Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File ie.exe received on 2009.03.05 15:30:53 (UTC)
Current status: finished
Result: 15/38 (39.47%)
Antivirus Version Last Update Result
a-squared 4.0.0.101 2009.03.05 Trojan.Win32.Redosdru!IK
AhnLab-V3 5.0.0.2 2009.02.27 Win-Trojan/Agent.667864
AntiVir 7.9.0.100 2009.03.05 -
Authentium 5.1.0.4 2009.03.04 -
Avast 4.8.1335.0 2009.03.05 Win32:Trojan-gen {Other}
AVG 8.0.0.237 2009.03.05 Rootkit-Agent.CB
BitDefender 7.2 2009.03.05 -
CAT-QuickHeal 10.00 2009.03.05 Trojan.Agent.ated
ClamAV 0.94.1 2009.03.05 -
Comodo 1027 2009.03.05 TrojWare.Win32.PSW.OnLineGames.~ASV
DrWeb 4.44.0.09170 2009.03.05 -
eSafe 7.0.17.0 2009.03.04 -
eTrust-Vet 31.6.6382 2009.03.05 -
F-Prot 4.4.4.56 2009.03.04 -
Fortinet 3.117.0.0 2009.03.05 -
GData 19 2009.03.05 Win32:Trojan-gen {Other}
Ikarus T3.1.1.45.0 2009.03.05 Trojan.Win32.Redosdru
K7AntiVirus 7.10.657 2009.03.04 -
Kaspersky 7.0.0.125 2009.03.05 -
McAfee 5543 2009.03.04 -
McAfee+Artemis 5543 2009.03.04 -
Microsoft 1.4405 2009.03.05 -
NOD32 3910 2009.03.05 -
Norman 6.00.06 2009.03.05 -
nProtect 2009.1.8.0 2009.03.05 Trojan/W32.Agent.673996
Panda 10.0.0.10 2009.03.05 -
PCTools 4.4.2.0 2009.03.05 -
Prevx1 V2 2009.03.05 High Risk Cloaked Malware
Rising 21.19.32.00 2009.03.05 Trojan.Win32.Nodef.ehm
SecureWeb-Gateway 6.7.6 2009.03.05 Trojan.LooksLike.Agent.ALMJ
Sophos 4.39.0 2009.03.05 Troj/Redos-Gen
Sunbelt 3.2.1858.2 2009.03.05 -
Symantec 10 2009.03.05 -
TheHacker 6.3.2.7.272 2009.03.05 -
TrendMicro 8.700.0.1004 2009.03.05 -
VBA32 3.12.10.1 2009.03.05 suspected of Win32.BrokenEmbeddedSignature (paranoid heuristics)
ViRobot 2009.3.5.1635 2009.03.05 Trojan.Win32.Agent.673792
VirusBuster 4.5.11.0 2009.03.04 -
Additional information
File size: 683412 bytes
MD5...: 51097390741f7be1acabaa184facad1b
SHA1..: 813edc81169b31547c23d2d124235471128c4653
SHA256: 071f4dcaa7d017b5e2e1722572b9fcbc8fac5e7f692be631da08de703516b116
SHA512: 58cfc90a4ef50178c0b9d3b2b4a621549cd199fb4947579a02a2b240231ec7d7
42cb98f78ee8db7cf7bc2481b6792deba79728f061591d0e2672c93392737a0a
ssdeep: 12288:3RAXGa5NwYkK19iOCr+TMoO30mYn0YaAsGhQ8zM5DKTrH5EZQ21d:WXG3K
19iOCr+TMoO30mYn0YaAst8zM5B
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1a5e
timedatestamp.....: 0x49407508 (Thu Dec 11 02:03:52 2008)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x6a04 0x6c00 6.57 77d9a0b458324cf3ff584e76eed0dd6f
.rdata 0x8000 0x251a 0x2600 5.47 18e27bd9e1948d36f58c6a7f20edafe4
.data 0xb000 0x197c 0xe00 2.39 f5bd0600784ea13633131d2c5ace59f2
.rsrc 0xd000 0x99000 0x98c00 6.78 3b503e8827a16711b67c654c47064522
.reloc 0xa6000 0x17de 0x1800 3.01 514fb23882e77df41533d946be7ef4a3

( 2 imports )
> KERNEL32.dll: HeapReAlloc, GetFileSize, FreeResource, lstrlenA, FindResourceW, FreeLibrary, LoadResource, HeapAlloc, HeapFree, GetTickCount, GetProcessHeap, WriteFile, GetSystemDirectoryW, LoadLibraryW, SizeofResource, ReadFile, GetModuleFileNameW, CreateFileW, GetProcAddress, GetCurrentThreadId, CloseHandle, LCMapStringW, LCMapStringA, GetStringTypeW, GetStartupInfoW, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetLastError, GetModuleHandleW, Sleep, ExitProcess, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, DeleteCriticalSection, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, InterlockedDecrement, HeapCreate, VirtualFree, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, LeaveCriticalSection, EnterCriticalSection, VirtualAlloc, RtlUnwind, LoadLibraryA, InitializeCriticalSectionAndSpinCount, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, HeapSize, GetLocaleInfoA, WideCharToMultiByte, GetStringTypeA, MultiByteToWideChar
> USER32.dll: wsprintfA, wsprintfW, GetInputState, PostThreadMessageW, GetMessageW

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=DE2DF45894A1787E6D820AA961EBB500798C0EDF

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file