Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File rm.exe received on 2008.06.24 13:01:05 (UTC)
Current status: finished
Result: 25/33 (75.76%)
Antivirus Version Last Update Result
AhnLab-V3 2008.6.24.0 2008.06.24 Win-Trojan/Mapler.122880
AntiVir 7.8.0.59 2008.06.24 TR/PSW.Mapler.AC
Authentium 5.1.0.4 2008.06.24 W32/OnlineGames.B.gen!Eldorado
Avast 4.8.1195.0 2008.06.23 Win32:Mapler-G
AVG 7.5.0.516 2008.06.24 Generic10.TBK
BitDefender 7.2 2008.06.24 Trojan.PWS.Onlinegames.ZBJ
CAT-QuickHeal 9.50 2008.06.23 TrojanPSW.Mapler.ae
ClamAV 0.93.1 2008.06.24 -
DrWeb 4.44.0.09170 2008.06.24 Trojan.PWS.Gamania.9824
eSafe 7.0.17.0 2008.06.24 Win32.Mapler.ao
eTrust-Vet 31.6.5900 2008.06.24 Win32/Lineage!generic
Ewido 4.0 2008.06.24 Trojan.Mapler.ae
F-Prot 4.4.4.56 2008.06.23 W32/OnlineGames.B.gen!Eldorado
F-Secure 7.60.13501.0 2008.06.20 Trojan-PSW.Win32.Mapler.ae
Fortinet 3.14.0.0 2008.06.24 W32/Mapler.AE!tr.pws
GData 2.0.7306.1023 2008.06.24 Trojan-PSW.Win32.Mapler.ae
Ikarus T3.1.1.26.0 2008.06.24 Backdoor.Win32.HacDef.073.B
Kaspersky 7.0.0.125 2008.06.24 Trojan-PSW.Win32.Mapler.ae
McAfee 5323 2008.06.23 -
Microsoft None 2008.06.24 -
NOD32v2 3213 2008.06.24 -
Norman 5.80.02 2008.06.23 W32/Mapler.BT
Panda 9.0.0.4 2008.06.23 Suspicious file
Prevx1 V2 2008.06.24 -
Rising 20.50.10.00 2008.06.24 Trojan.Win32.Agent.zri
Sophos 4.30.0 2008.06.24 -
Sunbelt 3.0.1153.1 2008.06.15 Trojan-PSW.Win32.Nilage.o
Symantec 10 2008.06.24 -
TheHacker 6.2.92.359 2008.06.24 -
TrendMicro 8.700.0.1004 2008.06.24 TSPY_MAPLER.AH
VBA32 3.12.6.8 2008.06.23 Trojan-PSW.Win32.Mapler.ae
VirusBuster 4.5.11.0 2008.06.23 Trojan.PWS.Nilage.Gen.3
Webwasher-Gateway 6.6.2 2008.06.24 Trojan.PSW.Mapler.AC
Additional information
File size: 118784 bytes
MD5...: ff214049c594f0b92ddd4b9337a7408a
SHA1..: 86164d9cd869ae4a67eac48a03a1364e87b9189b
SHA256: 8296a28123c25d8b402b8be74e53ecaeda2952f24bca104f6ca1ab9b6d31a11e
SHA512: 3dfe531faa8c392de4de0e240e1378979981ded16010da8b96345443f37a2803
cd05f8f0388c388fe951c7b7fb74b709b04d61745d219c2cb63f2a1f5479680b
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x40598c
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)

( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0x5040 0x5200 6.47 142f5dd4214b79e5799afb72989c0085
DATA 0x7000 0x4b0 0x600 4.48 afcb79443260a01cc99cc5ea8a20110a
BSS 0x8000 0x759 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0x9000 0x62c 0x800 3.76 16ec57644243625350b25b1a362684a7
.tls 0xa000 0x8 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 0xb000 0x18 0x200 0.20 7efef057f2f391b4d0bc263815821c3e
.reloc 0xc000 0x54c 0x600 6.22 d7291496ebcea894c1e6ddd929dd87f3
.rsrc 0xd000 0x16400 0x16400 6.50 be8ed3b487526dd76bedcf163deb3dd3

( 7 imports )
> kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetVersion, GetCurrentThreadId, GetThreadLocale, GetStartupInfoA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCommandLineA, FreeLibrary, ExitProcess, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileA, CloseHandle
> user32.dll: GetKeyboardType, MessageBoxA, CharNextA
> advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey
> kernel32.dll: TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA
> advapi32.dll: RegSetValueExA, RegCreateKeyExA, RegCloseKey
> kernel32.dll: SizeofResource, SetEndOfFile, OpenMutexA, MapViewOfFile, LockResource, LoadResource, LoadLibraryA, GetWindowsDirectoryA, GetProcAddress, FreeResource, FreeLibrary, FindResourceA, FindFirstFileA, FindClose, FileTimeToLocalFileTime, FileTimeToDosDateTime, CreateMutexA, CreateFileA
> user32.dll: PostMessageA

( 0 exports )

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file