Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File waledac.exe received on 2009.04.17 11:21:22 (UTC)
Current status: finished
Result: 17/40 (42.50%)
Antivirus Version Last Update Result
a-squared 4.0.0.101 2009.04.17 -
AhnLab-V3 5.0.0.2 2009.04.17 -
AntiVir 7.9.0.143 2009.04.17 TR/Crypt.ZPACK.Gen
Antiy-AVL 2.0.3.1 2009.04.17 Worm/Win32.Iksmas
Authentium 5.1.2.4 2009.04.17 -
Avast 4.8.1335.0 2009.04.16 Win32:WalDrop
AVG 8.5.0.287 2009.04.17 Win32/Heur
BitDefender 7.2 2009.04.17 Trojan.Waledac.Gen.1
CAT-QuickHeal 10.00 2009.04.17 (Suspicious) - DNAScan
ClamAV 0.94.1 2009.04.17 -
Comodo 1117 2009.04.17 -
DrWeb 4.44.0.09170 2009.04.17 -
eSafe 7.0.17.0 2009.04.13 -
eTrust-Vet 31.6.6455 2009.04.14 -
F-Prot 4.4.4.56 2009.04.16 -
F-Secure 8.0.14470.0 2009.04.17 Packed:W32/Waledac.gen!I
Fortinet 3.117.0.0 2009.04.17 W32/WaledPak.A@mm
GData 19 2009.04.17 Trojan.Waledac.Gen.1
Ikarus T3.1.1.49.0 2009.04.17 -
K7AntiVirus 7.10.704 2009.04.15 -
Kaspersky 7.0.0.125 2009.04.17 Email-Worm.Win32.Iksmas.all
McAfee 5586 2009.04.16 W32/Waledac.gen.j
McAfee+Artemis 5586 2009.04.16 W32/Waledac.gen.j
McAfee-GW-Edition 6.7.6 2009.04.17 Trojan.Crypt.ZPACK.Gen
Microsoft 1.4502 2009.04.17 Trojan:Win32/Waledac.gen!A
NOD32 4016 2009.04.17 a variant of Win32/Waledac.IX
Norman 6.00.06 2009.04.16 -
nProtect 2009.1.8.0 2009.04.17 -
Panda 10.0.0.14 2009.04.17 -
PCTools 4.4.2.0 2009.04.17 -
Prevx1 V2 2009.04.17 -
Rising 21.25.42.00 2009.04.17 -
Sophos 4.40.0 2009.04.17 Mal/WaledPak-A
Sunbelt 3.2.1858.2 2009.04.17 -
Symantec 1.4.4.12 2009.04.17 Packed.Generic.221
TheHacker 6.3.4.0.309 2009.04.16 -
TrendMicro 8.700.0.1004 2009.04.17 -
VBA32 3.12.10.2 2009.04.12 -
ViRobot 2009.4.17.1698 2009.04.17 -
VirusBuster 4.6.5.0 2009.04.16 -
Additional information
File size: 418816 bytes
MD5...: ae9404cf5996d04a5ed8e32daf7cdbe1
SHA1..: 7f57d15442d7524d431e76fb1c1a67b3ad6e25a7
SHA256: 9064a1a32a7e3f4a9953ec115e83511dd8d9bce861f7f675b4f6653491b4d211
SHA512: 25492afb8b8734de585edab67118fe97b37accc7696a1a2e2d9e51eb5967ffe6
a45f4b833612e17cac4d3db7fa31e34a89fa7d4f573df47c314199ca3d370a37
ssdeep: 12288:RZMfq0plvesk+t9Lndi+p+YJIDUsCLuw:RZMfbplDk6x+hAs
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (38.4%)
Win32 Dynamic Link Library (generic) (34.2%)
Clipper DOS Executable (9.1%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x6320e
timedatestamp.....: 0x473c491b (Thu Nov 15 13:26:51 2007)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xf5000 0x65800 7.95 ac2e9b4f42aa40b39a7a3d6a6fc6ec05
.idata 0xf6000 0x1000 0x400 3.67 8b876569386e4fab93ae8dad6975104d
.rsrc 0xf7000 0x1000 0x400 1.94 2670dcce2d8427f252073998564e44d0

( 2 imports )
> kernel32.dll: GetConsoleFontInfo, UnlockFile, Sleep, ActivateActCtx, GetConsoleNlsMode, LZCreateFileW, ChangeTimerQueueTimer, GetSystemDefaultUILanguage, OutputDebugStringW, GlobalUnWire
> user32.dll: InitializeWin32EntryTable, OemToCharBuffW, DefWindowProcW, TrackPopupMenuEx, GetDialogBaseUnits, EnumWindowStationsW, GetKeyState, SendDlgItemMessageW, LockWindowStation, GetMenuDefaultItem, DefFrameProcW, DdeQueryConvInfo

( 0 exports )
RDS...: NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file