|
Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information... |
| Antivirus | Version | Last Update | Result |
|---|---|---|---|
| a-squared | 4.5.0.41 | 2009.10.31 | Trojan-PWS.Win32.Riodrv!IK |
| AhnLab-V3 | 5.0.0.2 | 2009.10.30 | - |
| AntiVir | 7.9.1.53 | 2009.10.30 | BDS/Backdoor.Gen2 |
| Antiy-AVL | 2.0.3.7 | 2009.10.30 | Backdoor/Win32.DeAlfa.gen |
| Authentium | 5.1.2.4 | 2009.10.31 | W32/Banload.C.gen!Eldorado |
| Avast | 4.8.1351.0 | 2009.10.31 | - |
| AVG | 8.5.0.423 | 2009.11.01 | Agent.4.AO |
| BitDefender | 7.2 | 2009.11.01 | Backdoor.Generic.221293 |
| CAT-QuickHeal | 10.00 | 2009.10.31 | - |
| ClamAV | 0.94.1 | 2009.11.01 | - |
| Comodo | 2799 | 2009.11.01 | Heur.Suspicious |
| DrWeb | 5.0.0.12182 | 2009.11.01 | BackDoor.Siggen.1875 |
| eSafe | 7.0.17.0 | 2009.10.29 | Win32.BDSBackdoor |
| eTrust-Vet | 35.1.7094 | 2009.10.30 | Win32/Riodrv!generic |
| F-Prot | 4.5.1.85 | 2009.10.31 | W32/Banload.C.gen!Eldorado |
| F-Secure | 9.0.15370.0 | 2009.10.30 | Backdoor:W32/Agent.MCT |
| Fortinet | 3.120.0.0 | 2009.11.01 | - |
| GData | 19 | 2009.11.01 | Backdoor.Generic.221293 |
| Ikarus | T3.1.1.72.0 | 2009.10.31 | Trojan-PWS.Win32.Riodrv |
| Jiangmin | 11.0.800 | 2009.10.31 | - |
| K7AntiVirus | 7.10.885 | 2009.10.31 | Trojan.Win32.Malware.1 |
| Kaspersky | 7.0.0.125 | 2009.11.01 | Backdoor.Win32.DeAlfa.fa |
| McAfee | 5788 | 2009.10.31 | - |
| McAfee+Artemis | 5788 | 2009.10.31 | Artemis!BEFCBF177C66 |
| McAfee-GW-Edition | 6.8.5 | 2009.11.01 | Heuristic.LooksLike.Trojan.PSW.Riodrv.I |
| Microsoft | 1.5202 | 2009.10.31 | Trojan:Win32/Modphip.A |
| NOD32 | 4561 | 2009.10.31 | - |
| Norman | 6.03.02 | 2009.10.31 | - |
| nProtect | 2009.1.8.0 | 2009.11.01 | - |
| Panda | 10.0.2.2 | 2009.10.31 | Generic Trojan |
| PCTools | 7.0.3.5 | 2009.10.30 | - |
| Prevx | 3.0 | 2009.11.01 | - |
| Rising | 21.53.60.00 | 2009.11.01 | - |
| Sophos | 4.47.0 | 2009.11.01 | Troj/Bkdr-C |
| Sunbelt | 3.2.1858.2 | 2009.10.31 | - |
| Symantec | 1.4.4.12 | 2009.11.01 | - |
| TheHacker | 6.5.0.2.058 | 2009.10.31 | - |
| TrendMicro | 8.950.0.1094 | 2009.11.01 | Possible_Virus |
| VBA32 | 3.12.10.11 | 2009.10.30 | Backdoor.Win32.Delf.owj |
| ViRobot | 2009.10.31.2015 | 2009.10.31 | - |
| VirusBuster | 4.6.5.0 | 2009.10.31 | - |
| Additional information |
|---|
| File size: 516096 bytes |
| MD5 : befcbf177c6677cfbe13dd9f73585ba4 |
| SHA1 : 30ad4a96525747af649358b0c4d591630fec0ead |
| SHA256: 52729d2b4416bd01a4527baf397c3c21ce88a88446f7af5171da09ae25db6027 |
| PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x6DD54 timedatestamp.....: 0x2A425E19 (Sat Jun 20 00:22:17 1992) machinetype.......: 0x14C (Intel I386) ( 8 sections ) name viradd virsiz rawdsiz ntrpy md5 CODE 0x1000 0x6D7D4 0x6D800 6.58 a041c97c61d347209ae942f558580c5a DATA 0x6F000 0x1B64 0x1C00 4.77 279c80c0e117ff7db9ffce55a836c3be BSS 0x71000 0xE49 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e .idata 0x72000 0x2788 0x2800 4.96 8d1ff8a6361a83618f66abd28749206f .tls 0x75000 0x10 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e .rdata 0x76000 0x18 0x200 0.21 062547fda4f2054a13543ae2ca583243 .reloc 0x77000 0x6AA0 0x6C00 6.69 