Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File postcard.exe received on 2008.12.18 18:12:21 (UTC)
Current status: finished
Result: 23/38 (60.53%)
Antivirus Version Last Update Result
AhnLab-V3 2008.12.19.0 2008.12.18 -
AntiVir 7.9.0.45 2008.12.18 BDS/Zapchast.PI
Authentium 5.1.0.4 2008.12.18 REG/Zapchast.H
Avast 4.8.1281.0 2008.12.18 VBS:Malware-gen
AVG 8.0.0.199 2008.12.18 BackDoor.Generic_c.CFI
BitDefender 7.2 2008.12.18 Dropped:Backdoor.Zapchast.PI
CAT-QuickHeal 10.00 2008.12.18 -
ClamAV 0.94.1 2008.12.18 Trojan.IRC.Zapchast-16
Comodo 771 2008.12.17 -
DrWeb 4.44.0.09170 2008.12.18 -
eSafe 7.0.17.0 2008.12.18 -
eTrust-Vet 31.6.6267 2008.12.18 -
Ewido 4.0 2008.12.18 -
F-Prot 4.4.4.56 2008.12.18 REG/Zapchast.H
F-Secure 8.0.14332.0 2008.12.18 Client-IRC.Win32.mIRC.603
Fortinet 3.117.0.0 2008.12.18 -
GData 19 2008.12.18 Dropped:Backdoor.Zapchast.PI
Ikarus T3.1.1.45.0 2008.12.18 -
K7AntiVirus 7.10.557 2008.12.18 Non-Virus:Client-IRC.Win32.mIRC.603
Kaspersky 7.0.0.125 2008.12.18 not-a-virus:Client-IRC.Win32.mIRC.603
McAfee 5468 2008.12.18 potentially unwanted program IRC/Client
McAfee+Artemis 5468 2008.12.18 potentially unwanted program IRC/Client
Microsoft 1.4205 2008.12.18 Backdoor:Win32/IRCFlood
NOD32 3703 2008.12.18 REG/RunKeys.NAA
Norman 5.80.02 2008.12.18 -
Panda 9.0.0.4 2008.12.18 BAT/Autorun.TA
PCTools 4.4.2.0 2008.12.18 Trojan.mIRC-Based.AM
Prevx1 V2 2008.12.18 -
Rising 21.08.32.00 2008.12.18 -
SecureWeb-Gateway 6.7.6 2008.12.18 -
Sophos 4.37.0 2008.12.18 Mal/Zapchas-A
Sunbelt 3.2.1801.2 2008.12.11 mIRC based
Symantec 10 2008.12.18 Backdoor.IRC.Aladinz
TheHacker 6.3.1.4.191 2008.12.17 -
TrendMicro 8.700.0.1004 2008.12.18 REG_ZAPCHAST.ED
VBA32 3.12.8.10 2008.12.18 BackDoor.IRC.based
ViRobot 2008.12.18.1525 2008.12.18 -
VirusBuster 4.5.11.0 2008.12.18 Trojan.mIRC-Based.AM
Additional information
File size: 1281843 bytes
MD5...: 737e10be307601f22a491fd76798cd21
SHA1..: 9523bccfc96fd77228cb6b28dc06466ca2dbb76e
SHA256: ed94789d28aebf7ebf3ca87b4896260ce5e432a68696833df00f2a6652b700af
SHA512: 9eb79c54346f11fdf81fa8354b8202e4e8b7395efc725931418fbc3318cedcc4
080f18a4cc4a5716c22f70e0c15311b126523e78a636fcdd2e984422eae09d54
ssdeep: 24576:1nJ2kPyZvjXamZ4Nj9KRpRoUWmmKKR+Pz3VZcwZ60PX0wS7fLIugqOCpLv
:1J2hZbXnSNj4fWm/KUPDVZnZfPtELPg6
PEiD..: -
TrID..: File type identification
WinRAR Self Extracting archive (96.2%)
Win32 Executable Generic (1.5%)
Win32 Dynamic Link Library (generic) (1.4%)
Generic Win/DOS Executable (0.3%)
DOS Executable Generic (0.3%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x401000
timedatestamp.....: 0x43463a52 (Fri Oct 07 09:05:22 2005)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x13000 0x12600 6.46 bcefd13d879b5aa1628d5731462b1935
.data 0x14000 0x7000 0xa00 4.73 0eb9af4768d13f3fe805922a21fcbf55
.idata 0x1b000 0x1000 0x1000 5.02 7f9440e32acb299f3bda96288136b63a
.rsrc 0x1c000 0x46ce8 0x46e00 6.23 fd5ee05e6e48c036136c72401a64ebfa

