Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File wh_83504654.exe received on 2009.11.07 00:04:44 (UTC)
Current status: finished
Result: 27/40 (67.50%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.11.06 Trojan-PWS.Win32.Dybalom!IK
AhnLab-V3 5.0.0.2 2009.11.06 -
AntiVir 7.9.1.61 2009.11.06 -
Antiy-AVL 2.0.3.7 2009.11.05 Trojan/Win32.Dybalom.gen
Authentium 5.2.0.5 2009.11.06 W32/Trojan2.INPQ
Avast 4.8.1351.0 2009.11.06 -
AVG 8.5.0.423 2009.11.06 PSW.Generic7.VAZ
BitDefender 7.2 2009.11.06 Trojan.Generic.2346559
CAT-QuickHeal 10.00 2009.11.06 -
ClamAV 0.94.1 2009.11.06 Trojan.Spy-64317
Comodo 2866 2009.11.07 TrojWare.Win32.TrojanDownloader.Agent.~XQA
DrWeb 5.0.0.12182 2009.11.06 Trojan.DownLoad.44662
eTrust-Vet 35.1.7108 2009.11.06 Win32/Fignotok.A
F-Prot 4.5.1.85 2009.11.06 W32/Trojan2.INPQ
F-Secure 9.0.15370.0 2009.11.04 Trojan.Generic.2346559
Fortinet 3.120.0.0 2009.11.06 -
GData 19 2009.11.07 Trojan.Generic.2346559
Ikarus T3.1.1.74.0 2009.11.06 Trojan-PWS.Win32.Dybalom
Jiangmin 11.0.800 2009.11.06 Trojan/PSW.Dybalom.b
K7AntiVirus 7.10.890 2009.11.06 -
Kaspersky 7.0.0.125 2009.11.07 -
McAfee 5794 2009.11.06 Generic Downloader!hv.x
McAfee+Artemis 5794 2009.11.06 Generic Downloader!hv.x
McAfee-GW-Edition 6.8.5 2009.11.06 Heuristic.LooksLike.Win32.PasswordStealer.L
Microsoft 1.5202 2009.11.06 PWS:Win32/Fignotok.A
NOD32 4580 2009.11.06 Win32/PSW.Agent.NNI
Norman 6.03.02 2009.11.06 -
nProtect 2009.1.8.0 2009.11.06 Trojan-PWS/W32.Dybalom.32768
Panda 10.0.2.2 2009.11.06 Trj/Downloader.MDW
PCTools 7.0.3.5 2009.11.06 Trojan-PSW.Generic
Prevx 3.0 2009.11.07 High Risk Information Stealer
Rising 21.54.44.00 2009.11.06 -
Sophos 4.47.0 2009.11.06 Troj/Dloadr-CTC
Sunbelt 3.2.1858.2 2009.11.06 -
Symantec 1.4.4.12 2009.11.07 Infostealer
TheHacker 6.5.0.2.063 2009.11.06 Trojan/Downloader.Small.amam
TrendMicro 9.0.0.1003 2009.11.06 -
VBA32 3.12.10.11 2009.11.06 Trojan-Downloader.Win32.Small.amam
ViRobot 2009.11.6.2025 2009.11.06 -
VirusBuster 4.6.5.0 2009.11.06 -
Additional information
File size: 32768 bytes
MD5   : 04d40866fe384d040ac10caa3ab20811
SHA1  : 4a191998cb2f48d9331073d5955a2726eee31887
SHA256: c3d9abb7c121a509f54eea42f56677a8af3219a3509ea67f3135bd655cb0e740
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x44A6
timedatestamp.....: 0x4A7F5E39 (Mon Aug 10 01:39:37 2009)
machinetype.......: 0x14C (Intel I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x363C 0x4000 5.61 f5a64aa0114a04b9ced9d9e4608d9e6d
.rdata 0x5000 0x654 0x1000 2.42 35235d132e09141a46a34be5b00c2b23
.data 0x6000 0xC74 0x1000 4.63 b3824b15f70438065fab0bfe3791e664
.rsrc 0x7000 0x100 0x1000 0.22 94ad93ecd38f891ba83f9550e927803b

( 6 imports )

> advapi32.dll: RegEnumKeyExA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, GetUserNameA
> kernel32.dll: FindResourceA, GetComputerNameA, GetVolumeInformationA, GetDriveTypeA, LoadResource, GetProcAddress, LoadLibraryA, GetModuleHandleA, GetStartupInfoA, LockResource, SizeofResource, FreeResource, GetModuleFileNameA, FreeLibrary, GetShortPathNameA
> msvcrt.dll: _XcptFilter, strcat, strcpy, strlen, fclose, fread, malloc, ftell, fseek, fopen, strncpy, sprintf, exit, fwrite, memcpy, free, sscanf, strncat, realloc, _exit, memcmp, _acmdln, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp
> shell32.dll: ShellExecuteA
> user32.dll: FindWindowA
> wininet.dll: FindNextUrlCacheEntryA, InternetOpenUrlA, InternetOpenA, FindCloseUrlCache, InternetCloseHandle, FindFirstUrlCacheEntryA

( 0 exports )
TrID  : File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=04d40866fe384d040ac10caa3ab20811
ssdeep: 384:sdSm6WK5O8i2yy4eFZXh7/+BIimaUxpoGbz8gTFA/oqY7aoWjeMz98fuGh:86h5O9FtIiPUxpRbYgT+oqDG
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=9400175A009F08998045003E917E2000F48E777B
PEiD  : -
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file