Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File s.exe received on 2009.10.22 13:53:29 (UTC)
Current status: finished
Result: 37/41 (90.24%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.10.22 Worm.Win32.Pushbot!IK
AhnLab-V3 5.0.0.2 2009.10.22 Win32/Kolab.worm.80384.C
AntiVir 7.9.1.42 2009.10.22 TR/Proxy.Agent.HZ.2
Antiy-AVL 2.0.3.7 2009.10.22 Backdoor/Win32.SdBot.gen
Authentium 5.1.2.4 2009.10.22 W32/Downldr2.GLSP
Avast 4.8.1351.0 2009.10.21 Win32:Trojan-gen
AVG 8.5.0.423 2009.10.22 Nakgo.A
BitDefender 7.2 2009.10.22 Trojan.Generic.2208424
CAT-QuickHeal 10.00 2009.10.22 I-Worm.Kolab.dss
ClamAV 0.94.1 2009.10.22 -
Comodo 2689 2009.10.22 UnclassifiedMalware
DrWeb 5.0.0.12182 2009.10.22 Trojan.Spambot.3480
eSafe 7.0.17.0 2009.10.21 -
eTrust-Vet 35.1.7079 2009.10.22 Win32/IRCBot.UL
F-Prot 4.5.1.85 2009.10.22 W32/Downldr2.GLSP
F-Secure 9.0.15370.0 2009.10.22 Trojan.Generic.2208424
Fortinet 3.120.0.0 2009.10.22 PossibleThreat
GData 19 2009.10.22 Trojan.Generic.2208424
Ikarus T3.1.1.72.0 2009.10.22 Worm.Win32.Pushbot
Jiangmin 11.0.800 2009.10.22 Backdoor/SdBot.nmz
K7AntiVirus 7.10.876 2009.10.21 Trojan.Win32.Malware.1
Kaspersky 7.0.0.125 2009.10.22 Net-Worm.Win32.Kolab.dwe
McAfee 5778 2009.10.21 Generic Proxy!f
McAfee+Artemis 5778 2009.10.21 Generic Proxy!f
McAfee-GW-Edition 6.8.5 2009.10.22 Trojan.Proxy.Agent.HZ.2
Microsoft 1.5202 2009.10.22 TrojanProxy:Win32/Agent.HZ
NOD32 4533 2009.10.22 a variant of Win32/Injector.YG
Norman 6.03.02 2009.10.22 W32/Smalltroj.RHIW
nProtect 2009.1.8.0 2009.10.22 Worm/W32.Kolab.80384.B
Panda 10.0.2.2 2009.10.21 W32/Gaobot.OXI.worm
PCTools 4.4.2.0 2009.10.19 -
Prevx 3.0 2009.10.22 High Risk System Back Door
Rising 21.52.34.00 2009.10.22 -
Sophos 4.46.0 2009.10.22 Mal/Generic-A
Sunbelt 3.2.1858.2 2009.10.22 Trojan.Win32.Malware (fs)
Symantec 1.4.4.12 2009.10.22 Packed.Generic.252
TheHacker 6.5.0.2.050 2009.10.22 W32/Kolab.dst
TrendMicro 8.950.0.1094 2009.10.22 TROJ_AGENT.AVFG
VBA32 3.12.10.11 2009.10.22 Backdoor.Win32.SdBot.oqp
ViRobot 2009.10.22.2001 2009.10.22 Worm.Win32.Net-Kolab.80384
VirusBuster 4.6.5.0 2009.10.22 Trojan.PR.Agent.OQJB
Additional information
File size: 80384 bytes
MD5   : 273a07dccdfff421bfde652912f02e32
SHA1  : 794022a73ae8de195ca125a4dbebb81239b71b8d
SHA256: 52702204fc268e4a7b900b32f526b98f5cad8a6db2971084c295cca76a177b61
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x5BF0
timedatestamp.....: 0x4A9449BB (Tue Aug 25 22:29:47 2009)
machinetype.......: 0x14C (Intel I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x4DEE 0x4E00 6.21 7679ebeb04e1c312f3568efa6c90d0c0
.rdata 0x6000 0xB6C 0xC00 5.02 07bee7e7f4e02ae01f21ac4f45c578bb
.data 0x7000 0x752C94 0x800 5.99 9d127824c02042b7b8bc16827d1860d6
.rsrc 0x75A000 0xD38C 0xD400 7.83 764d80fbbd5312a9772bc7cff2c36134

( 6 imports )

> gdi32.dll: CreateCompatibleDC, CreateSolidBrush, SetBkMode, SetTextColor, TextOutA, BitBlt, CreateCompatibleBitmap, SelectObject, DeleteObject, DeleteDC
> kernel32.dll: CreateThread, Sleep, lstrlenA, GetModuleHandleA, GetStartupInfoA
> msvcp60.dll: __Tidy@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEX_N@Z, __1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ, ___F_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEXXZ, __0Init@ios_base@std@@QAE@XZ, __0_Winit@std@@QAE@XZ, __1_Winit@std@@QAE@XZ, _replace@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@IIABV12@II@Z, _substr@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QBE_AV12@II@Z, _npos@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@2IB, _find@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QBEIPBDII@Z, __C@_1___Nullstr@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@CAPBDXZ@4DB, _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, __1Init@ios_base@std@@QAE@XZ
> msvcrt.dll: strlen, _controlfp, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _XcptFilter, _exit, _terminate@@YAXXZ, _onexit, __dllonexit, free, _EH_prolog, __CxxFrameHandler, strcmp, memmove, malloc, sprintf, rand, _except_handler3, memcpy, memset, _stricmp, __2@YAPAXI@Z, getenv
> ole32.dll: CoInitialize
> user32.dll: SetTimer, PostQuitMessage, EndPaint, BeginPaint, DestroyWindow, ReleaseDC, GetDC, LoadBitmapA, GetClientRect, wsprintfA, FillRect, MessageBoxA, LoadCursorA, DispatchMessageA, DefWindowProcA, LoadIconA, TranslateMessage, GetMessageA, UpdateWindow, ShowWindow, CreateWindowExA, RegisterClassExA

( 0 exports )
TrID  : File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=273a07dccdfff421bfde652912f02e32
ssdeep: 1536:5EyvvBZPQez70cevxRMefOcCclIHhb05e4kamQ2lmj+gDDBsx8gN:55vB1Qez4cevxRMefqdhbkuflmj+n8
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=1A1791AB0095A75D3A5901C1E7DA8000E1456738
PEiD  : -
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file