Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File e9fe212900b685bf600d06868cf94400c6b96c1a.EXE received on 2009.07.16 17:15:52 (UTC)
Current status: finished
Result: 35/40 (87.50%)
Antivirus Version Last Update Result
a-squared 4.5.0.24 2009.07.16 Trojan.Win32.Obfuscated!IK
AhnLab-V3 5.0.0.2 2009.07.16 Win-Trojan/Swizzor.417792.NI
AntiVir 7.9.0.220 2009.07.16 TR/Dldr.Swizzor.Gen
Antiy-AVL 2.0.3.7 2009.07.16 -
Authentium 5.1.2.4 2009.07.16 W32/Swizzor-based.2!Maximus
Avast 4.8.1335.0 2009.07.16 Win32:Swizzor
AVG 8.5.0.387 2009.07.16 Downloader.Swizzor
BitDefender 7.2 2009.07.16 Trojan.Swizzor.4
CAT-QuickHeal 10.00 2009.07.16 Win32.Trojan.Swizzor.a.4
ClamAV 0.94.1 2009.07.16 -
Comodo 1670 2009.07.16 TrojWare.Win32.TrojanDownloader.Swizzor.Gen
DrWeb 5.0.0.12182 2009.07.16 Trojan.Swizzor.based
eSafe 7.0.17.0 2009.07.16 Win32.TRDldr.Swizzor
eTrust-Vet 31.6.6617 2009.07.15 Win32/Swizzor!generic
F-Prot 4.4.4.56 2009.07.16 W32/Swizzor-based.2!Maximus
F-Secure 8.0.14470.0 2009.07.16 Trojan.Win32.Swizzor.a
Fortinet 3.120.0.0 2009.07.16 PossibleThreat
GData 19 2009.07.16 Trojan.Swizzor.4
Ikarus T3.1.1.64.0 2009.07.16 Trojan.Win32.Obfuscated
Jiangmin 11.0.800 2009.07.16 -
K7AntiVirus 7.10.794 2009.07.16 Trojan.Win32.Malware.1
McAfee 5678 2009.07.16 Swizzor.gen.c
McAfee+Artemis 5678 2009.07.16 Swizzor.gen.c
McAfee-GW-Edition 6.8.5 2009.07.16 Trojan.Dldr.Swizzor.Gen
Microsoft 1.4803 2009.07.16 Trojan:Win32/C2Lop.gen!I
NOD32 4250 2009.07.16 a variant of Win32/TrojanDownloader.Swizzor.NBY
Norman 2009.07.16 W32/Swizzor.AXER
nProtect 2009.1.8.0 2009.07.16 Trojan/W32.Swizzor.417792.CB
Panda 10.0.0.14 2009.07.16 Malicious Packer
PCTools 4.4.2.0 2009.07.16 -
Prevx 3.0 2009.07.16 Low Risk Adware
Rising 21.38.34.00 2009.07.16 Trojan.DL.Win32.Swizzor.dtp
Sophos 4.43.0 2009.07.16 Mal/Swizzor-B
Sunbelt 3.2.1858.2 2009.07.16 C2.Lop
Symantec 1.4.4.12 2009.07.16 Trojan Horse
TheHacker 6.3.4.3.368 2009.07.15 Trojan/Swizzor.gen
TrendMicro 8.950.0.1094 2009.07.16 TROJ_SWIZZOR.JXQ
VBA32 3.12.10.8 2009.07.15 BScope.Trojan.BugsWay.H.Obfs
ViRobot 2009.7.16.1839 2009.07.16 -
VirusBuster 4.6.5.0 2009.07.16 Trojan.DL.Swizzor.Gen!Pac.5
Additional information
File size: 417792 bytes
MD5   : ff87a5ee6472783276ddaf5f8d9b43ec
SHA1  : af904e65a11a13b618a1a946496e5801edac3d35
SHA256: c183027d96313b757be9d9d066742e793127858b6c89a132d826b0cde9f529f7
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x8E16
timedatestamp.....: 0x4729562F (Thu Nov 1 05:29:35 2007)
machinetype.......: 0x14C (Intel I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x22769 0x23000 6.60 94d524e60412982894b2b8ac3c948b66
.rdata 0x24000 0x1749B 0x18000 7.81 12612420dccc9e3aa2e56420fdf5fd38
.data 0x3C000 0x1BFA8 0x18000 7.07 7fb69dcbe6368aa8d8a60a43447b3e0c
.rsrc 0x58000 0x11EC0 0x12000 5.64 f3e7242d76dd82a95a221c1b5d91c9c0

