Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File 1952405D00EE6FBD3E0000E9F4250F00643110CC.exe received on 2009.10.16 16:57:24 (UTC)
Current status: finished
Result: 6/41 (14.63%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.10.16 -
AhnLab-V3 5.0.0.2 2009.10.16 -
AntiVir 7.9.1.35 2009.10.16 -
Antiy-AVL 2.0.3.7 2009.10.16 -
Authentium 5.1.2.4 2009.10.16 -
Avast 4.8.1351.0 2009.10.14 -
AVG 8.5.0.420 2009.10.16 -
BitDefender 7.2 2009.10.16 -
CAT-QuickHeal 10.00 2009.10.16 -
ClamAV 0.94.1 2009.10.16 -
Comodo 2622 2009.10.16 Heur.Packed.Unknown
DrWeb 5.0.0.12182 2009.10.16 -
eSafe 7.0.17.0 2009.10.15 Suspicious File
eTrust-Vet 35.1.7071 2009.10.16 -
F-Prot 4.5.1.85 2009.10.15 -
F-Secure 8.0.14470.0 2009.10.16 -
Fortinet 3.120.0.0 2009.10.16 -
GData 19 2009.10.16 -
Ikarus T3.1.1.72.0 2009.10.16 -
Jiangmin 11.0.800 2009.10.16 -
K7AntiVirus 7.10.872 2009.10.16 -
Kaspersky 7.0.0.125 2009.10.16 -
McAfee 5772 2009.10.15 -
McAfee+Artemis 5772 2009.10.15 -
McAfee-GW-Edition 6.8.5 2009.10.16 -
Microsoft 1.5101 2009.10.16 -
NOD32 4515 2009.10.16 -
Norman 6.03.02 2009.10.16 -
nProtect 2009.1.8.0 2009.10.15 -
Panda 10.0.2.2 2009.10.15 Suspicious file
PCTools 4.4.2.0 2009.10.16 -
Prevx 3.0 2009.10.16 High Risk System Back Door
Rising 21.51.44.00 2009.10.16 Dropper.Win32.Mnless.esg
Sophos 4.46.0 2009.10.16 -
Sunbelt 3.2.1858.2 2009.10.15 -
Symantec 1.4.4.12 2009.10.16 -
TheHacker 6.5.0.2.043 2009.10.15 -
TrendMicro 8.950.0.1094 2009.10.16 PAK_Generic.001
VBA32 3.12.10.11 2009.10.15 -
ViRobot 2009.10.16.1988 2009.10.16 -
VirusBuster 4.6.5.0 2009.10.16 -
Additional information
File size: 15872 bytes
MD5   : 006c4ff5e85ed16b827e9fa144d8214f
SHA1  : 2c29482fcd1a857e6b4ca98b3b1a7e9876f7455c
SHA256: b6d5386298ec44cf220b1768a9fdc3b0a6d38f078d233c9d8edf761fe9589362
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xF640
timedatestamp.....: 0x2A425E19 (Sat Jun 20 00:22:17 1992)
machinetype.......: 0x14C (Intel I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0xB000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0xC000 0x4000 0x3800 7.88 c56d1eb3c5722ddb7a36ae7b66922e36
UPX2 0x10000 0x1000 0x200 2.13 4f690e825fdd066b4422a97275c22884

( 2 imports )

> advapi32.dll: RegOpenKeyExA
> kernel32.dll: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess

( 0 exports )
TrID  : File type identification
UPX compressed Win32 Executable (38.5%)
Win32 EXE Yoda's Crypter (33.4%)
Win32 Executable Generic (10.7%)
Win32 Dynamic Link Library (generic) (9.5%)
Win16/32 Executable Delphi generic (2.6%)
ssdeep: 384:Ug2oF+rZWuGPwUcz2fWWUdEC3lrM/BBZGFjAnInusv8LRhvc:Ug2qjwoUVVM/juzurj
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=1952405D00EE6FBD3E0000E9F4250F00643110CC
PEiD  : -
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file