|
Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information... |
| Antivirus | Version | Last Update | Result |
|---|---|---|---|
| a-squared | 4.0.0.101 | 2009.05.19 | - |
| AhnLab-V3 | 5.0.0.2 | 2009.05.19 | - |
| AntiVir | 7.9.0.168 | 2009.05.19 | - |
| Antiy-AVL | 2.0.3.1 | 2009.05.19 | - |
| Authentium | 5.1.2.4 | 2009.05.19 | - |
| Avast | 4.8.1335.0 | 2009.05.18 | - |
| AVG | 8.5.0.336 | 2009.05.19 | - |
| BitDefender | 7.2 | 2009.05.19 | - |
| CAT-QuickHeal | 10.00 | 2009.05.15 | TrojanDownloader.Adload.hz |
| ClamAV | 0.94.1 | 2009.05.19 | - |
| Comodo | 1157 | 2009.05.08 | - |
| DrWeb | 5.0.0.12182 | 2009.05.19 | - |
| eSafe | 7.0.17.0 | 2009.05.19 | - |
| eTrust-Vet | 31.6.6509 | 2009.05.18 | - |
| F-Prot | 4.4.4.56 | 2009.05.18 | - |
| F-Secure | 8.0.14470.0 | 2009.05.19 | - |
| Fortinet | 3.117.0.0 | 2009.05.19 | - |
| GData | 19 | 2009.05.19 | - |
| Ikarus | T3.1.1.49.0 | 2009.05.19 | - |
| K7AntiVirus | 7.10.737 | 2009.05.16 | Backdoor.Win32.VB |
| Kaspersky | 7.0.0.125 | 2009.05.19 | - |
| McAfee | 5619 | 2009.05.18 | - |
| McAfee+Artemis | 5619 | 2009.05.18 | - |
| McAfee-GW-Edition | 6.7.6 | 2009.05.19 | Virus.Win32.FileInfector.gen!92 (suspicious) |
| Microsoft | 1.4602 | 2009.05.19 | - |
| NOD32 | 4086 | 2009.05.19 | - |
| Norman | 6.01.05 | 2009.05.18 | - |
| nProtect | 2009.1.8.0 | 2009.05.19 | - |
| Panda | 10.0.0.14 | 2009.05.18 | - |
| PCTools | 4.4.2.0 | 2009.05.18 | - |
| Prevx | 3.0 | 2009.05.19 | - |
| Rising | 21.30.12.00 | 2009.05.19 | - |
| Sophos | 4.41.0 | 2009.05.19 | - |
| Sunbelt | 3.2.1858.2 | 2009.05.18 | - |
| Symantec | 1.4.4.12 | 2009.05.19 | - |
| TheHacker | 6.3.4.1.327 | 2009.05.19 | - |
| TrendMicro | 8.950.0.1092 | 2009.05.19 | - |
| VBA32 | 3.12.10.5 | 2009.05.19 | - |
| ViRobot | 2009.5.19.1740 | 2009.05.19 | - |
| Additional information |
|---|
| File size: 1212416 bytes |
| MD5...: 0925f30901debecb9faf37a8f452c565 |
| SHA1..: 43512e7db2c26de7b36fde4330d3c6b23d40be09 |
| SHA256: 7c1c25ff2534057a91e777ee3921fd593e5b053dc40a354fbde9b871e62da66f |
| SHA512: 7ee3d3be34780cf0b8d530ff5f0056180b211e2aa8352d8064608766ef9cb918 fec23f0b14186c09d25bb0f3ec847fc93402b39503304df0df2c6abcb5ce3312 |
| ssdeep: 24576:atnD/KxknW/Sm7P33FinwgiSrqWoAWc/+CxC7ve3KUxHgjzwD6:PxkaLlc iEaAWEwqhV6 |
| PEiD..: - |
| TrID..: File type identification Generic Win/DOS Executable (49.9%) DOS Executable Generic (49.8%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%) |
| PEInfo: PE Structure information ( base data ) entrypointaddress.: 0xf3000 timedatestamp.....: 0x49eb37ec (Sun Apr 19 14:40:44 2009) machinetype.......: 0x14c (I386) ( 8 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x77b78 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e .rdata 0x79000 0x1f68a 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e .data 0x99000 0x9f5c 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e .text1 0xa3000 0x50000 0x43000 7.97 d3ec8ee1c1285f3094929cac03a8462a .adata 0xf3000 0x10000 0xd000 7.01 c7902203d41eeb2ef8ccef634826ffc8 .data1 0x103000 0x20000 0xa000 3.08 d167e81655999a1a941789daa9e2fead .pdata 0x123000 0xb0000 0xa7000 8.00 a1c902c2902db37f5fea2e823ed8fbcf .rsrc 0x1d3000 0x409000 0x26000 5.44 cd245d9ee21f2a15dd3e899774d7a164 ( 3 imports ) > KERNEL32.dll: CreateThread, GlobalUnlock, GlobalLock, GlobalAlloc, GetTickCount, WideCharToMultiByte, IsBadReadPtr, GlobalAddAtomA, GlobalAddAtomW, GetModuleHandleA, GlobalFree, GlobalGetAtomNameA, GlobalDeleteAtom, GlobalGetAtomNameW, FreeConsole, GetEnvironmentVariableA, VirtualProtect, VirtualAlloc, GetProcAddress, GetLastError, LoadLibraryA, SetLastError, SetThreadPriority, GetCurrentThread, CreateProcessA, GetCommandLineA, GetStartupInfoA, SetEnvironmentVariableA, ReleaseMutex, WaitForSingleObject, CreateMutexA, OpenMutexA, GetCurrentThreadId, ReadFile, GetFileSize, CreateFileA, FindClose, FindFirstFileA, FindFirstFileW, VirtualQueryEx, GetExitCodeProcess, ReadProcessMemory, UnmapViewOfFile, ContinueDebugEvent, SetThreadContext, GetThreadContext, WaitForDebugEvent, CloseHandle, DebugActiveProcess, ResumeThread, CreateProcessW, GetCommandLineW, GetStartupInfoW, MapViewOfFile, DuplicateHandle, GetCurrentProcess, CreateFileMappingA, VirtualProtectEx, WriteProcessMemory, ExitProcess, CompareStringA, FlushFileBuffers, LCMapStringW, LCMapStringA, SetStdHandle, GetOEMCP, GetACP, GetCPInfo, GetStringTypeW, CompareStringW, GetStringTypeA, MultiByteToWideChar, SetFilePointer, HeapReAlloc, WriteFile, VirtualFree, HeapCreate, HeapDestroy, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, HeapFree, HeapAlloc, GetVersion, GetLocalTime, GetSystemTime, GetTimeZoneInformation, RtlUnwind, TerminateProcess, Sleep, EnterCriticalSection, LeaveCriticalSection, GetVersionExA, InitializeCriticalSection, GetCurrentProcessId, GetModuleFileNameW, GetShortPathNameW, GetModuleFileNameA, SuspendThread, GetShortPathNameA > USER32.dll: GetDesktopWindow, MoveWindow, SetPropA, EnumThreadWindows, GetPropA, GetMessageA, BeginPaint, EndPaint, KillTimer, GetAsyncKeyState, GetSystemMetrics, SetTimer, SetWindowTextA, GetDlgItem, CreateDialogIndirectParamA, ShowWindow, UpdateWindow, LoadStringA, LoadStringW, FindWindowA, WaitForInputIdle, DestroyWindow, MessageBoxA, InSendMessage, UnpackDDElParam, FreeDDElParam, DefWindowProcA, LoadCursorA, RegisterClassW, CreateWindowExW, RegisterClassA, CreateWindowExA, GetWindowThreadProcessId, SendMessageW, PeekMessageA, TranslateMessage, DispatchMessageA, EnumWindows, IsWindowUnicode, PackDDElParam, PostMessageW, PostMessageA, IsWindow, SendMessageA > GDI32.dll: DeleteDC, RealizePalette, SelectPalette, CreateDCA, CreatePalette, DeleteObject, BitBlt, SelectObject, CreateCompatibleDC, CreateDIBitmap ( 0 exports ) |
| PDFiD.: - |
| RDS...: NSRL Reference Data Set - |
| packers (Kaspersky): Armadillo |
| packers (F-Prot): Armadillo |
ATTENTION:
VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.