Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File Tribalwar_Skin.exe received on 2009.11.06 09:08:03 (UTC)
Current status: finished
Result: 18/40 (45.00%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.11.06 -
AhnLab-V3 5.0.0.2 2009.11.06 -
AntiVir 7.9.1.59 2009.11.05 -
Antiy-AVL 2.0.3.7 2009.11.05 -
Authentium 5.2.0.5 2009.11.06 -
Avast 4.8.1351.0 2009.11.06 Win32:Adware-gen
AVG 8.5.0.423 2009.11.05 Generic13.BVJZ
BitDefender 7.2 2009.11.06 Trojan.Generic.2281886
CAT-QuickHeal 10.00 2009.11.06 -
ClamAV 0.94.1 2009.11.06 -
Comodo 2857 2009.11.06 -
DrWeb 5.0.0.12182 2009.11.06 Adware.Reklosoft.5
eTrust-Vet 35.1.7106 2009.11.05 -
F-Prot 4.5.1.85 2009.11.05 -
F-Secure 9.0.15370.0 2009.11.04 Trojan.Generic.2281886
Fortinet 3.120.0.0 2009.11.05 -
GData 19 2009.11.06 Trojan.Generic.2281886
Ikarus T3.1.1.74.0 2009.11.06 Trojan.Win32.BHO
Jiangmin 11.0.800 2009.11.06 -
K7AntiVirus 7.10.889 2009.11.05 -
Kaspersky 7.0.0.125 2009.11.06 Trojan-Ransom.Win32.Kerlofost.w
McAfee 5793 2009.11.05 -
McAfee+Artemis 5793 2009.11.05 Artemis!8C5B240C01B8
McAfee-GW-Edition 6.8.5 2009.11.06 Heuristic.BehavesLike.Win32.Dropper.I
Microsoft 1.5202 2009.11.05 BrowserModifier:Win32/Kerlofost
NOD32 4577 2009.11.05 Win32/BHO.NQT
Norman 6.03.02 2009.11.05 -
nProtect 2009.1.8.0 2009.11.06 -
Panda 10.0.2.2 2009.11.05 Trj/CI.A
PCTools 7.0.3.5 2009.11.06 Trojan.Adwareloader
Prevx 3.0 2009.11.06 -
Rising 21.54.42.00 2009.11.06 -
Sophos 4.47.0 2009.11.06 Troj/BHO-MN
Sunbelt 3.2.1858.2 2009.11.06 -
Symantec 1.4.4.12 2009.11.06 Trojan.Adwareloader
TheHacker 6.5.0.2.062 2009.11.05 -
TrendMicro 9.0.0.1003 2009.11.06 TROJ_ADLOAD.JQ
VBA32 3.12.10.11 2009.11.06 -
ViRobot 2009.11.6.2025 2009.11.06 -
VirusBuster 4.6.5.0 2009.11.05 Trojan.Kerlofost.C
Additional information
File size: 457594 bytes
MD5   : 8c5b240c01b8df9f0922c963d689b498
SHA1  : 352322ddb745e78a9d8ce675f0ffad7d0d8a96c7
SHA256: 5dba5c58536979dba0a5eef1ab3b098c5277cebaf3ced3da6e0a31102e12434b
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x30DE
timedatestamp.....: 0x498A4804 (Thu Feb 5 02:59:32 2009)
machinetype.......: 0x14C (Intel I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x5A28 0x5C00 6.46 a1468fc03fb3881e4551c7b7575e1ec8
.rdata 0x7000 0x1190 0x1200 5.18 0f7b157b78f399340e80aa07581634eb
.data 0x9000 0x399798 0x400 4.62 554e9357136d3067e20cc58702e35f8d
.ndata 0x3A3000 0xB000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0x3AE000 0x16EB0 0x17000 3.67 75b4c5419d7304ff37747dac2a03ceba

( 8 imports )

