Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File setup2.exe received on 2009.07.09 04:48:53 (UTC)
Current status: finished
Result: 20/41 (48.78%)
Antivirus Version Last Update Result
a-squared 4.5.0.18 2009.07.09 Trojan-Dropper.Win32.Winwebsec!IK
AhnLab-V3 5.0.0.2 2009.07.08 -
AntiVir 7.9.0.204 2009.07.08 TR/Dropper.Gen
Antiy-AVL 2.0.3.1 2009.07.09 Packed/Win32.Tdss
Authentium 5.1.2.4 2009.07.08 -
Avast 4.8.1335.0 2009.07.08 -
AVG 8.5.0.386 2009.07.09 -
BitDefender 7.2 2009.07.09 -
CAT-QuickHeal 10.00 2009.07.09 -
ClamAV 0.94.1 2009.07.08 -
Comodo 1588 2009.07.09 -
DrWeb 5.0.0.12182 2009.07.09 Trojan.MulDrop.32233
eSafe 7.0.17.0 2009.07.08 -
eTrust-Vet 31.6.6604 2009.07.08 Win32/Droplet.LQ
F-Prot 4.4.4.56 2009.07.08 -
F-Secure 8.0.14470.0 2009.07.09 Trojan-Downloader.Win32.CodecPack.ilv
Fortinet 3.117.0.0 2009.07.03 -
GData 19 2009.07.09 -
Ikarus T3.1.1.64.0 2009.07.09 Trojan-Dropper.Win32.Winwebsec
Jiangmin 11.0.706 2009.07.08 -
K7AntiVirus 7.10.787 2009.07.08 Trojan.Win32.Malware.1
Kaspersky 7.0.0.125 2009.07.09 Packed.Win32.Tdss.m
McAfee 5670 2009.07.08 FakeAlert-EZ
McAfee+Artemis 5670 2009.07.08 FakeAlert-EZ
McAfee-GW-Edition 6.8.5 2009.07.09 Trojan.Dropper.Gen
Microsoft 1.4803 2009.07.08 TrojanDropper:Win32/Insnot.gen!A
NOD32 4226 2009.07.09 Win32/TrojanDownloader.FakeAlert.ADO
Norman 6.01.09 2009.07.08 W32/Antivirus2008.DGI
nProtect 2009.1.8.0 2009.07.09 -
Panda 10.0.0.14 2009.07.08 Trj/CI.A
PCTools 4.4.2.0 2009.07.08 -
Prevx 3.0 2009.07.09 Medium Risk Malware
Rising 21.37.24.00 2009.07.08 -
Sophos 4.43.0 2009.07.09 Mal/Generic-A
Sunbelt 3.2.1858.2 2009.07.09 Bulk Trojan
Symantec 1.4.4.12 2009.07.09 -
TheHacker 6.3.4.3.363 2009.07.08 -
TrendMicro 8.950.0.1094 2009.07.09 -
VBA32 3.12.10.7 2009.07.09 Trojan-Dropper.Win32.Agent.atmg
ViRobot 2009.7.9.1825 2009.07.09 -
VirusBuster 4.6.5.0 2009.07.08 -
Additional information
File size: 909950 bytes
MD5   : e28ecac172dd0b6a178e4abbd6e92af7
SHA1  : f3d2b1552d41ec2f609a4895158dc2cf66cd7cdb
SHA256: bb261e0740321a984fac2c6a8f69090791de63377889b78de5acdb036008efda
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1000
timedatestamp.....: 0x4A3FFBAA (Mon Jun 22 23:46:18 2009)
machinetype.......: 0x14C (Intel I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3B9 0x400 5.71 f9d2894cfaa421b0e7df8a0b95d042e0
.data 0x2000 0x4163 0x600 4.79 cb7c2b3d8979d50f421f1d37faf58286
.rsrc 0x7000 0x502 0x600 2.01 57b631d3cd1913738e9e32bdef3d3abd

( 3 imports )

> kernel32.dll: CloseHandle, CreateFileA, CreateFileMappingA, CreateProcessA, ExitProcess, FormatMessageA, GetFileSize, GetLastError, GetModuleFileNameA, GetStartupInfoA, GetTempFileNameA, GetTempPathA, GetVersion, GetWindowsDirectoryA, LocalFree, MapViewOfFile, MoveFileExA, RtlMoveMemory, Sleep, UnmapViewOfFile, WriteFile, WritePrivateProfileStringA, lstrcatA
> user32.dll: MessageBoxA, wsprintfA
> wininet.dll: InternetOpenA, InternetOpenUrlA, InternetCloseHandle

( 0 exports )
TrID  : File type identification
InstallShield setup (77.4%)
Win32 Executable Generic (15.3%)
Generic Win/DOS Executable (3.5%)
DOS Executable Generic (3.5%)
VXD Driver (0.0%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=e28ecac172dd0b6a178e4abbd6e92af7
ssdeep: 24576:XdYkwJ7B4yolgueW4+dNjzwt4AOLoBjO7QfAJQt:XdYRJebHdNjznAmojAJQt
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=38C74BB17EEED8F8E2140D54CBE801000F9A3D07
PEiD  : -
packers (Kaspersky): PE_Patch.UPX, UPX
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file