Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File csrss.exe received on 2008.07.23 17:04:09 (UTC)
Current status: finished
Result: 21/35 (60.00%)
Antivirus Version Last Update Result
AhnLab-V3 2008.7.24.0 2008.07.23 -
AntiVir 7.8.1.11 2008.07.23 TR/Delf.cyw
Authentium 5.1.0.4 2008.07.23 -
Avast 4.8.1195.0 2008.07.23 Win32:Trojan-gen {Other}
AVG 8.0.0.130 2008.07.23 SHeur.BTKR
BitDefender 7.2 2008.07.23 Dropped:Trojan.Generic.360795
CAT-QuickHeal 9.50 2008.07.22 Trojan.Delf.cyw
ClamAV 0.93.1 2008.07.23 Trojan.Delf-5995
DrWeb 4.44.0.09170 2008.07.23 Trojan.PWS.Banker.21635
eSafe 7.0.17.0 2008.07.23 Win32.Delf.cyw
eTrust-Vet 31.6.5976 2008.07.23 Win32/VMalum.DPOK
Ewido 4.0 2008.07.23 Trojan.Delf.cyw
F-Prot 4.4.4.56 2008.07.22 -
F-Secure 7.60.13501.0 2008.07.23 Trojan.Win32.Delf.cyw
Fortinet 3.14.0.0 2008.07.23 -
GData 2.0.7306.1023 2008.07.23 Trojan.Win32.Delf.cyw
Ikarus T3.1.1.34.0 2008.07.23 Trojan.Win32.Delf.cyw
Kaspersky 7.0.0.125 2008.07.23 Trojan.Win32.Delf.cyw
McAfee 5345 2008.07.23 -
Microsoft 1.3704 2008.07.23 -
NOD32v2 3292 2008.07.23 -
Norman 5.80.02 2008.07.23 -
Panda 9.0.0.4 2008.07.23 Suspicious file
PCTools 4.4.2.0 2008.07.23 -
Prevx1 V2 2008.07.23 -
Rising 20.54.22.00 2008.07.23 -
Sophos 4.31.0 2008.07.23 -
Sunbelt 3.1.1536.1 2008.07.18 Packed.Win32.NSAnti.e
Symantec 10 2008.07.23 Trojan Horse
TheHacker 6.2.96.387 2008.07.23 Trojan/Delf.cyw
TrendMicro 8.700.0.1004 2008.07.23 TROJ_DELF.JWL
VBA32 3.12.8.1 2008.07.23 Trojan.Win32.Delf.cyw
VIRobot 2008.7.23.1307 2008.07.23 -
VirusBuster 4.5.11.0 2008.07.23 -
Webwasher-Gateway 6.6.2 2008.07.23 Trojan.Delf.cyw
Additional information
File size: 284160 bytes
MD5...: f39fee75f46f4d6083bd56cb42f6b0c9
SHA1..: bf3ebcd0ac2807ddfb766d5dc6e438c11dab96fd
SHA256: 9ed4a928e9b132c368e8f8ee235933f9dd361c83855a2267f9615cd830e032d0
SHA512: 1f43d850b18fcb6548e18d474359fcc6c7d2ab9fe154f7358e5ac6f37e08f67d
a3b27cba876382eebb02dad424a36e1aa777839de325a286edbb43e3adaebe18
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4d1d50
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x8e000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x8f000 0x44000 0x43a00 8.00 bccf4d17c21178a5cbe353e5de5a9efe
.rsrc 0xd3000 0x2000 0x1800 2.51 6ac74c9de0f33bab6818fb4c3cea7199

( 10 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> advapi32.dll: RegFlushKey
> comctl32.dll: ImageList_Add
> gdi32.dll: SaveDC
> ole32.dll: OleDraw
> oleaut32.dll: VariantCopy
> shell32.dll: ShellExecuteA
> user32.dll: GetDC
> version.dll: VerQueryValueA
> wininet.dll: InternetGetConnectedState

( 0 exports )
packers (Kaspersky): UPX
packers (F-Prot): UPX_LZMA

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file