Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File nppagent.exe received on 2008.11.12 20:06:41 (UTC)
Current status: finished
Result: 13/36 (36.11%)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.13.0 2008.11.12 Win-Trojan/Xema.variant
AntiVir 7.9.0.31 2008.11.12 TR/Spy.Delf.NRS
Authentium 5.1.0.4 2008.11.12 -
Avast 4.8.1248.0 2008.11.12 Win32:Spyware-gen
AVG 8.0.0.199 2008.11.12 -
BitDefender 7.2 2008.11.12 Trojan.Spy.Delf.NRS
CAT-QuickHeal 9.50 2008.11.12 -
ClamAV 0.94.1 2008.11.12 -
DrWeb 4.44.0.09170 2008.11.12 -
eSafe 7.0.17.0 2008.11.12 Suspicious File
eTrust-Vet 31.6.6204 2008.11.11 -
Ewido 4.0 2008.11.12 -
F-Prot 4.4.4.56 2008.11.06 -
F-Secure 8.0.14332.0 2008.11.12 -
Fortinet 3.117.0.0 2008.11.12 -
GData 19 2008.11.12 Trojan.Spy.Delf.NRS
Ikarus T3.1.1.45.0 2008.11.12 Trojan-Downloader.Win32.Banload
K7AntiVirus 7.10.523 2008.11.12 -
Kaspersky 7.0.0.125 2008.11.12 -
McAfee 5431 2008.11.12 -
Microsoft 1.4104 2008.11.12 -
NOD32 3607 2008.11.12 Win32/PSW.Delf.NMB
Norman 5.80.02 2008.11.12 -
Panda 9.0.0.4 2008.11.12 Trj/Nabload.DJO
PCTools 4.4.2.0 2008.11.12 -
Prevx1 V2 2008.11.12 -
Rising 21.03.22.00 2008.11.12 -
SecureWeb-Gateway 6.7.6 2008.11.12 Trojan.Spy.Delf.NRS
Sophos 4.35.0 2008.11.12 -
Sunbelt 3.1.1783.2 2008.11.05 Trojan-Spy.Delf.NRS
Symantec 10 2008.11.12 -
TheHacker 6.3.1.1.149 2008.11.12 -
TrendMicro 8.700.0.1004 2008.11.12 TSPY_DELF.AIY
VBA32 3.12.8.9 2008.11.11 suspected of Malware.Delf.104 (paranoid heuristics)
ViRobot 2008.11.12.1463 2008.11.12 -
VirusBuster 4.5.11.0 2008.11.12 -
Additional information
File size: 179712 bytes
MD5...: 91f4c75a4f000f3b5bdc2cd74fb5d0d8
SHA1..: a7b74ea8da3a4bcdf29c4a14b3621ca0edbd0614
SHA256: 81bf7543db0e10b004f656285a3992d7a369b4b0331512346b7ce4c7ca4b0421
SHA512: 6bc64279f7d2d767c102931e0adcccd2b6b4cd2f3b744a4f3846beee78611370
4a0a5445e39b06a52552092a0efe92a09c41d401c90830f7e0c64a011f750df2
PEiD..: -
TrID..: File type identification
UPX compressed Win32 Executable (38.5%)
Win32 EXE Yoda's Crypter (33.4%)
Win32 Executable Generic (10.7%)
Win32 Dynamic Link Library (generic) (9.5%)
Win16/32 Executable Delphi generic (2.6%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x476a40
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x4b000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x4c000 0x2b000 0x2ac00 7.92 949931a531c095c18ca69978a1fe4e09
.rsrc 0x77000 0x1000 0xe00 3.04 7ca4e934e50115f7b14bf07ac869c39e

( 7 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> advapi32.dll: RegCloseKey
> comctl32.dll: ImageList_Add
> gdi32.dll: SaveDC
> oleaut32.dll: VariantCopy
> user32.dll: GetDC
> version.dll: VerQueryValueA

( 0 exports )
packers (Kaspersky): UPX
packers (F-Prot): UPX

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file