> advapi32.dll: RegQueryValueExA, RegSetValueExA, RegEnumKeyA, RegEnumValueA, RegOpenKeyExA, RegDeleteKeyA, RegDeleteValueA, RegCloseKey, RegCreateKeyExA
> comctl32.dll: ImageList_AddMasked, ImageList_Destroy, -, ImageList_Create
> gdi32.dll: SetBkColor, GetDeviceCaps, DeleteObject, CreateBrushIndirect, CreateFontIndirectA, SetBkMode, SetTextColor, SelectObject
> kernel32.dll: CompareFileTime, SearchPathA, GetShortPathNameA, GetFullPathNameA, MoveFileA, SetCurrentDirectoryA, GetFileAttributesA, GetLastError, CreateDirectoryA, SetFileAttributesA, Sleep, GetTickCount, GetFileSize, GetModuleFileNameA, GetCurrentProcess, CopyFileA, ExitProcess, GetWindowsDirectoryA, SetFileTime, GetCommandLineA, SetErrorMode, LoadLibraryA, lstrcpynA, GetDiskFreeSpaceA, GlobalUnlock, GlobalLock, CreateThread, CreateProcessA, RemoveDirectoryA, CreateFileA, GetTempFileNameA, lstrlenA, lstrcatA, GetSystemDirectoryA, GetVersion, CloseHandle, lstrcmpiA, lstrcmpA, ExpandEnvironmentStringsA, GlobalFree, GlobalAlloc, WaitForSingleObject, GetExitCodeProcess, GetModuleHandleA, LoadLibraryExA, GetProcAddress, FreeLibrary, MultiByteToWideChar, WritePrivateProfileStringA, GetPrivateProfileStringA, WriteFile, ReadFile, MulDiv, SetFilePointer, FindClose, FindNextFileA, FindFirstFileA, DeleteFileA, GetTempPathA
> ole32.dll: CoTaskMemFree, OleInitialize, OleUninitialize, CoCreateInstance
> shell32.dll: SHGetPathFromIDListA, SHBrowseForFolderA, SHGetFileInfoA, ShellExecuteA, SHFileOperationA, SHGetSpecialFolderLocation
> user32.dll: EndDialog, ScreenToClient, GetWindowRect, EnableMenuItem, GetSystemMenu, SetClassLongA, IsWindowEnabled, SetWindowPos, GetSysColor, GetWindowLongA, SetCursor, LoadCursorA, CheckDlgButton, GetMessagePos, LoadBitmapA, CallWindowProcA, IsWindowVisible, CloseClipboard, SetClipboardData, EmptyClipboard, RegisterClassA, TrackPopupMenu, AppendMenuA, CreatePopupMenu, GetSystemMetrics, SetDlgItemTextA, GetDlgItemTextA, MessageBoxIndirectA, CharPrevA, DispatchMessageA, PeekMessageA, DestroyWindow, CreateDialogParamA, SetTimer, SetWindowTextA, PostQuitMessage, SetForegroundWindow, wsprintfA, SendMessageTimeoutA, FindWindowExA, SystemParametersInfoA, CreateWindowExA, GetClassInfoA, DialogBoxParamA, CharNextA, OpenClipboard, ExitWindowsEx, IsWindow, GetDlgItem, SetWindowLongA, LoadImageA, GetDC, EnableWindow, InvalidateRect, SendMessageA, DefWindowProcA, BeginPaint, GetClientRect, FillRect, DrawTextA, EndPaint, ShowWindow
> version.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA

( 0 exports )
TrID  : File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
ssdeep: 6144:NN3WYEEj3+LmYMviupTCqqV28jvIu/sxKN91oJzLJN2BWqWR2gDMcEFjKu:3bxj3+LMfA26vI8sxG91obN2B7WFpu
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=7112DAB97A3D22D5FBB80623C6C1D7003A1D43F4
PEiD  : -
packers (F-Prot): NSIS
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file