( 8 imports )
> ADVAPI32.DLL: AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA, SetFileSecurityA, SetFileSecurityW
> KERNEL32.DLL: CloseHandle, CompareStringA, CreateDirectoryA, CreateDirectoryW, CreateFileA, CreateFileW, DeleteFileA, DeleteFileW, DosDateTimeToFileTime, ExitProcess, ExpandEnvironmentStringsA, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, FindFirstFileA, FindFirstFileW, FindNextFileA, FindNextFileW, FindResourceA, FreeLibrary, GetCPInfo, GetCommandLineA, GetCurrentDirectoryA, GetCurrentProcess, GetDateFormatA, GetFileAttributesA, GetFileAttributesW, GetFileType, GetFullPathNameA, GetLastError, GetLocaleInfoA, GetModuleFileNameA, GetModuleHandleA, GetNumberFormatA, GetProcAddress, GetProcessHeap, GetStdHandle, GetTempPathA, GetTickCount, GetTimeFormatA, GetVersionExA, GlobalAlloc, HeapAlloc, HeapFree, HeapReAlloc, IsDBCSLeadByte, LoadLibraryA, LocalFileTimeToFileTime, MoveFileA, MoveFileExA, MultiByteToWideChar, ReadFile, SetCurrentDirectoryA, SetEndOfFile, SetEnvironmentVariableA, SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFileTime, SetLastError, Sleep, SystemTimeToFileTime, WaitForSingleObject, WideCharToMultiByte, WriteFile, lstrcmpiA, lstrlenA
> COMCTL32.DLL: -
> COMDLG32.DLL: CommDlgExtendedError, GetOpenFileNameA
> GDI32.DLL: DeleteObject
> SHELL32.DLL: SHBrowseForFolderA, SHChangeNotify, SHFileOperationA, SHGetFileInfoA, SHGetMalloc, SHGetSpecialFolderLocation, ShellExecuteExA, SHGetPathFromIDListA
> USER32.DLL: CharToOemBuffA, CharUpperA, CopyRect, CreateWindowExA, DefWindowProcA, DestroyIcon, DestroyWindow, DialogBoxParamA, DispatchMessageA, EnableWindow, EndDialog, FindWindowExA, GetClassNameA, GetClientRect, GetDlgItem, GetDlgItemTextA, GetMessageA, GetParent, GetSysColor, GetSystemMetrics, GetWindow, GetWindowLongA, GetWindowRect, GetWindowTextA, IsWindow, IsWindowVisible, LoadBitmapA, LoadCursorA, LoadIconA, LoadStringA, MapWindowPoints, MessageBoxA, OemToCharA, OemToCharBuffA, PeekMessageA, PostMessageA, RegisterClassExA, SendDlgItemMessageA, SendMessageA, SetDlgItemTextA, SetFocus, SetMenu, SetWindowLongA, SetWindowPos, SetWindowTextA, ShowWindow, TranslateMessage, UpdateWindow, WaitForInputIdle, wsprintfA, wvsprintfA
> OLE32.DLL: CLSIDFromString, CoCreateInstance, CreateStreamOnHGlobal, OleInitialize, OleUninitialize

( 0 exports )
packers (F-Prot): RAR, Unicode
packers (Authentium): RAR, Unicode, RAR, RAR
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=737e10be307601f22a491fd76798cd21

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file