Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File sislsvdv.wa received on 2009.03.26 18:49:45 (UTC)
Current status: finished
Result: 38/40 (95.00%)
Antivirus Version Last Update Result
a-squared 4.0.0.101 2009.03.26 Worm.Win32.Conficker!IK
AhnLab-V3 5.0.0.2 2009.03.26 Win32/Kido.worm.164737
AntiVir 7.9.0.129 2009.03.26 Worm/Kido.GF
Antiy-AVL 2.0.3.1 2009.03.26 -
Authentium 5.1.2.4 2009.03.26 W32/Conficker!Generic
Avast 4.8.1335.0 2009.03.25 Win32:Confi
AVG 8.5.0.283 2009.03.26 Worm/Downadup
BitDefender 7.2 2009.03.26 Worm.Generic.42121
CAT-QuickHeal 10.00 2009.03.26 Win32.Net-Worm.Kido.ih.3.Pack
ClamAV 0.94.1 2009.03.26 Trojan.Dropper-18535
Comodo 1085 2009.03.26 NetWorm.Win32.Kido.gf
DrWeb 4.44.0.09170 2009.03.26 Win32.HLLW.Shadow.based
eSafe 7.0.17.0 2009.03.26 Win32.Banker
eTrust-Vet 31.6.6418 2009.03.26 Win32/Conficker
F-Prot 4.4.4.56 2009.03.26 W32/Conficker!Generic
F-Secure 8.0.14470.0 2009.03.26 Worm:W32/Downadup.gen!A
Fortinet 3.117.0.0 2009.03.26 W32/Conficker.A!worm
GData 19 2009.03.26 Worm.Generic.42121
Ikarus T3.1.1.48.0 2009.03.26 Worm.Win32.Conficker
K7AntiVirus 7.10.682 2009.03.26 Net-Worm.Win32.Downadup.gf
Kaspersky 7.0.0.125 2009.03.26 Net-Worm.Win32.Kido.ih
McAfee 5565 2009.03.26 W32/Conficker.worm.gen.a
McAfee+Artemis 5565 2009.03.26 Generic!Artemis
McAfee-GW-Edition 6.7.6 2009.03.26 Worm.Kido.GF
Microsoft 1.4502 2009.03.26 Worm:Win32/Conficker.C
NOD32 3966 2009.03.26 a variant of Win32/Conficker.AE
Norman 6.00.06 2009.03.26 W32/FakeAV.BJZ
nProtect 2009.1.8.0 2009.03.26 Worm/W32.Kido.164737
Panda 10.0.0.10 2009.03.26 W32/Conficker.C.worm
PCTools 4.4.2.0 2009.03.26 -
Prevx1 V2 2009.03.26 High Risk Worm
Rising 21.22.32.00 2009.03.26 Hack.Exploit.Win32.MS08-067.jx
Sophos 4.40.0 2009.03.26 Mal/Conficker-A
Sunbelt 3.2.1858.2 2009.03.26 Net-Worm.Win32.Kido.gf
Symantec 1.4.4.12 2009.03.26 W32.Downadup.B
TheHacker 6.3.3.7.292 2009.03.26 W32/Kido.gf
TrendMicro 8.700.0.1004 2009.03.26 WORM_DOWNAD.AD
VBA32 3.12.10.1 2009.03.26 Worm.Win32.kido.106
ViRobot 2009.3.26.1664 2009.03.26 Worm.Win32.Conficker.164737
VirusBuster 4.6.5.0 2009.03.26 Trojan.Conficker.Gen!Pac
Additional information
File size: 164737 bytes
MD5...: ef87b673c8e3b77bdf2342e42e1b5f0c
SHA1..: 417935c909a38d65b28c39f5e5455852ab739c2c
SHA256: 1ac7186c23c81e169857232d1c1f5588babd4914d81d8b0d776a45fe21b987c0
SHA512: c56e7f532fdccffac44c39c7f97fe1e992a4a8cc91f870b4549c73f42a31ae32
f7d791fec822133015ed27978635d4d2b108120a95e5c1486308b00c25fba3b7
ssdeep: 3072:1cWLB87FRWJp6J2ByXt4MnWc43e7BvGqhA92SSxJl5ghZlWr6vf:1cWe7mJ
px80EBvGuA92nghWr6vf
PEiD..: -
TrID..: File type identification
UPX compressed Win32 Executable (38.5%)
Win32 EXE Yoda's Crypter (33.5%)
Win32 Executable Generic (10.7%)
Win32 Dynamic Link Library (generic) (9.5%)
Clipper DOS Executable (2.5%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x19100
timedatestamp.....: 0x3c29b8cd (Wed Dec 26 11:47:25 2001)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x4000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x5000 0x15000 0x14400 7.80 1b39fbd672a4de7e90c9b13e343bd63d
UPX2 0x1a000 0x1000 0x200 3.74 0f81fa29189dea7e2e203ab19f8a0686

( 7 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree
> ADVAPI32.dll: IsValidSid
> GDI32.dll: GetROP2
> MSVCRT.dll: div
> ole32.dll: CoDosDateTimeToFileTime
> SHELL32.dll: -
> USER32.dll: IsMenu

( 0 exports )
RDS...: NSRL Reference Data Set
-
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX
packers (Authentium): UPX
packers (Avast): UPX
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=D344F3BB81EED8A6837F02B51EBF8A000807A052

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file