Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File MGA_crack.exe received on 2009.10.28 05:40:22 (UTC)
Current status: finished
Result: 21/41 (51.22%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.10.28 -
AhnLab-V3 5.0.0.2 2009.10.27 -
AntiVir 7.9.1.44 2009.10.27 HEUR/Crypted
Antiy-AVL 2.0.3.7 2009.10.27 -
Authentium 5.1.2.4 2009.10.28 W32/Backdoor2.ELUF
Avast 4.8.1351.0 2009.10.27 -
AVG 8.5.0.423 2009.10.27 -
BitDefender 7.2 2009.10.28 -
CAT-QuickHeal 10.00 2009.10.28 -
ClamAV 0.94.1 2009.10.28 Trojan.Dropper-19980
Comodo 2754 2009.10.28 UnclassifiedMalware
DrWeb 5.0.0.12182 2009.10.27 Trojan.Hosts.82
eSafe 7.0.17.0 2009.10.27 Win32.HEURCrypted
eTrust-Vet 35.1.7086 2009.10.27 -
F-Prot 4.5.1.85 2009.10.27 W32/Backdoor2.ELUF
F-Secure 9.0.15370.0 2009.10.27 Gen:Trojan.Heur.eG0@rOo!Hodi
Fortinet 3.120.0.0 2009.10.28 PossibleThreat
GData 19 2009.10.28 -
Ikarus T3.1.1.72.0 2009.10.28 not-a-virus.Hacktool.WPA
Jiangmin 11.0.800 2009.10.26 Trojan/Agent.cdnm
K7AntiVirus 7.10.881 2009.10.27 Trojan.Win32.Malware.3
Kaspersky 7.0.0.125 2009.10.28 -
McAfee 5784 2009.10.27 Generic.dx!fhi
McAfee+Artemis 5784 2009.10.27 Artemis!23275D9B2CE3
McAfee-GW-Edition 6.8.5 2009.10.27 Heuristic.Crypted
Microsoft 1.5202 2009.10.27 -
NOD32 4550 2009.10.28 -
Norman 6.03.02 2009.10.27 Smalltroj.RUSB
nProtect 2009.1.8.0 2009.10.28 -
Panda 10.0.2.2 2009.10.27 Suspicious file
PCTools 4.4.2.0 2009.10.19 -
Prevx 3.0 2009.10.28 Medium Risk Malware
Rising 21.53.20.00 2009.10.28 -
Sophos 4.46.0 2009.10.28 Mal/Generic-A
Sunbelt 3.2.1858.2 2009.10.27 -
Symantec 1.4.4.12 2009.10.28 Trojan Horse
TheHacker 6.5.0.2.055 2009.10.27 -
TrendMicro 8.950.0.1094 2009.10.27 -
VBA32 3.12.10.11 2009.10.27 Trojan.Win32.Agent.bvxl
ViRobot 2009.10.28.2008 2009.10.28 -
VirusBuster 4.6.5.0 2009.10.28 -
Additional information
File size: 5556020 bytes
MD5   : 23275d9b2ce33707c647048691c53ed2
SHA1  : f8df4583c420f97c040fb54a8e68db30040e9d67
SHA256: aa9b86200ddd29a3fc7db0482e5086b88964a89e5c4d4fbd053d4341057047f4
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1000
timedatestamp.....: 0x46F268E6 (Thu Sep 20 14:34:46 2007)
machinetype.......: 0x14C (Intel I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x14000 0x13800 6.47 8c499086717691066d921075ed5bdb09
.data 0x15000 0x7000 0xA00 4.91 0cb811e47f78b5404a658fb36b591857
.idata 0x1C000 0x1000 0x1000 5.12 8bf175092a70a21f11fd06cc4087c7d0
.rsrc 0x1D000 0x8F7C 0x9000 3.96 9983b5829a3b2e179f0f619923f95b76

( 8 imports )

