Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File smss.exe received on 2009.01.08 11:23:00 (UTC)
Current status: finished
Result: 10/38 (26.32%)
Antivirus Version Last Update Result
a-squared 4.0.0.73 2009.01.08 -
AhnLab-V3 2009.1.8.0 2009.01.08 -
AntiVir 7.9.0.45 2009.01.08 TR/Dropper.Gen
Authentium 5.1.0.4 2009.01.08 -
Avast 4.8.1281.0 2009.01.07 -
AVG 8.0.0.199 2009.01.08 -
BitDefender 7.2 2009.01.08 -
CAT-QuickHeal 10.00 2009.01.08 -
ClamAV 0.94.1 2009.01.08 -
Comodo 891 2009.01.07 -
DrWeb 4.44.0.09170 2009.01.08 Trojan.PWS.Wow.993
eSafe 7.0.17.0 2009.01.06 Suspicious File
eTrust-Vet 31.6.6296 2009.01.07 -
F-Prot 4.4.4.56 2009.01.08 -
F-Secure 8.0.14470.0 2009.01.08 -
Fortinet 3.117.0.0 2009.01.08 -
GData 19 2009.01.08 -
Ikarus T3.1.1.45.0 2009.01.08 -
K7AntiVirus 7.10.582 2009.01.08 -
Kaspersky 7.0.0.125 2009.01.08 Trojan-GameThief.Win32.WOW.edw
McAfee 5488 2009.01.07 -
McAfee+Artemis 5488 2009.01.07 Generic!Artemis
Microsoft 1.4205 2009.01.08 -
NOD32 3750 2009.01.08 Win32/PSW.WOW.NHG
Norman 5.99.02 2009.01.08 -
Panda 9.4.3.3 2009.01.08 -
PCTools 4.4.2.0 2009.01.07 -
Prevx1 V2 2009.01.08 -
Rising 21.11.32.00 2009.01.08 Trojan.PSW.Win32.GameOL.too
SecureWeb-Gateway 6.7.6 2009.01.08 Trojan.Dropper.Gen
Sophos 4.37.0 2009.01.08 -
Sunbelt 3.2.1809.2 2008.12.22 -
Symantec 10 2009.01.08 -
TheHacker 6.3.1.4.212 2009.01.08 -
TrendMicro 8.700.0.1004 2009.01.08 PAK_Generic.001
VBA32 3.12.8.10 2009.01.07 -
ViRobot 2009.1.8.1550 2009.01.08 Trojan.Win32.PSWWow.26624.B
VirusBuster 4.5.11.0 2009.01.07 -
Additional information
File size: 26624 bytes
MD5...: 8f9e856344470e505b22c2738c5512e2
SHA1..: c36acbfb67fde465f887c902f2c9fb5297b41917
SHA256: dff60f3c362934de8ac2aabc32c6928fa59ebaf5c6c87e3e45455e201320726e
SHA512: e8e5ef8697d7262e4e4dc5656442077d30dd1270a533ccb92fab1ebbf6eb15cc
984d0b58048df50b21e12d707586a3c4df166ddb02bb6199867294dc8f38198b
ssdeep: 768:JTzN/cFx++bLVIYhS2nR8MqG5+ymvyaw80R/gBl:hNEq0VdM2KMqG5+yVaw8
0RY
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
TrID..: File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x413070
timedatestamp.....: 0x49643b2e (Wed Jan 07 05:18:38 2009)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0xc000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0xd000 0x7000 0x6200 7.90 fd232f2e58442cca195a9f3f4c593d0c
.rsrc 0x14000 0x1000 0x200 3.57 94a100192871e2a5fce26e4f9f83f46c

( 6 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, ExitProcess
> ADVAPI32.dll: GetAce
> MSVCRT.dll: rand
> NETAPI32.dll: NetApiBufferFree
> SHLWAPI.dll: SHDeleteKeyA
> USER32.dll: wsprintfA

( 0 exports )
packers (F-Prot): UPX
packers (Kaspersky): PE_Patch.UPX, UPX

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file