Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File vkon.exe_ received on 2009.10.18 23:56:26 (UTC)
Current status: finished
Result: 21/40 (52.50%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.10.18 Trojan-Dropper.Win32.Malf!IK
AhnLab-V3 5.0.0.2 2009.10.17 -
AntiVir 7.9.1.35 2009.10.18 TR/Dropper.Gen
Antiy-AVL 2.0.3.7 2009.10.16 Worm/Win32.Bagle
Authentium 5.1.2.4 2009.10.18 -
Avast 4.8.1351.0 2009.10.18 Win32:Trojan-gen
AVG 8.5.0.420 2009.10.18 -
BitDefender 7.2 2009.10.19 -
CAT-QuickHeal 10.00 2009.10.18 -
ClamAV 0.94.1 2009.10.19 -
Comodo 2650 2009.10.19 -
DrWeb 5.0.0.12182 2009.10.18 Win32.HLLM.Beagle.306
eSafe 7.0.17.0 2009.10.18 Win32.TRDropper
eTrust-Vet 35.1.7072 2009.10.16 -
F-Prot 4.5.1.85 2009.10.18 -
F-Secure 9.0.15300.0 2009.10.16 -
Fortinet 3.120.0.0 2009.10.16 -
GData 19 2009.10.19 Win32:Trojan-gen
Ikarus T3.1.1.72.0 2009.10.18 Trojan-Dropper.Win32.Malf
Jiangmin 11.0.800 2009.10.18 -
K7AntiVirus 7.10.872 2009.10.16 Trojan.Win32.Malware.1
Kaspersky 7.0.0.125 2009.10.19 Trojan-Dropper.Win32.Agent.bftb
McAfee 5775 2009.10.18 Generic Dropper!bdn
McAfee+Artemis 5775 2009.10.18 Generic Dropper!bdn
McAfee-GW-Edition 6.8.5 2009.10.18 Trojan.Dropper.Gen
Microsoft 1.5101 2009.10.19 TrojanDropper:Win32/Malf.gen
NOD32 4520 2009.10.18 -
Norman 6.03.02 2009.10.17 W32/Bagle.OXM
nProtect 2009.1.8.0 2009.10.18 -
Panda 10.0.2.2 2009.10.18 Trj/CI.A
PCTools 4.4.2.0 2009.10.18 -
Rising 21.51.62.00 2009.10.18 RootKit.Win32.Small.cnb
Sophos 4.46.0 2009.10.18 Mal/Generic-A
Sunbelt 3.2.1858.2 2009.10.18 -
Symantec 1.4.4.12 2009.10.18 Trojan Horse
TheHacker 6.5.0.2.046 2009.10.19 -
TrendMicro 8.950.0.1094 2009.10.18 PAK_Generic.001
VBA32 3.12.10.11 2009.10.18 Trojan-Dropper.Win32.Agent.bftb
ViRobot 2009.10.17.1990 2009.10.17 -
VirusBuster 4.6.5.0 2009.10.18 -
Additional information
File size: 51712 bytes
MD5   : da436611fb5e3e4e12cf69ac563240ce
SHA1  : bff7711b92608291f42156e13404b30e4a790590
SHA256: 546caf2c2bd1682a6564a304b862a5d312e3eec1370f190fb34458917cb21e09
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x20190
timedatestamp.....: 0x4ACF566D (Fri Oct 9 17:27:41 2009)
machinetype.......: 0x14C (Intel I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x13000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x14000 0xD000 0xC400 7.93 d5b475bc92722d0c8882b1e04cdcdbd3
.rsrc 0x21000 0x1000 0x200 3.36 b835af9d451479410e691a8c92c0cc65

( 3 imports )

> kernel32.dll: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> shell32.dll: ShellExecuteA
> user32.dll: FindWindowA

( 0 exports )
TrID  : File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=da436611fb5e3e4e12cf69ac563240ce
ssdeep: 1536:7GnlT5Tt29WwdQHy3vLpCVNzej9sqX0oJl:72Pwd/4VNo9r3
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=F6CB306D00AA82BACA4C00849E6D3F00568BF7F1
PEiD  : -
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file