| עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File ri.exe received on 05.07.2008 10:36:30 (CET)
Current status: finished
Result: 7/30 (23.33%)
Antivirus Version Last Update Result
AhnLab-V3 2008.5.3.0 2008.05.06 -
AntiVir 7.8.0.11 2008.05.07 TR/Dropper.Gen
Authentium 4.93.8 2008.05.07 -
Avast 4.8.1169.0 2008.05.06 -
AVG 7.5.0.516 2008.05.06 -
BitDefender 7.2 2008.05.07 -
CAT-QuickHeal 9.50 2008.05.06 -
ClamAV 0.92.1 2008.05.07 -
DrWeb 4.44.0.09170 2008.05.07 Trojan.MulDrop.origin
eTrust-Vet 31.4.5766 2008.05.07 -
Ewido 4.0 2008.05.06 -
F-Prot 4.4.2.54 2008.05.06 -
F-Secure 6.70.13260.0 2008.05.07 Trojan.Win32.Agent.lpv
Fortinet 3.14.0.0 2008.05.07 -
Ikarus T3.1.1.26 2008.05.07 Trojan-Dropper
Kaspersky 7.0.0.125 2008.05.07 Trojan.Win32.Agent.lpv
McAfee 5289 2008.05.06 -
Microsoft 1.3408 2008.05.07 -
NOD32v2 3080 2008.05.06 -
Norman 5.80.02 2008.05.06 -
Panda 9.0.0.4 2008.05.06 Suspicious file
Prevx1 V2 2008.05.07 -
Rising 20.43.12.00 2008.05.07 -
Sophos 4.29.0 2008.05.07 -
Sunbelt 3.0.1097.0 2008.05.07 -
Symantec 10 2008.05.07 -
TheHacker 6.2.92.302 2008.05.07 -
VBA32 3.12.6.5 2008.05.06 -
VirusBuster 4.3.26:9 2008.05.06 -
Webwasher-Gateway 6.6.2 2008.05.07 Trojan.Dropper.Gen
Additional information
File size: 38400 bytes
MD5...: 4fae9734c0b06526fcf6399a96607c04
SHA1..: 6332f298a727e0219cf0f6f1a62a81061c9ebb5c
SHA256: fa79ad23ccb701529b90f77c2be94f2bc8af6106ff0978206d93735d35658caa
SHA512: f8deb2f8424d19ffe12076ee2a7ee1b6f7cbdb9473cc0ed72784ee3fcbdf17d9
020f22b8d6b460b74bf1fe03ad4773e002ef4f57093f75951bdf4799d142f644
PEiD..: Crypto-Lock v2.02 (Eng) -> Ryan Thian
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x410e90
timedatestamp.....: 0x48149298 (Sun Apr 27 14:50:00 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x8000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x9000 0x8000 0x8000 7.75 d295f00356faa4d8eeb7bf944546bb9c
.rsrc 0x11000 0x1000 0x200 2.47 fbf58b595abea1852cd40113562845d5

( 3 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> ADVAPI32.dll: RegCloseKey
> MSVCRT.dll: memcpy

( 0 exports )
packers: UPX
packers: UPX
packers: UPX

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file