Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File msn.exe received on 2009.10.05 11:26:05 (UTC)
Current status: finished
Result: 23/41 (56.10%)
Antivirus Version Last Update Result
a-squared 4.5.0.24 2009.10.05 -
AhnLab-V3 5.0.0.2 2009.10.05 -
AntiVir 7.9.1.33 2009.10.05 TR/Crypt.NSPM.Gen
Antiy-AVL 2.0.3.7 2009.10.05 Trojan/Win32.Chifrax.gen
Authentium 5.1.2.4 2009.10.04 W32/OnlineGames!Generic
Avast 4.8.1351.0 2009.10.04 -
AVG 8.5.0.420 2009.10.04 BackDoor.Hupigon5.VHW
BitDefender 7.2 2009.10.05 -
CAT-QuickHeal 10.00 2009.10.05 -
ClamAV 0.94.1 2009.10.05 Trojan.Downloader.VBS.Small-7
Comodo 2517 2009.10.05 Heur.Packed.Unknown
DrWeb 5.0.0.12182 2009.10.05 -
eSafe 7.0.17.0 2009.10.04 Suspicious File
eTrust-Vet 31.6.6777 2009.10.05 -
F-Prot 4.5.1.85 2009.10.04 W32/OnlineGames!Generic
F-Secure 8.0.14470.0 2009.10.05 Trojan-GameThief.Win32.OnLineGames.vrbp
Fortinet 3.120.0.0 2009.10.05 PossibleThreat
GData 19 2009.10.05 -
Ikarus T3.1.1.72.0 2009.10.05 Trojan-PWS.Win32.Lmir.AGP
Jiangmin 11.0.800 2009.10.05 -
K7AntiVirus 7.10.861 2009.10.03 -
Kaspersky 7.0.0.125 2009.10.05 Trojan-GameThief.Win32.OnLineGames.vrbp
McAfee 5761 2009.10.04 -
McAfee+Artemis 5761 2009.10.04 Suspect-29!4B986C7E95E6
McAfee-GW-Edition 6.8.5 2009.10.05 Heuristic.BehavesLike.Win32.Dropper.H
Microsoft 1.5101 2009.10.05 Trojan:Win32/Helpud.A
NOD32 4480 2009.10.05 -
Norman 6.01.09 2009.10.05 W32/Obfuscated.A2!genr
nProtect 2009.1.8.0 2009.10.05 -
Panda 10.0.2.2 2009.10.04 Trj/CI.A
PCTools 4.4.2.0 2009.10.05 Packed/NSPack
Prevx 3.0 2009.10.05 Medium Risk Malware
Rising 21.49.22.00 2009.09.30 -
Sophos 4.45.0 2009.10.05 Mal/Packer
Sunbelt 3.2.1858.2 2009.10.04 Trojan.Win32.Generic!BT
Symantec 1.4.4.12 2009.10.05 W32.Gammima
TheHacker 6.5.0.2.029 2009.10.05 -
TrendMicro 8.950.0.1094 2009.10.05 -
VBA32 3.12.10.11 2009.10.05 -
ViRobot 2009.10.5.1970 2009.10.05 -
VirusBuster 4.6.5.0 2009.10.04 Packed/NSPack
Additional information
File size: 243253 bytes
MD5   : 4b986c7e95e673bea996c6613a245030
SHA1  : d08552d2bcf1ed478861675044cc54a2fabf5d81
SHA256: c770284c6ee6aafe1134ef4f8f83c0eae4526dbcbf7d5d6b2523c9a738dcb839
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1000
timedatestamp.....: 0x4894133D (Sat Aug 2 09:56:45 2008)
machinetype.......: 0x14C (Intel I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x14000 0x13A00 6.48 b4fb79885c55492e7af6d4be13b922cf
.data 0x15000 0x8000 0xA00 4.94 6b3642729564e92f38646d9f50a5c940
.idata 0x1D000 0x2000 0x1200 4.79 4223794b90a12cb19ec33fbd0cd56503
.rsrc 0x1F000 0x4000 0x3C00 4.95 30d6daba82d6c31d85a04377eeca6af9