> advapi32.dll: AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA, SetFileSecurityA, SetFileSecurityW
> comctl32.dll: -
> comdlg32.dll: CommDlgExtendedError, GetOpenFileNameA, GetSaveFileNameA
> gdi32.dll: DeleteObject
> kernel32.dll: CloseHandle, CompareStringA, CreateDirectoryA, CreateDirectoryW, CreateFileA, CreateFileW, DeleteFileA, DeleteFileW, DosDateTimeToFileTime, ExitProcess, ExpandEnvironmentStringsA, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, FindFirstFileA, FindFirstFileW, FindNextFileA, FindNextFileW, FindResourceA, FreeLibrary, GetCPInfo, GetCommandLineA, GetCurrentDirectoryA, GetCurrentProcess, GetDateFormatA, GetFileAttributesA, GetFileAttributesW, GetFileType, GetFullPathNameA, GetLastError, GetLocaleInfoA, GetModuleFileNameA, GetModuleHandleA, GetNumberFormatA, GetProcAddress, GetProcessHeap, GetStdHandle, GetTempPathA, GetTickCount, GetTimeFormatA, GetVersionExA, GlobalAlloc, HeapAlloc, HeapFree, HeapReAlloc, IsDBCSLeadByte, LoadLibraryA, LocalFileTimeToFileTime, MoveFileA, MoveFileExA, MultiByteToWideChar, ReadFile, SetCurrentDirectoryA, SetEndOfFile, SetEnvironmentVariableA, SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFileTime, SetLastError, Sleep, SystemTimeToFileTime, WaitForSingleObject, WideCharToMultiByte, WriteFile, lstrcmpiA, lstrlenA
> ole32.dll: CLSIDFromString, CoCreateInstance, CreateStreamOnHGlobal, OleInitialize, OleUninitialize
> shell32.dll: SHBrowseForFolderA, SHChangeNotify, SHFileOperationA, SHGetFileInfoA, SHGetMalloc, SHGetSpecialFolderLocation, ShellExecuteExA, SHGetPathFromIDListA
> user32.dll: CharToOemA, CharToOemBuffA, CharUpperA, CopyRect, CreateWindowExA, DefWindowProcA, DestroyIcon, DestroyWindow, DialogBoxParamA, DispatchMessageA, EnableWindow, EndDialog, FindWindowExA, GetClassNameA, GetClientRect, GetDlgItem, GetDlgItemTextA, GetMessageA, GetParent, GetSysColor, GetSystemMetrics, GetWindow, GetWindowLongA, GetWindowRect, GetWindowTextA, IsWindow, IsWindowVisible, LoadBitmapA, LoadCursorA, LoadIconA, LoadStringA, MapWindowPoints, MessageBoxA, OemToCharA, OemToCharBuffA, PeekMessageA, PostMessageA, RegisterClassExA, SendDlgItemMessageA, SendMessageA, SetDlgItemTextA, SetFocus, SetMenu, SetWindowLongA, SetWindowPos, SetWindowTextA, ShowWindow, TranslateMessage, UpdateWindow, WaitForInputIdle, wsprintfA, wvsprintfA

( 0 exports )
TrID  : File type identification
WinRAR Self Extracting archive (73.5%)
Windows OCX File (17.5%)
InstallShield setup (6.1%)
Win32 Executable Generic (1.2%)
Win32 Dynamic Link Library (generic) (1.0%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=23275d9b2ce33707c647048691c53ed2
ssdeep: 98304:WJeHz8e5m7p2TESBK14uiWqX/jKQ0G5LkWD10Gqrsg3yTNReRmDX:W+vge1duI7f0G5TZTkViTNL
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=1C6C006034379704C7BA54CDCE600A000F002349
PEiD  : -
packers (Kaspersky): PE_Patch, PE_Patch
packers (F-Prot): RAR, Unicode, CAB
packers (Authentium): RAR
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file