( 3 imports )

> comctl32.dll: CreateStatusWindow, ImageList_SetDragCursorImage, CreatePropertySheetPageW, CreateToolbar, DrawInsert, ImageList_GetImageRect, ImageList_Destroy, ImageList_SetFlags, ImageList_GetBkColor, ImageList_LoadImageA, CreateMappedBitmap, ImageList_EndDrag, DrawStatusTextW, ImageList_Duplicate, ImageList_Create, CreatePropertySheetPageA, ImageList_LoadImageW, ImageList_SetBkColor, ImageList_Draw, CreateUpDownControl, InitCommonControlsEx, ImageList_BeginDrag
> kernel32.dll: GetModuleHandleW, GetDateFormatA, TlsAlloc, SetHandleCount, IsDebuggerPresent, SetUnhandledExceptionFilter, GetStringTypeW, GetModuleFileNameA, InterlockedExchange, SetLastError, GetModuleHandleA, WaitForDebugEvent, CreateFileA, FlushFileBuffers, SetConsoleTitleW, GetCPInfo, WriteConsoleW, GetCurrentProcessId, GetTimeZoneInformation, WriteConsoleA, GetACP, FreeEnvironmentStringsW, GetEnvironmentStrings, SetFilePointer, GetProcAddress, InterlockedDecrement, GetFileType, HeapCreate, GetTimeFormatA, CloseHandle, GetStartupInfoA, EnterCriticalSection, MultiByteToWideChar, DeleteCriticalSection, WideCharToMultiByte, IsValidLocale, GetConsoleOutputCP, GetSystemTimeAsFileTime, GetLastError, VirtualFree, CreateMutexA, VirtualQuery, HeapFree, TerminateProcess, GetEnvironmentStringsW, HeapDestroy, GetCurrentThreadId, VirtualAlloc, InitializeCriticalSectionAndSpinCount, Sleep, GetLocaleInfoA, GetConsoleCP, HeapSize, GetCommandLineA, CompareStringW, LeaveCriticalSection, HeapAlloc, GetStdHandle, GetConsoleMode, ExitProcess, WriteFile, FreeLibrary, TlsSetValue, GetStringTypeA, GetCurrentThread, CompareStringA, GetLocaleInfoW, LCMapStringA, OpenMutexA, IsValidCodePage, ReadFile, UnhandledExceptionFilter, HeapReAlloc, LCMapStringW, GetCurrentProcess, GetUserDefaultLCID, SetEnvironmentVariableA, TlsGetValue, TlsFree, SetConsoleCtrlHandler, GetTickCount, QueryPerformanceCounter, InterlockedIncrement, SetStdHandle, EnumSystemLocalesA, LoadLibraryA, RtlUnwind, FreeEnvironmentStringsA, GetOEMCP
> user32.dll: GetSystemMenu, ShowCursor, InsertMenuItemA, CharNextExA, AttachThreadInput, GetClassInfoExA, LoadMenuIndirectA, GetUpdateRect, GetCapture, DlgDirSelectComboBoxExW, GetClipboardSequenceNumber, GetSystemMetrics, RegisterClassA, ToAscii, SetProcessWindowStation, GetComboBoxInfo, FlashWindow, GetClassWord, RemovePropW, GetNextDlgTabItem, OemToCharW, GetInputDesktop, wsprintfW, LoadAcceleratorsW, CreateAcceleratorTableA, RegisterClassExA, OffsetRect, DialogBoxParamA, SetWindowsHookExA, GetUserObjectSecurity

( 0 exports )
TrID  : File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=ff87a5ee6472783276ddaf5f8d9b43ec
ssdeep: 6144:+US6qMfwYlmFoGWNeX6Usfag2JIjJWzV5eAhJd5lO9wkqNtV:+UbwoGWNeX6xRJWBrd5qwk
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=E9FE212900B685BF600D06868CF94400C6B96C1A
PEiD  : -
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file