( 8 imports )

> advapi32.dll: AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA, SetFileSecurityA, SetFileSecurityW
> comctl32.dll: -
> comdlg32.dll: CommDlgExtendedError, GetOpenFileNameA, GetSaveFileNameA
> gdi32.dll: DeleteObject
> kernel32.dll: CloseHandle, CompareStringA, CreateDirectoryA, CreateDirectoryW, CreateFileA, CreateFileW, DeleteFileA, DeleteFileW, DosDateTimeToFileTime, ExitProcess, ExpandEnvironmentStringsA, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, FindFirstFileA, FindFirstFileW, FindNextFileA, FindNextFileW, FindResourceA, FreeLibrary, GetCPInfo, GetCommandLineA, GetCurrentDirectoryA, GetCurrentProcess, GetDateFormatA, GetFileAttributesA, GetFileAttributesW, GetFileType, GetFullPathNameA, GetLastError, GetLocaleInfoA, GetModuleFileNameA, GetModuleFileNameW, GetModuleHandleA, GetNumberFormatA, GetProcAddress, GetProcessHeap, GetStdHandle, GetSystemTime, GetTempPathA, GetTickCount, GetTimeFormatA, GetVersionExA, GlobalAlloc, HeapAlloc, HeapFree, HeapReAlloc, IsDBCSLeadByte, LoadLibraryA, LocalFileTimeToFileTime, MoveFileA, MoveFileExA, MultiByteToWideChar, ReadFile, SetCurrentDirectoryA, SetEndOfFile, SetEnvironmentVariableA, SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFileTime, SetLastError, Sleep, SystemTimeToFileTime, WaitForSingleObject, WideCharToMultiByte, WriteFile, lstrcmpiA, lstrlenA
> ole32.dll: CLSIDFromString, CoCreateInstance, CreateStreamOnHGlobal, OleInitialize, OleUninitialize
> shell32.dll: SHBrowseForFolderA, SHChangeNotify, SHFileOperationA, SHGetFileInfoA, SHGetMalloc, SHGetSpecialFolderLocation, ShellExecuteExA, SHGetPathFromIDListA
> user32.dll: CharToOemA, CharToOemBuffA, CharUpperA, CopyRect, CreateWindowExA, DefWindowProcA, DestroyIcon, DestroyWindow, DialogBoxParamA, DispatchMessageA, EnableWindow, EndDialog, FindWindowExA, GetClassNameA, GetClientRect, GetDlgItem, GetDlgItemTextA, GetMessageA, GetParent, GetSysColor, GetSystemMetrics, GetWindow, GetWindowLongA, GetWindowRect, GetWindowTextA, IsWindow, IsWindowVisible, LoadBitmapA, LoadCursorA, LoadIconA, LoadStringA, MapWindowPoints, MessageBoxA, OemToCharA, OemToCharBuffA, PeekMessageA, PostMessageA, RegisterClassExA, SendDlgItemMessageA, SendMessageA, SetDlgItemTextA, SetFocus, SetMenu, SetWindowLongA, SetWindowPos, SetWindowTextA, ShowWindow, TranslateMessage, UpdateWindow, WaitForInputIdle, wsprintfA, wvsprintfA

( 0 exports )
TrID  : File type identification
WinRAR Self Extracting archive (95.7%)
Win32 Executable Generic (1.5%)
Win32 Dynamic Link Library (generic) (1.4%)
Win32 Executable Watcom C++ (generic) (0.4%)
Generic Win/DOS Executable (0.3%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=4b986c7e95e673bea996c6613a245030
ssdeep: 6144:Bs0QZboaDpb/UJkfMthdNKnxplA1a/wwLI1ADZ:tQ1DfEthdNWxplA1+Fr
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=80B6C6FA358FD7DBB6830394B5E8A900E3D8FB8E
PEiD  : -
packers (Kaspersky): NSPack
packers (F-Prot): RAR, NSPack, PE_Patch
packers (Authentium): RAR, NSPack, PE_Patch
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file