Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File winbox.exe received on 2009.10.24 09:03:36 (UTC)
Current status: finished
Result: 3/41 (7.32%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.10.24 -
AhnLab-V3 5.0.0.2 2009.10.23 -
AntiVir 7.9.1.44 2009.10.23 -
Antiy-AVL 2.0.3.7 2009.10.23 -
Authentium 5.1.2.4 2009.10.24 -
Avast 4.8.1351.0 2009.10.24 -
AVG 8.5.0.423 2009.10.24 -
BitDefender 7.2 2009.10.24 -
CAT-QuickHeal 10.00 2009.10.24 -
ClamAV 0.94.1 2009.10.24 -
Comodo 2712 2009.10.24 -
DrWeb 5.0.0.12182 2009.10.24 -
eSafe 7.0.17.0 2009.10.22 Suspicious File
eTrust-Vet 35.1.7082 2009.10.23 -
F-Prot 4.5.1.85 2009.10.23 -
F-Secure 9.0.15370.0 2009.10.22 -
Fortinet 3.120.0.0 2009.10.24 -
GData 19 2009.10.24 -
Ikarus T3.1.1.72.0 2009.10.24 -
Jiangmin 11.0.800 2009.10.24 -
K7AntiVirus 7.10.878 2009.10.23 -
Kaspersky 7.0.0.125 2009.10.24 -
McAfee 5780 2009.10.23 -
McAfee+Artemis 5780 2009.10.23 -
McAfee-GW-Edition 6.8.5 2009.10.24 Heuristic.BehavesLike.Win32.Worm.A
Microsoft 1.5202 2009.10.24 -
NOD32 4537 2009.10.23 -
Norman 6.03.02 2009.10.23 -
nProtect 2009.1.8.0 2009.10.24 -
Panda 10.0.2.2 2009.10.23 -
PCTools 4.4.2.0 2009.10.19 -
Prevx 3.0 2009.10.24 -
Rising 21.52.52.00 2009.10.24 -
Sophos 4.46.0 2009.10.24 -
Sunbelt 3.2.1858.2 2009.10.24 -
Symantec 1.4.4.12 2009.10.24 -
TheHacker 6.5.0.2.051 2009.10.22 -
TrendMicro 8.950.0.1094 2009.10.24 PAK_Generic.001
VBA32 3.12.10.11 2009.10.23 -
ViRobot 2009.10.23.2003 2009.10.23 -
VirusBuster 4.6.5.0 2009.10.23 -
Additional information
File size: 36864 bytes
MD5   : 95dca55c1f3c9f5e18aa1abe9ad7f4f8
SHA1  : 6a97153500807ae64298bca10500224d592b7ad2
SHA256: c2f98e9e01f367d6feccad935fb2714acba9e5d1e16ea81463b85189465b693e
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1FE60
timedatestamp.....: 0x49800A00 (Wed Jan 28 08:32:16 2009)
machinetype.......: 0x14C (Intel I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x17000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x18000 0x8000 0x8000 7.84 aff8162ac1dc5d52fac0c529310af7a2
.rsrc 0x20000 0x1000 0xE00 3.87 7b239e5de8036ffbc22130ffc433125c

( 8 imports )

> advapi32.dll: RegOpenKeyExA
> comctl32.dll: ImageList_Create
> comdlg32.dll: GetOpenFileNameA
> kernel32.dll: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> msvcrt.dll: _iob
> netapi32.dll: Netbios
> user32.dll: IsIconic
> ws2_32.dll: bind

( 0 exports )
TrID  : File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=95dca55c1f3c9f5e18aa1abe9ad7f4f8
ssdeep: 768:faQPupkCBVH+WB3bZJyAn7atnlYEjNjm4MYciq2sp8d6istP07dysjJ2:faQPuqCt9StlRj9NdqO5LJ2
sigcheck: publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=9411E874007A0BC290EE0093B09A84009F5936CF
PEiD  : UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX
CWSandbox: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=95dca55c1f3c9f5e18aa1abe9ad7f4f8
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file