Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File fireworks.exe received on 07.04.2008 03:27:34 (CET)
Current status: finished
Result: 17/33 (51.52%)
Antivirus Version Last Update Result
AhnLab-V3 2008.7.4.0 2008.07.03 -
AntiVir 7.8.0.64 2008.07.03 WORM/Zhelatin.Gen
Authentium 5.1.0.4 2008.07.04 -
Avast 4.8.1195.0 2008.07.04 -
AVG 7.5.0.516 2008.07.03 I-Worm/Nuwar.U
BitDefender 7.2 2008.07.03 Trojan.Peed.JLV
CAT-QuickHeal 9.50 2008.07.03 Win32.Trojan-Downloader.Cntr.ca.3
ClamAV 0.93.1 2008.07.04 -
DrWeb 4.44.0.09170 2008.07.03 Trojan.Packed.555
eSafe 7.0.17.0 2008.07.03 Suspicious File
eTrust-Vet 31.6.5925 2008.07.04 Win32/Sintun.FB
Ewido 4.0 2008.07.03 -
F-Prot 4.4.4.56 2008.07.03 -
F-Secure 7.60.13501.0 2008.07.03 -
Fortinet 3.14.0.0 2008.07.04 -
GData 2.0.7306.1023 2008.07.03 Email-Worm.Win32.Zhelatin.add
Ikarus T3.1.1.26.0 2008.07.04 Email-Worm.Win32.Zhelatin.zy
Kaspersky 7.0.0.125 2008.07.04 Email-Worm.Win32.Zhelatin.add
McAfee 5331 2008.07.03 W32/Nuwar@MM
Microsoft 1.3704 2008.07.03 Backdoor:Win32/Nuwar.gen!D
NOD32v2 3240 2008.07.04 Win32/Nuwar.DC
Norman 5.80.02 2008.07.03 -
Panda 9.0.0.4 2008.07.03 Suspicious file
Prevx1 V2 2008.07.04 -
Rising 20.51.32.00 2008.07.03 -
Sophos 4.30.0 2008.07.04 Troj/Dorf-BP
Sunbelt 3.1.1509.1 2008.07.04 -
Symantec 10 2008.07.04 Trojan.Peacomm.D
TheHacker 6.2.96.370 2008.07.04 -
TrendMicro 8.700.0.1004 2008.07.03 -
VBA32 3.12.6.8 2008.07.03 -
VirusBuster 4.5.11.0 2008.07.03 -
Webwasher-Gateway 6.6.2 2008.07.04 Worm.Zhelatin.Gen
Additional information
File size: 118785 bytes
MD5...: 5f59f14c6a02d2ce26a2843e0556e797
SHA1..: 7cb31b8a7e940f1b8c71dec4b7ea4a1faab2c287
SHA256: 39272d54ed2e3307d55cb2c941338a87c6b47e9b4fa80bb3375185344873d39b
SHA512: 4560eda5fe7c2d0796d99b337d5feae60fec40a416082ef2460892b3b4f4ca07
88ebd530413ca69e902aafb3525cb229a5b63b0ae4d42f2c7ed79570381049e3
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x41d0c7
timedatestamp.....: 0x486ce3c0 (Thu Jul 03 14:35:44 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1c280 0x1c400 8.00 76c43f354cdc2165f851d58cde750ca4
.rdata 0x1e000 0x197 0x200 3.86 fd746d583d8f1a2de5c24e60b4126a93
.data 0x1f000 0x599 0x600 6.14 e5759eba680d11d31e7cadb06e56013b

( 2 imports )
> KERNEL32.dll: GetModuleHandleW, VirtualAlloc, GetProcAddress
> PSAPI.DLL: EnumProcesses

( 2 exports )
reqwqs, sfdbee

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file