438a239fe63b0743f1fc94b3b5239f73 .rsrc 0x7E000 0x5200 0x5200 4.17 1554ad4c3b41572c5d8aa3e0dec83bed ( 12 imports ) > advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey, RegSetValueExA, RegQueryValueExA, RegOpenKeyExA, RegDeleteKeyA, RegCloseKey > comctl32.dll: ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_SetDragCursorImage, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Remove, ImageList_DrawEx, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create > gdi32.dll: UnrealizeObject, StretchBlt, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetEnhMetaFileBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RestoreDC, RectVisible, RealizePalette, PlayEnhMetaFile, PatBlt, MoveToEx, MaskBlt, LineTo, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetPixel, GetPaletteEntries, GetObjectA, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, GdiFlush, ExcludeClipRect, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectA, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileA, BitBlt > kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, SetCurrentDirectoryA, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCurrentDirectoryA, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, CreateThread, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle, TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA, lstrcpyA, _lwrite, _lread, _lopen, _lcreat, _lclose, WriteFile, WinExec, WaitForSingleObject, VirtualQuery, VirtualAlloc, TerminateThread, Sleep, SizeofResource, SetThreadLocale, SetFilePointer, SetFileAttributesA, SetEvent, SetErrorMode, SetEndOfFile, ResetEvent, ReadFile, MultiByteToWideChar, MulDiv, MoveFileExA, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GlobalUnlock, GlobalReAlloc, GlobalHandle, GlobalLock, GlobalFree, GlobalFindAtomA, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetWindowsDirectoryA, GetVersionExA, GetVersion, GetTickCount, GetThreadLocale, GetSystemTime, GetSystemInfo, GetSystemDirectoryA, GetStringTypeExA, GetStdHandle, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetFileAttributesA, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCurrentProcessId, GetCPInfo, GetACP, FreeResource, InterlockedExchange, FreeLibrary, FormatMessageA, FindResourceA, FindNextFileA, FindFirstFileA, FindClose, FileTimeToLocalFileTime, FileTimeToDosDateTime, ExitProcess, EnumCalendarInfoA, EnterCriticalSection, DeleteFileA, DeleteCriticalSection, CreateThread, CreateMutexA, CreateFileA, CreateEventA, CompareStringA, CloseHandle, Sleep > ole32.dll: CoCreateInstance, CoUninitialize, CoInitialize > oleaut32.dll: SysFreeString, SysReAllocStringLen, SysAllocStringLen, SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit, GetErrorInfo, SysFreeString > shell32.dll: ShellExecuteA, SHGetSpecialFolderPathA > urlmon.dll: URLDownloadToFileA > user32.dll: