9c68dd5d33ce74931
ssdeep: 1536:3H2zh3QnP3njbHnVQtrlt0DQAHHA+boxipThSo5NH:3HAhCvHVcrleD/gEKoTIo5B
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=408D698F00643072529401D95BE9B9009056A782
PEiD  : -
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file