Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File xloader.exe received on 2008.11.13 01:25:36 (UTC)
Current status: finished
Result: 6/36 (16.67%)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.13.0 2008.11.12 -
AntiVir 7.9.0.31 2008.11.12 -
Authentium 5.1.0.4 2008.11.12 -
Avast 4.8.1248.0 2008.11.12 -
AVG 8.0.0.199 2008.11.12 -
BitDefender 7.2 2008.11.12 -
CAT-QuickHeal 9.50 2008.11.12 -
ClamAV 0.94.1 2008.11.12 -
DrWeb 4.44.0.09170 2008.11.13 -
eSafe 7.0.17.0 2008.11.12 Suspicious File
eTrust-Vet 31.6.6204 2008.11.11 -
Ewido 4.0 2008.11.12 -
F-Prot 4.4.4.56 2008.11.12 -
F-Secure 8.0.14332.0 2008.11.12 -
Fortinet 3.117.0.0 2008.11.12 -
GData 19 2008.11.12 -
Ikarus T3.1.1.45.0 2008.11.12 Trojan-Downloader.Win32.Elfph
K7AntiVirus 7.10.523 2008.11.12 -
Kaspersky 7.0.0.125 2008.11.13 Trojan-Downloader.Win32.Small.agfc
McAfee 5432 2008.11.13 -
Microsoft 1.4104 2008.11.13 TrojanDownloader:Win32/Elfph
NOD32 3607 2008.11.12 -
Norman 5.80.02 2008.11.12 -
Panda 9.0.0.4 2008.11.12 -
PCTools 4.4.2.0 2008.11.13 -
Prevx1 V2 2008.11.13 Information Stealer
Rising 21.03.22.00 2008.11.12 -
SecureWeb-Gateway 6.7.6 2008.11.12 -
Sophos 4.35.0 2008.11.13 -
Sunbelt 3.1.1785.2 2008.11.11 -
Symantec 10 2008.11.13 -
TheHacker 6.3.1.1.151 2008.11.13 -
TrendMicro 8.700.0.1004 2008.11.13 PAK_Generic.001
VBA32 3.12.8.9 2008.11.12 -
ViRobot 2008.11.12.1463 2008.11.12 -
VirusBuster 4.5.11.0 2008.11.12 -
Additional information
File size: 15872 bytes
MD5...: efe48c6ea123b7d5a07f1beaf4b9efb1
SHA1..: 9abf6e3aff651d8c0fa88b34f4de3ce728cb495f
SHA256: f6fd88d64cede2df2ffda4ce98633e1b4b65588ae4a4e9897aabc3ea24c75d53
SHA512: 688524144de9e64d65f87af39e016aa9132939cc6958002aa9ca0c48e5b17d47
12c1f5c3db06c4be434660e4d97c1f3b723c11671a23831f048200acc5e88eb7
PEiD..: -
TrID..: File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x40e4c0
timedatestamp.....: 0x490e49b2 (Mon Nov 03 00:45:38 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0xa000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0xb000 0x4000 0x3800 7.51 52e10f06971d9f57788f9854aa0b43c9
UPX2 0xf000 0x1000 0x200 2.34 069ad20d0699cdec5c3f0e8f59942268

( 3 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> GDI32.dll: CancelDC
> USER32.dll: wsprintfA

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=465E0CB500586C013E6B00C2E6802800FC2C794E
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file