GetKeyboardType, LoadStringA, MessageBoxA, CharNextA, CreateWindowExA, WindowFromPoint, WinHelpA, WaitMessage, UpdateWindow, UnregisterClassA, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, SystemParametersInfoA, ShowWindow, ShowScrollBar, ShowOwnedPopups, ShowCursor, SetWindowsHookExA, SetWindowPos, SetWindowPlacement, SetWindowLongA, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropA, SetParent, SetMenuItemInfoA, SetMenu, SetForegroundWindow, SetFocus, SetCursor, SetClassLongA, SetCapture, SetActiveWindow, SendMessageA, ScrollWindow, ScreenToClient, RemovePropA, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageA, RegisterClipboardFormatA, RegisterClassA, RedrawWindow, PtInRect, PostQuitMessage, PostMessageA, PeekMessageA, OpenClipboard, OffsetRect, OemToCharA, MessageBoxA, MapWindowPoints, MapVirtualKeyA, LoadStringA, LoadKeyboardLayoutA, LoadIconA, LoadCursorA, LoadBitmapA, KillTimer, IsZoomed, IsWindowVisible, IsWindowEnabled, IsWindow, IsRectEmpty, IsIconic, IsDialogMessageA, IsChild, InvalidateRect, IntersectRect, InsertMenuItemA, InsertMenuA, InflateRect, GetWindowThreadProcessId, GetWindowTextA, GetWindowRect, GetWindowPlacement, GetWindowLongA, GetWindowDC, GetTopWindow, GetSystemMetrics, GetSystemMenu, GetSysColorBrush, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetPropA, GetParent, GetWindow, GetMessageA, GetMenuStringA, GetMenuState, GetMenuItemInfoA, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextA, GetIconInfo, GetForegroundWindow, GetFocus, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClipboardData, GetClientRect, GetClassNameA, GetClassInfoA, GetCapture, GetAsyncKeyState, GetActiveWindow, FrameRect, FindWindowA, FillRect, EqualRect, EnumWindows, EnumThreadWindows, EndPaint, EnableWindow, EnableScrollBar, EnableMenuItem, DrawTextA, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawEdge, DispatchMessageA, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcA, DefMDIChildProcA, DefFrameProcA, CreatePopupMenu, CreateMenu, CreateIcon, CloseClipboard, ClientToScreen, CheckMenuItem, CallWindowProcA, CallNextHookEx, BeginPaint, CharNextA, CharLowerBuffA, CharLowerA, CharToOemA, AdjustWindowRectEx, ActivateKeyboardLayout, DdeCmpStringHandles, DdeFreeStringHandle, DdeQueryStringA, DdeCreateStringHandleA, DdeGetLastError, DdeFreeDataHandle, DdeUnaccessData, DdeAccessData, DdeCreateDataHandle, DdeClientTransaction, DdeNameService, DdePostAdvise, DdeSetUserHandle, DdeQueryConvInfo, DdeDisconnect, DdeConnect, DdeUninitialize, DdeInitializeA > version.dll: VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA > wininet.dll: InternetReadFile, InternetOpenUrlA, InternetOpenA, InternetCloseHandle > wsock32.dll: WSAStartup, gethostbyname, socket, send, inet_ntoa, inet_addr, htons, connect, closesocket ( 0 exports ) |
| TrID : File type identification Win32 Executable Borland Delphi 7 (69.1%) Win32 Executable Borland Delphi 6 (27.0%) Win32 Executable Delphi generic (1.5%) Win32 Executable Generic (0.8%) Win32 Dynamic Link Library (generic) (0.7%) |
| ThreatExpert: http://www.threatexpert.com/report.aspx?md5=befcbf177c6677cfbe13dd9f73585ba4 |
| ssdeep: 12288:j3RHehaYT2zrzQ1OuKlyToIIodS1BbRAmaGK:jV2al/zQOZpKgvAma |
| Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=45805840005F7C4AE0B907E43D4E1C00069516DD |
| PEiD : - |
| RDS : NSRL Reference Data Set - |
ATTENTION:
VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.