Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File ba.exe received on 2009.10.26 03:13:00 (UTC)
Current status: finished
Result: 21/41 (51.22%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.10.26 Trojan.Win32.StartPage!IK
AhnLab-V3 5.0.0.2 2009.10.23 -
AntiVir 7.9.1.44 2009.10.25 TR/Crypt.XDR.Gen
Antiy-AVL 2.0.3.7 2009.10.23 -
Authentium 5.1.2.4 2009.10.25 -
Avast 4.8.1351.0 2009.10.25 Win32:Trojan-gen
AVG 8.5.0.423 2009.10.25 BackDoor.Generic12.BWY
BitDefender 7.2 2009.10.26 Gen:Trojan.Heur.bmKfITyIfghb
CAT-QuickHeal 10.00 2009.10.24 (Suspicious) - DNAScan
ClamAV 0.94.1 2009.10.26 -
Comodo 2732 2009.10.26 -
DrWeb 5.0.0.12182 2009.10.26 Trojan.Siggen.564
eSafe 7.0.17.0 2009.10.25 Suspicious File
eTrust-Vet 35.1.7082 2009.10.23 -
F-Prot 4.5.1.85 2009.10.25 -
F-Secure 9.0.15370.0 2009.10.22 Gen:Trojan.Heur.bmKfITyIfghb
Fortinet 3.120.0.0 2009.10.26 -
GData 19 2009.10.26 Gen:Trojan.Heur.bmKfITyIfghb
Ikarus T3.1.1.72.0 2009.10.26 Trojan.Win32.StartPage
Jiangmin 11.0.800 2009.10.26 -
K7AntiVirus 7.10.879 2009.10.24 -
Kaspersky 7.0.0.125 2009.10.26 Backdoor.Win32.Wuca.fy
McAfee 5782 2009.10.25 Generic Dropper.lo
McAfee+Artemis 5782 2009.10.25 Artemis!A0308559B25C
McAfee-GW-Edition 6.8.5 2009.10.26 Heuristic.BehavesLike.Win32.Downloader.B
Microsoft 1.5202 2009.10.25 TrojanDropper:Win32/Kufgal.A
NOD32 4541 2009.10.25 a variant of Win32/TrojanDownloader.Small.ORD
Norman 6.03.02 2009.10.23 -
nProtect 2009.1.8.0 2009.10.26 -
Panda 10.0.2.2 2009.10.25 Trj/CI.A
PCTools 4.4.2.0 2009.10.19 -
Prevx 3.0 2009.10.26 High Risk Worm
Rising 21.53.00.00 2009.10.26 -
Sophos 4.46.0 2009.10.26 Troj/PWS-AXY
Sunbelt 3.2.1858.2 2009.10.25 -
Symantec 1.4.4.12 2009.10.26 Trojan Horse
TheHacker 6.5.0.2.053 2009.10.24 -
TrendMicro 8.950.0.1094 2009.10.25 -
VBA32 3.12.10.11 2009.10.23 -
ViRobot 2009.10.26.2004 2009.10.26 -
VirusBuster 4.6.5.0 2009.10.25 -
Additional information
File size: 22528 bytes
MD5   : a0308559b25c5c578751b09942de6f1c
SHA1  : 21896f4d16d59568655af7f69251602443e14475
SHA256: 698d7015b2a7c3cb236b0fadda258681b76f87a69b2db4eb53cda4f90e352d6a
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xBAB0
timedatestamp.....: 0x4AE44FB2 (Sun Oct 25 14:16:34 2009)
machinetype.......: 0x14C (Intel I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0x6000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
DATA 0x7000 0x5000 0x4E00 7.73 65b4d1c79295d3531aad85bce5c2b418
.rsrc 0xC000 0x1000 0x600 3.25 7bd42aacbdd5303c64bb25f8ecd28b65

( 5 imports )

> advapi32.dll: RegOpenKeyA
> kernel32.dll: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> shell32.dll: ShellExecuteA
> user32.dll: MessageBoxA
> ws2_32.dll: -

( 0 exports )
TrID  : File type identification
Win32 EXE Yoda's Crypter (56.9%)
Win32 Executable Generic (18.2%)
Win32 Dynamic Link Library (generic) (16.2%)
Generic Win/DOS Executable (4.2%)
DOS Executable Generic (4.2%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=a0308559b25c5c578751b09942de6f1c
ssdeep: 384:ikZxZOOC2hKCtkntcGbmC7mY7cObCmacZqyz+6bGzsNwgk2h1u//brS14kyZT:ikrAOC2inWGbp7hCEdGMwEh1u/TRkyZ
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=ACA3A1D900DA227E589900B237A477006D85EFC6
PEiD  : -
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file