Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File server.exe received on 2008.12.12 10:05:11 (UTC)
Current status: finished
Result: 24/38 (63.16%)
Antivirus Version Last Update Result
AhnLab-V3 2008.12.12.0 2008.12.12 -
AntiVir 7.9.0.45 2008.12.12 TR/MSNPass.D
Authentium 5.1.0.4 2008.12.11 -
Avast 4.8.1281.0 2008.12.11 Win32:Trojan-gen {Other}
AVG 8.0.0.199 2008.12.12 PSW.VB.AAO
BitDefender 7.2 2008.12.12 Trojan.Generic.557149
CAT-QuickHeal 10.00 2008.12.11 Constructor.VB.ef (Not a Virus)
ClamAV 0.94.1 2008.12.12 -
Comodo 733 2008.12.11 -
DrWeb 4.44.0.09170 2008.12.12 -
eSafe 7.0.17.0 2008.12.11 Win32.VB.ef
eTrust-Vet 31.6.6257 2008.12.12 -
Ewido 4.0 2008.12.11 Not-A-Virus.Constructor.Win32.VB.ef
F-Prot 4.4.4.56 2008.12.11 -
F-Secure 8.0.14332.0 2008.12.12 Constructor.Win32.VB.ef
Fortinet 3.117.0.0 2008.12.12 W32/VB.EF!kit
GData 19 2008.12.12 Trojan.Generic.557149
Ikarus T3.1.1.45.0 2008.12.12 Backdoor.Win32.VB
K7AntiVirus 7.10.551 2008.12.11 Constructor.Win32.VB.ef
Kaspersky 7.0.0.125 2008.12.12 Constructor.Win32.VB.ef
McAfee 5461 2008.12.11 Generic.dx
McAfee+Artemis 5461 2008.12.11 Generic.dx
Microsoft 1.4205 2008.12.12 VirTool:Win32/Vtub.AM
NOD32 3685 2008.12.12 -
Norman 5.80.02 2008.12.11 W32/Smalltroj.JDTZ
Panda 9.0.0.4 2008.12.11 Adware/AccesMembre
PCTools 4.4.2.0 2008.12.11 -
Prevx1 V2 2008.12.12 Spyware
Rising 21.07.42.00 2008.12.12 -
SecureWeb-Gateway 6.7.6 2008.12.12 Trojan.MSNPass.D
Sophos 4.36.0 2008.12.12 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.12 Trojan Horse
TheHacker 6.3.1.2.184 2008.12.11 Trojan/Constructor.VB.ef
TrendMicro 8.700.0.1004 2008.12.12 -
VBA32 3.12.8.10 2008.12.11 Constructor.Win32.VB.ef
ViRobot 2008.12.12.1515 2008.12.12 Not_a_virus:Constructor.VB.49195.A
VirusBuster 4.5.11.0 2008.12.11 -
Additional information
File size: 49195 bytes
MD5...: e4696fa38947f08e81cfd177ebbc661f
SHA1..: be1e73e509aa4088164eaf12028143ff48ba61c0
SHA256: 6da7191e4a23670c13655398bb02ea0ad6ca60dd1ba4982d7038097c27b1d112
SHA512: f22251224a534ff43c08465e0bd4b6d042663ecba3f394e6ac02f7069f211819
1e900a6f76463617ddbeae214e675f2c23f614b74dea654efe88aae2d8734527
ssdeep: 768:e/gIxoVHvokGGB8VFHJ9vo93wyo1XXwTi8he:e/gI2UGB8OqXAbhe
PEiD..: -
TrID..: File type identification
Win32 Executable Microsoft Visual Basic 6 (86.2%)
Win32 Executable Generic (5.8%)
Win32 Dynamic Link Library (generic) (5.1%)
Generic Win/DOS Executable (1.3%)
DOS Executable Generic (1.3%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x401654
timedatestamp.....: 0x48067450 (Wed Apr 16 21:49:04 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x86fc 0x9000 5.60 2014a79b86bf11c5aecb5c45466d2a16
.data 0xa000 0xd84 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rsrc 0xb000 0x5c0 0x1000 1.55 a82d7745da2b070044d1bebe656f8d40

( 1 imports )
> MSVBVM60.DLL: _CIcos, _adj_fptan, __vbaStrI4, __vbaVarVargNofree, __vbaAryMove, __vbaFreeVar, __vbaLateIdCall, __vbaStrVarMove, __vbaLenBstr, __vbaEnd, __vbaFreeVarList, _adj_fdiv_m64, __vbaFreeObjList, -, _adj_fprem1, __vbaRecAnsiToUni, __vbaStrCat, __vbaSetSystemError, __vbaRecDestruct, __vbaHresultCheckObj, _adj_fdiv_m32, __vbaAryVar, -, __vbaAryDestruct, __vbaForEachCollObj, __vbaExitProc, __vbaObjSet, __vbaOnError, __vbaVargObj, _adj_fdiv_m16i, __vbaObjSetAddref, _adj_fdivr_m16i, -, __vbaBoolVar, __vbaVargVar, _CIsin, -, __vbaErase, __vbaNextEachCollObj, -, __vbaChkstk, __vbaFileClose, -, EVENT_SINK_AddRef, __vbaGenerateBoundsError, __vbaGet3, -, __vbaStrCmp, __vbaAryConstruct2, DllFunctionCall, __vbaRedimPreserve, _adj_fpatan, __vbaLateIdCallLd, __vbaRedim, __vbaRecUniToAnsi, EVENT_SINK_Release, __vbaUI1I2, _CIsqrt, __vbaObjIs, EVENT_SINK_QueryInterface, __vbaUI1I4, __vbaExceptHandler, -, __vbaPrintFile, __vbaStrToUnicode, -, _adj_fprem, _adj_fdivr_m64, -, __vbaI2Str, __vbaFailedFriend, __vbaFPException, -, __vbaStrVarVal, __vbaUbound, __vbaVarCat, -, -, -, _CIlog, __vbaErrorOverflow, __vbaFileOpen, -, __vbaInStr, __vbaVar2Vec, __vbaNew2, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, __vbaI4Str, __vbaFreeStrList, _adj_fdivr_m32, _adj_fdiv_r, -, __vbaI4Var, __vbaAryLock, __vbaVarDup, __vbaStrToAnsi, -, __vbaFpI4, __vbaUnkVar, __vbaLateMemCallLd, _CIatan, __vbaAryCopy, __vbaStrMove, __vbaCastObj, _allmul, __vbaLateIdSt, _CItan, __vbaAryUnlock, _CIexp, __vbaRecAssign, __vbaFreeStr, __vbaFreeObj, -

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=02E7A90A2B7BE01CC08D0017C7C50100F6038C9D
CWSandbox info: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=e4696fa38947f08e81cfd177ebbc661f

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file