Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File malware.exe received on 2009.04.29 15:27:11 (UTC)
Current status: finished
Result: 14/40 (35.00%)
Antivirus Version Last Update Result
a-squared 4.0.0.101 2009.04.29 Virus.Win32.Sality!IK
AhnLab-V3 5.0.0.2 2009.04.29 -
AntiVir 7.9.0.156 2009.04.29 TR/Drop.Bagle.FR
Antiy-AVL 2.0.3.1 2009.04.29 -
Authentium 5.1.2.4 2009.04.29 W32/Sality.AC
Avast 4.8.1335.0 2009.04.28 Win32:Sality-V
AVG 8.5.0.287 2009.04.29 Win32/Heur
BitDefender 7.2 2009.04.29 -
CAT-QuickHeal 10.00 2009.04.29 -
ClamAV 0.94.1 2009.04.29 -
Comodo 1141 2009.04.29 -
DrWeb 4.44.0.09170 2009.04.29 -
eSafe 7.0.17.0 2009.04.27 Suspicious File
eTrust-Vet 31.6.6482 2009.04.29 -
F-Prot 4.4.4.56 2009.04.29 W32/Sality.AC
F-Secure 8.0.14470.0 2009.04.29 -
Fortinet 3.117.0.0 2009.04.29 -
GData 19 2009.04.29 Win32:Sality-V
Ikarus T3.1.1.49.0 2009.04.29 Virus.Win32.Sality
K7AntiVirus 7.10.719 2009.04.29 -
Kaspersky 7.0.0.125 2009.04.29 -
McAfee 5599 2009.04.28 -
McAfee+Artemis 5599 2009.04.28 -
McAfee-GW-Edition 6.7.6 2009.04.29 Trojan.Drop.Bagle.FR
Microsoft 1.4602 2009.04.29 -
NOD32 4043 2009.04.29 -
Norman 6.01.05 2009.04.29 -
nProtect 2009.1.8.0 2009.04.29 -
Panda 10.0.0.14 2009.04.28 Suspicious file
PCTools 4.4.2.0 2009.04.29 -
Prevx1 3.0 2009.04.29 -
Rising 21.27.22.00 2009.04.29 -
Sophos 4.41.0 2009.04.29 Mal/HckPk-A
Sunbelt 3.2.1858.2 2009.04.28 -
Symantec 1.4.4.12 2009.04.29 Suspicious.MH690.A
TheHacker 6.3.4.1.317 2009.04.29 -
TrendMicro 8.950.0.1092 2009.04.29 PAK_Generic.001
VBA32 3.12.10.3 2009.04.29 -
ViRobot 2009.4.29.1715 2009.04.29 -
VirusBuster 4.6.5.0 2009.04.29 -
Additional information
File size: 47616 bytes
MD5...: 4c998e16e58c9cfa74e371c9591290e2
SHA1..: c1d92676bf213c0ac1af596545ec1fafb884c0bd
SHA256: e8781737413cd9fcd1f1826d31fd95e8d5880e8d363a4354a71fc208f951c62c
SHA512: 3bb018a1e9283c7c109d6bb7bc6427fd24c0cbe6ff112e3c88dc7452459806fa
214fb49d0373613ba7879d7c4f51c53bb189a123ffd4222244c99fc48d3abfa3
ssdeep: 48:6zwbxvtaX5fbp0tw+WSq2Upu8metqPrIXHimU7zdvP1vnz6nGY8Je9ItZKnZg
e08:KwbxlaX5fmvWSKUpACLFz0ltVSPY
PEiD..: -
TrID..: File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xe037
timedatestamp.....: 0x43f1ddf9 (Tue Feb 14 13:41:13 2006)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0xc000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0xd000 0xbac 0xc00 3.03 816b647e030b7e89eb5bb49cdfe66433
UPX2 0xe000 0xb000 0xaa00 0.40 149d85bebc36ea09e1082dc97ebd54df

( 11 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress
> kernel32.dll: Sleep
> user32.dll: DrawTextA
> wsock32.dll: send
> ole32.dll: CoInitialize
> shlwapi.dll: StrDupA
> wininet.dll: InternetOpenA
> advapi32.dll: RegCloseKey
> urlmon.dll: URLDownloadToFileA
> shell32.dll: ShellExecuteA
> gdi32.dll: DeleteDC

( 0 exports )
PDFiD.: -
RDS...: NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file