Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File setup.exe received on 2009.07.09 14:41:38 (UTC)
Current status: finished
Result: 21/41 (51.22%)
Antivirus Version Last Update Result
a-squared 4.5.0.18 2009.07.09 Gen.Trojan!IK
AhnLab-V3 5.0.0.2 2009.07.09 -
AntiVir 7.9.0.204 2009.07.09 TR/Spy.45059.1
Antiy-AVL 2.0.3.1 2009.07.09 -
Authentium 5.1.2.4 2009.07.08 -
Avast 4.8.1335.0 2009.07.08 Win32:Spyware-gen
AVG 8.5.0.386 2009.07.09 FakeAlert.KT
BitDefender 7.2 2009.07.09 Gen:Trojan.Heur.20659ACF1F
CAT-QuickHeal 10.00 2009.07.09 (Suspicious) - DNAScan
ClamAV 0.94.1 2009.07.09 -
Comodo 1593 2009.07.09 -
DrWeb 5.0.0.12182 2009.07.09 Trojan.Fakealert.4510
eSafe 7.0.17.0 2009.07.09 Win32.VirToolObfusca
eTrust-Vet 31.6.6606 2009.07.09 -
F-Prot 4.4.4.56 2009.07.08 -
F-Secure 8.0.14470.0 2009.07.09 Trojan-Downloader.Win32.FraudLoad.exm
Fortinet 3.117.0.0 2009.07.03 -
GData 19 2009.07.09 Gen:Trojan.Heur.20659ACF1F
Ikarus T3.1.1.64.0 2009.07.09 Gen.Trojan
Jiangmin 11.0.706 2009.07.09 -
K7AntiVirus 7.10.788 2009.07.09 Trojan-Downloader.Win32.FraudLoad.exm
Kaspersky 7.0.0.125 2009.07.09 Trojan-Downloader.Win32.FraudLoad.exm
McAfee 5670 2009.07.08 -
McAfee+Artemis 5670 2009.07.08 Artemis!513FFC855DAE
McAfee-GW-Edition 6.8.5 2009.07.09 Trojan.Spy.45059.1
Microsoft 1.4803 2009.07.09 VirTool:Win32/Obfuscator.DO
NOD32 4228 2009.07.09 Win32/TrojanDownloader.FakeAlert.AEL
Norman 6.01.09 2009.07.09 DLoader.QOPA
nProtect 2009.1.8.0 2009.07.09 -
Panda 10.0.0.14 2009.07.08 Trj/CI.A
PCTools 4.4.2.0 2009.07.09 -
Prevx 3.0 2009.07.09 -
Rising 21.37.34.00 2009.07.09 -
Sophos 4.43.0 2009.07.09 Mal/EncPk-IF
Sunbelt 3.2.1858.2 2009.07.09 Bulk Trojan
Symantec 1.4.4.12 2009.07.09 -
TheHacker 6.3.4.3.363 2009.07.08 -
TrendMicro 8.950.0.1094 2009.07.09 -
VBA32 3.12.10.7 2009.07.09 -
ViRobot 2009.7.9.1827 2009.07.09 -
VirusBuster 4.6.5.0 2009.07.08 -
Additional information
File size: 45059 bytes
MD5   : 513ffc855daed8d0889188431add9d34
SHA1  : e333f28689de9e1259983b1a1e094e3414ee1d3c
SHA256: bdc3bfdfabe20ba63489bf9701ebf23c443f319c7fa826eefa736d386a7c60d9
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x134C
timedatestamp.....: 0x42F9D9B9 (Wed Aug 10 12:40:57 2005)
machinetype.......: 0x14C (Intel I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.code 0x1000 0x1A0F 0x1C00 7.64 68bf558ee4bf8cfd6e428d875e474b5d
.data 0x3000 0xB210 0x7400 7.94 3435fa99c98576c78b62f5057f751652
.idata 0xF000 0x40E 0x800 2.78 c41f8c5a81c9e4e9f6c743bc907a5f0a
.rsrc 0x10000 0x102C 0x1400 4.28 0d2c1042a9ca541409d640ab223f3722

( 4 imports )

> gdi32.dll: Rectangle, SelectObject, SaveDC, SetViewportExtEx
> kernel32.dll: GetCurrentDirectoryA, GetCurrentProcessId, ExitProcess, DebugBreak, SetThreadPriority, VirtualProtect, FileTimeToSystemTime, GetStringTypeW, GetCommandLineW, ResumeThread, GetEnvironmentVariableW, GetCommandLineA, GetPrivateProfileStringW, VirtualAlloc, LoadLibraryExA, Sleep, GetSystemTime, GetOEMCP, LoadLibraryA, GetExitCodeProcess, GetTimeFormatW, FlushFileBuffers, GetFileInformationByHandle, HeapCreate, SetCurrentDirectoryA, FreeEnvironmentStringsW
> msvcrt.dll: __setusermatherr, __p__fmode, realloc, _errno, _purecall, _controlfp, wcsncmp, ___U@YAPAXI@Z, _fileno
> ole32.dll: CoInitializeEx, CoCreateInstance

( 0 exports )
TrID  : File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=513ffc855daed8d0889188431add9d34
ssdeep: 768:cEzQPSS+6E4KMxWxjehjjc6PedBm5LDPJWmDbMCYMMYcwza/Q1ysX66pMWiN:K+6k3y/2BmJsmDA1MHcwG/Q1bNMvN
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=B426510B03B86A3AB042003C611E19005197AB0D
PEiD  : -
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file