Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File theme_html.exe received on 2009.11.01 02:34:42 (UTC)
Current status: finished
Result: 20/40 (50.00%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.10.31 Trojan-Spy.Win32.Zbot!IK
AhnLab-V3 5.0.0.2 2009.10.30 -
AntiVir 7.9.1.53 2009.10.30 TR/Crypt.ZPACK.Gen
Antiy-AVL 2.0.3.7 2009.10.30 -
Authentium 5.1.2.4 2009.10.31 -
Avast 4.8.1351.0 2009.10.31 -
AVG 8.5.0.423 2009.11.01 Win32/Cryptor
BitDefender 7.2 2009.11.01 Gen:Trojan.Heur.Zbot.fmW@cedFm6f
CAT-QuickHeal 10.00 2009.10.31 -
ClamAV 0.94.1 2009.11.01 -
Comodo 2796 2009.10.31 -
DrWeb 5.0.0.12182 2009.11.01 -
eTrust-Vet 35.1.7094 2009.10.30 -
F-Prot 4.5.1.85 2009.10.31 -
F-Secure 9.0.15370.0 2009.10.30 Gen:Trojan.Heur.Zbot.fmW@cedFm6f
Fortinet 3.120.0.0 2009.10.31 -
GData 19 2009.11.01 Gen:Trojan.Heur.Zbot.fmW@cedFm6f
Ikarus T3.1.1.72.0 2009.10.31 Trojan-Spy.Win32.Zbot
Jiangmin 11.0.800 2009.10.31 -
K7AntiVirus 7.10.885 2009.10.31 -
Kaspersky 7.0.0.125 2009.11.01 Trojan-Spy.Win32.Zbot.gen
McAfee 5788 2009.10.31 -
McAfee+Artemis 5788 2009.10.31 Artemis!942D928A7C12
McAfee-GW-Edition 6.8.5 2009.10.31 Heuristic.BehavesLike.Win32.Downloader.H
Microsoft 1.5202 2009.10.31 PWS:Win32/Zbot.gen!R
NOD32 4561 2009.10.31 a variant of Win32/Kryptik.ATQ
Norman 6.03.02 2009.10.31 W32/Zbot.DBB
nProtect 2009.1.8.0 2009.10.31 -
Panda 10.0.2.2 2009.10.31 Trj/CI.A
PCTools 7.0.3.5 2009.10.30 HeurEngine.MaliciousPacker
Prevx 3.0 2009.11.01 -
Rising 21.53.52.00 2009.10.31 -
Sophos 4.47.0 2009.11.01 Mal/Behav-353
Sunbelt 3.2.1858.2 2009.10.31 Trojan-Spy.Win32.Zbot.gen (v)
Symantec 1.4.4.12 2009.11.01 Packed.Generic.261
TheHacker 6.5.0.2.058 2009.10.31 -
TrendMicro 8.950.0.1094 2009.10.31 TSPY_ZBOT.SMO
VBA32 3.12.10.11 2009.10.30 Malware-Cryptor.Win32.Vals.21
ViRobot 2009.10.31.2015 2009.10.31 -
VirusBuster 4.6.5.0 2009.10.31 -
Additional information
File size: 83456 bytes
MD5   : 942d928a7c12b882b85759d4a7caa0b5
SHA1  : ae80d777b3cf39729951a34b227e586602e1b3de
SHA256: a22627a1dce5401ad29c1d79610e379d30fef2779f5c1e7ea552fdc8c1c983b8
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xF681
timedatestamp.....: 0x4719E761 (Sat Oct 20 13:32:49 2007)
machinetype.......: 0x14C (Intel I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x11039 0x11200 6.92 adbff65364603a6f94a92c2e0befeeb9
.rdata 0x13000 0x2C58 0x2E00 5.52 5ca75bc2f81e618f01a1ba091f68bd70
.data 0x16000 0x2039 0x200 0.83 5edf13b6605634ea60b1e71ecc97b2ce

( 2 imports )

> kernel32.dll: RemoveDirectoryA, WaitForMultipleObjects, VirtualUnlock, ContinueDebugEvent, SetSystemTime, LockFile, WriteFileEx, HeapFree, GetVersionExA, GetNumberFormatA, GetSystemDefaultLangID, ScrollConsoleScreenBufferW, GlobalReAlloc, GetProcessHeaps, CreateFileMappingW, SetComputerNameW, SetProcessPriorityBoost, lstrcpyA, GenerateConsoleCtrlEvent, GetLargestConsoleWindowSize, TransactNamedPipe, GetThreadContext, SetCalendarInfoW, EnumCalendarInfoExA, EnumResourceTypesA, CreateDirectoryExA, GetVolumeInformationW, CreateConsoleScreenBuffer, IsDBCSLeadByteEx, SizeofResource, GetProfileStringA, FatalExit, WritePrivateProfileSectionW, GetUserDefaultLCID, WinExec, VirtualProtect, SetNamedPipeHandleState, UnhandledExceptionFilter, GetCPInfo, LoadLibraryW, GetStringTypeW, GetProfileIntA, TlsSetValue, HeapCompact, VerLanguageNameA, GetLocaleInfoA, EnumResourceLanguagesW, FatalAppExitW, SetFileAttributesW, GetProcessShutdownParameters, GetComputerNameW, LocalLock, LCMapStringW, OutputDebugStringW, FindCloseChangeNotification, TerminateProcess, GetDiskFreeSpaceW, ReadConsoleOutputAttribute, WriteConsoleA, EnumSystemLocalesA, Process32Next, GetCurrentProcess, FileTimeToLocalFileTime, FatalAppExitA, GetDiskFreeSpaceA, CreatePipe, GetPrivateProfileIntW, Beep, VirtualFreeEx, CreateFiber, GetFileAttributesA, PeekConsoleInputA, UpdateResourceA, lstrcmpi, GetFullPathNameA, FindFirstChangeNotificationW, SetUnhandledExceptionFilter, GetStringTypeExA, FindAtomW, SystemTimeToTzSpecificLocalTime, OpenProcess, GetExitCodeThread, CreateProcessA, GlobalFindAtomW, WaitForSingleObjectEx, DisconnectNamedPipe, FlushInstructionCache, GetProcessWorkingSetSize, GetWriteWatch, GetSystemInfo, GetFileAttributesExW, GlobalUnfix, GetFileInformationByHandle, SetConsoleActiveScreenBuffer, SetThreadPriority, Process32First, SetProcessWorkingSetSize, GetAtomNameA, TlsFree, ResumeThread, SetHandleInformation, lstrcmpiA, FindNextFileW, EnumResourceNamesW, LocalAlloc, GetTimeZoneInformation, GetACP, SetDefaultCommConfigW, CreateFileMappingA, SetConsoleCtrlHandler, CompareStringW, GetProfileIntW, GetLastError, BuildCommDCBAndTimeoutsA, SetTimeZoneInformation, GlobalFree, FindClose, ExpandEnvironmentStringsW, GetOEMCP, FindNextFileA, SetThreadLocale, CancelIo, GlobalAlloc, FileTimeToDosDateTime, CreateMailslotW, SetThreadPriorityBoost, GlobalCompact, LocalUnlock, ReadFile, GetConsoleMode, GetShortPathNameW, RtlFillMemory, GetLogicalDriveStringsW, LocalHandle, GetStartupInfoA, GetProcessAffinityMask, ResetEvent, lstrcmp, lstrcpynW, WaitForMultipleObjectsEx, GetCommandLineA, SetDefaultCommConfigA, WaitForSingleObject, CreateMutexA, SetConsoleOutputCP, IsValidLocale, EnumTimeFormatsA, GetPrivateProfileStringW, GlobalHandle, TerminateThread, BeginUpdateResourceA, CompareFileTime, CreateSemaphoreW, GetDefaultCommConfigA, Heap32ListFirst, GetPriorityClass, FindFirstFileExW, GetLongPathNameW, GetTimeFormatA, DebugBreak, WritePrivateProfileStringA, SetEndOfFile, SetFilePointer, ReadFileScatter, WriteConsoleW, SetHandleCount, GetDriveTypeA, GetTempPathW, WritePrivateProfileStructA, SetFileTime, GetDefaultCommConfigW, WaitForDebugEvent, SetLocaleInfoA, SetThreadIdealProcessor, DeleteFileA, GetAtomNameW, WaitNamedPipeW, IsBadHugeReadPtr, CopyFileExW, EndUpdateResourceA, OutputDebugStringA, GetThreadSelectorEntry, EnumCalendarInfoW, GlobalUnWire, CreateIoCompletionPort, VirtualQuery, GetProcessVersion, DuplicateHandle, CreateDirectoryExW, FindResourceW, VirtualQueryEx, CallNamedPipeW, GetSystemPowerStatus, lstrcatW, GetStringTypeExW, GetProfileSectionW, HeapValidate, ReadConsoleW, VirtualAlloc, GetPrivateProfileIntA
> user32.dll: CallMsgFilterW, IsMenu, SetThreadDesktop, GetInputDesktop, LockWindowUpdate, DdeClientTransaction, WinHelpW, DdeAccessData, DestroyCursor, DestroyCaret, SetDeskWallpaper, SetUserObjectInformationW, CloseClipboard, PostQuitMessage, DlgDirSelectExA, DragObject, GetMenuContextHelpId, InvalidateRect, SwapMouseButton, GetKeyboardLayoutList, CheckMenuItem, CascadeWindows, EmptyClipboard, ReleaseCapture, SetClassWord, MonitorFromRect, CreateMDIWindowW, GetKeyNameTextA, SetPropW, TranslateAcceleratorA, DlgDirSelectExW, SendIMEMessageExW, ShowCursor, MonitorFromWindow, SetFocus, CharLowerBuffA, GetQueueStatus, GetClassNameW, EnumWindowStationsA, DdeUninitialize, CharUpperW, IsCharAlphaNumericW, GetWindowThreadProcessId, SetWindowTextA, GetMenuCheckMarkDimensions, DefDlgProcA, RegisterClipboardFormatA, GetKeyboardLayoutNameA, SetWinEventHook, TranslateMessage, OpenIcon, IsIconic, EnumDisplayMonitors, ChangeMenuW, GetMonitorInfoW, SendIMEMessageExA, OpenDesktopA, LoadCursorFromFileW, MessageBeep, TrackPopupMenu, DrawMenuBar, OpenWindowStationA, InternalGetWindowText, CloseDesktop, SendInput, ImpersonateDdeClientWindow, LoadImageW, GetAsyncKeyState, CharLowerW, DrawIconEx, CreatePopupMenu, GetGUIThreadInfo, GetForegroundWindow, GetThreadDesktop, GetClipboardSequenceNumber, BeginDeferWindowPos, EnumWindowStationsW, FindWindowExW, PostMessageW, VkKeyScanA, CharUpperA, ToUnicode, SetScrollRange, SetTimer, SetDlgItemTextW, ExitWindowsEx, CloseWindowStation, DlgDirListComboBoxW, GetParent, GetProcessDefaultLayout, DestroyIcon, GetKBCodePage, ShowWindow, VkKeyScanW, EnumChildWindows, GetAltTabInfo, ClientToScreen, LookupIconIdFromDirectoryEx, RegisterClassA, SetWindowPlacement, DdeNameService, DdeCreateDataHandle, SetCaretPos, CopyIcon, DispatchMessageA, WindowFromDC, GetWindowModuleFileNameA, LoadKeyboardLayoutA, CharPrevA, OemToCharA, EnumPropsW, SetCapture, LookupIconIdFromDirectory, ToAsciiEx, GetActiveWindow, RegisterDeviceNotificationA, EnumDisplayDevicesA, EnableMenuItem, SetUserObjectInformationA, RegisterHotKey, DdeFreeStringHandle, EndPaint, GetUpdateRgn, SetScrollInfo, MessageBoxExA, GetScrollPos, CopyImage, MapVirtualKeyW, RemovePropW, MapVirtualKeyA, GetMonitorInfoA, ChildWindowFromPoint, IsWindowEnabled, GetProcessWindowStation, DefFrameProcW, SetCaretBlinkTime, GetClassLongA, PackDDElParam, DrawEdge, DlgDirListA, OpenWindowStationW, CascadeChildWindows, ToUnicodeEx, CreateDialogParamA, GetMenuBarInfo, GrayStringW, SendMessageTimeoutA, DialogBoxIndirectParamA, DrawCaption, GetClassLongW, DrawIcon, GetSysColorBrush, GetDlgCtrlID, GetWindowLongA, DialogBoxIndirectParamW, SendNotifyMessageA, VkKeyScanExW, GetMenuItemInfoA, GetKeyboardType, IsDlgButtonChecked, BlockInput, LoadCursorA, LoadMenuIndirectA, ArrangeIconicWindows, GetMenuInfo, GetMessageW, SendMessageW, DdeQueryStringW, MessageBoxW, GetMenuItemRect, GetClassWord, RemovePropA, CreateIconFromResourceEx, WINNLSEnableIME, DrawTextExA, SendMessageTimeoutW, ChildWindowFromPointEx, UnhookWindowsHookEx, SetClassLongW, DefWindowProcW, ChangeDisplaySettingsA, CreateIconFromResource, GetMenuItemID, SystemParametersInfoA, CreateCaret, MsgWaitForMultipleObjectsEx, GetWindowPlacement, GetCursorInfo, WaitMessage, SetDoubleClickTime, IsWindowUnicode, GetCaretBlinkTime, LoadBitmapW, IsCharAlphaNumericA, DdeSetUserHandle, FillRect, CountClipboardFormats, UnpackDDElParam, SendDlgItemMessageW, ReleaseDC, RegisterClassW, OemToCharBuffA, CharPrevExA, CharToOemBuffA, DdeInitializeA, SendMessageA, WinHelpA, SetMenuItemInfoW, IsClipboardFormatAvailable, GetClipCursor, SwitchDesktop

( 0 exports )
TrID  : File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=942d928a7c12b882b85759d4a7caa0b5
ssdeep: 1536:5qYKrBulfFRiyEHQrs/pFzpQYDyqL3PiM/O3boScYTo3q3Ivm6C5:cLVuBSes/p9pQrqL3m3U6To3q3Ivm6A
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=8CFAD3BF004B906C4692010230991100552412EF
PEiD  : -
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file