Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File 1st-Hacks.exe received on 2009.06.20 09:04:20 (UTC)
Current status: finished
Result: 1/41 (2.44%)
Antivirus Version Last Update Result
a-squared 4.5.0.18 2009.06.20 -
AhnLab-V3 5.0.0.2 2009.06.19 -
AntiVir 7.9.0.193 2009.06.19 -
Antiy-AVL 2.0.3.1 2009.06.19 -
Authentium 5.1.2.4 2009.06.19 -
Avast 4.8.1335.0 2009.06.19 -
AVG 8.5.0.339 2009.06.20 -
BitDefender 7.2 2009.06.20 -
CAT-QuickHeal 10.00 2009.06.19 -
ClamAV 0.94.1 2009.06.20 -
Comodo 1377 2009.06.20 -
DrWeb 5.0.0.12182 2009.06.20 -
eSafe 7.0.17.0 2009.06.18 Win32.Downloader.aut
eTrust-Vet 31.6.6570 2009.06.19 -
F-Prot 4.4.4.56 2009.06.19 -
F-Secure 8.0.14470.0 2009.06.19 -
Fortinet 3.117.0.0 2009.06.19 -
GData 19 2009.06.20 -
Ikarus T3.1.1.59.0 2009.06.20 -
Jiangmin 11.0.706 2009.06.20 -
K7AntiVirus 7.10.768 2009.06.19 -
Kaspersky 7.0.0.125 2009.06.20 -
McAfee 5651 2009.06.19 -
McAfee+Artemis 5651 2009.06.19 -
McAfee-GW-Edition 6.7.6 2009.06.19 -
Microsoft 1.4803 2009.06.20 -
NOD32 4173 2009.06.20 -
Norman 6.01.09 2009.06.19 -
nProtect 2009.1.8.0 2009.06.20 -
Panda 10.0.0.16 2009.06.19 -
PCTools 4.4.2.0 2009.06.19 -
Prevx 3.0 2009.06.20 -
Rising 21.34.52.00 2009.06.20 -
Sophos 4.42.0 2009.06.20 -
Sunbelt 3.2.1858.2 2009.06.20 -
Symantec 1.4.4.12 2009.06.20 -
TheHacker 6.3.4.3.348 2009.06.19 -
TrendMicro 8.950.0.1094 2009.06.19 -
VBA32 3.12.10.7 2009.06.20 -
ViRobot 2009.6.19.1796 2009.06.19 -
VirusBuster 4.6.5.0 2009.06.19 -
Additional information
File size: 847254 bytes
MD5   : 92202fea067c30c452badf91eaaec4d9
SHA1  : 8bf6e5b366e4b505306f552a73de0fbaf8485334
SHA256: c7e09c6be7d7abbd6f5c7ba0704c19558d64b427749967c2bcfc94d967131205
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1240
timedatestamp.....: 0x48B3285F (Mon Aug 25 23:47:11 2008)
machinetype.......: 0x14C (Intel I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3E140 0x3E200 6.09 01a3b818249f8a89a35540fefd0a8f02
.data 0x40000 0x190 0x200 1.21 7ad2d8b0836bd28294f0dd6dc5ff75a2
.rdata 0x41000 0x2690 0x2800 5.08 8e6e6f547eebf0acf2e33ed444f842f7
.bss 0x44000 0x4C10 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0x49000 0xB38 0xC00 4.78 3057199323067216bb3465a1ddac4c36
.rsrc 0x4A000 0x5822C 0x58400 4.58 013c134b98aaafd541524ad3a19f7c25

( 5 imports )

> gdi32.dll: GetStockObject, GetTextMetricsA, SelectObject
> kernel32.dll: AddAtomA, CreateSemaphoreA, ExitProcess, FindAtomA, GetAtomNameA, GetCommandLineA, GetLastError, GetModuleHandleA, GetStartupInfoA, InterlockedDecrement, InterlockedIncrement, ReleaseSemaphore, SetLastError, SetUnhandledExceptionFilter, Sleep, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, WaitForSingleObject
> msvcrt.dll: _fdopen, _read, _strdup, _write, __getmainargs, __mb_cur_max, __p__environ, __p__fmode, __set_app_type, _assert, _cexit, _ctype, _errno, _filelengthi64, _fstati64, _iob, _isctype, _lseeki64, _onexit, _pctype, _setmode, _strnicmp, _vsnprintf, abort, atexit, fclose, fflush, fgetpos, fopen, fprintf, fread, free, fsetpos, fwrite, getc, localeconv, malloc, memchr, memcpy, memmove, memset, putc, setlocale, setvbuf, signal, strcmp, strcoll, strcpy, strftime, strlen, strtod, strxfrm, ungetc
> shell32.dll: ShellExecuteA
> user32.dll: BeginPaint, CreateWindowExA, DefWindowProcA, DestroyWindow, DispatchMessageA, DrawTextA, EndPaint, GetClientRect, GetDC, GetMessageA, GetSystemMetrics, LoadCursorA, LoadIconA, MoveWindow, PostQuitMessage, RegisterClassExA, ReleaseDC, ShowWindow, TranslateMessage, UpdateWindow

( 0 exports )
TrID  : File type identification
58.4% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win32 Executable Generic (8527/13/3)
14.1% (.DLL) Win32 Dynamic Link Library (generic) (7583/30/2)
3.8% (.EXE) Win16/32 Executable Delphi generic (2072/23)
3.7% (.EXE) Generic Win/DOS Executable (2002/3)
ssdeep: 24576:6ry1ZZuB7UstjHccEN0H7lSVZ2VDb4nWS/H:pJcEN0H7lSVZ2V4nZ
PEiD  : -
CWSandbox: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=92202fea067c30c452badf91eaaec4d9
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file