Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | English
Virus Total

Virustotal es un servicio de análisis de archivos sospechosos que permite detectar virus, gusanos, troyanos, y malware en general. Más información...

Análisis del archivo HPIEAddOn.dll recibido el 2009.09.14 16:58:35 (UTC)
Estado actual: análisis terminado
Resultado: 7/41 (17.07%)
Motor antivirus Versión Última actualización Resultado
a-squared 4.5.0.24 2009.09.14 -
AhnLab-V3 5.0.0.2 2009.09.14 -
AntiVir 7.9.1.14 2009.09.14 -
Antiy-AVL 2.0.3.7 2009.09.14 -
Authentium 5.1.2.4 2009.09.14 -
Avast 4.8.1351.0 2009.09.14 -
AVG 8.5.0.412 2009.09.14 Generic4.LYJ
BitDefender 7.2 2009.09.14 -
CAT-QuickHeal 10.00 2009.09.14 -
ClamAV 0.94.1 2009.09.14 -
Comodo 2317 2009.09.14 -
DrWeb 5.0.0.12182 2009.09.14 -
eSafe 7.0.17.0 2009.09.14 -
eTrust-Vet 31.6.6736 2009.09.14 -
F-Prot 4.5.1.85 2009.09.14 -
F-Secure 8.0.14470.0 2009.09.13 -
Fortinet 3.120.0.0 2009.09.14 Adware/DoubleD
GData 19 2009.09.14 -
Ikarus T3.1.1.72.0 2009.09.14 -
Jiangmin 11.0.800 2009.09.14 -
K7AntiVirus 7.10.844 2009.09.14 -
Kaspersky 7.0.0.125 2009.09.14 -
McAfee 5741 2009.09.14 potentially unwanted program Adware-DoubleD
McAfee+Artemis 5741 2009.09.14 potentially unwanted program Adware-DoubleD
McAfee-GW-Edition 6.8.5 2009.09.14 -
Microsoft 1.5005 2009.09.14 -
NOD32 4425 2009.09.14 a variant of Win32/Adware.DoubleD.AE
Norman 6.01.09 2009.09.14 -
nProtect 2009.1.8.0 2009.09.14 -
Panda 10.0.2.2 2009.09.13 Suspicious file
PCTools 4.4.2.0 2009.09.14 -
Prevx 3.0 2009.09.14 -
Rising 21.47.04.00 2009.09.14 -
Sophos 4.45.0 2009.09.14 Media Access Startup
Sunbelt 3.2.1858.2 2009.09.13 -
Symantec 1.4.4.12 2009.09.14 -
TheHacker 6.3.4.4.402 2009.09.12 -
TrendMicro 8.950.0.1094 2009.09.14 -
VBA32 3.12.10.10 2009.09.13 -
ViRobot 2009.9.14.1934 2009.09.14 -
VirusBuster 4.6.5.0 2009.09.14 -
Información adicional
File size: 221184 bytes
MD5   : e35bbcc732c34897917729c182915972
SHA1  : 7e8e06ec6467a1e6497722df80d87ebac24a122d
SHA256: 09a381ac0077d7e272fa1d82192b28bcba08d30e4151510041a10df7ebc3b943
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x12D25
timedatestamp.....: 0x4AA62552 (Tue Sep 8 11:35:14 2009)
machinetype.......: 0x14C (Intel I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x23D0C 0x24000 6.67 d4112fc7746f45c3e9804f0af9aa2173
.rdata 0x25000 0x8EF8 0x9000 4.86 c8f9eb8958035a3f723c76d75185b0d8
.data 0x2E000 0x3E60 0x2000 4.36 b4c198f08c4aa7e187a3ece0b980761a
.rsrc 0x32000 0x10D8 0x2000 4.72 58977802fce20cf952a18eca92ff6ef4
.reloc 0x34000 0x3C24 0x4000 4.69 3411ff9d31c5943e8bd4c68a2812d33b

( 11 imports )

> advapi32.dll: CryptGetKeyParam, CryptCreateHash, CryptHashData, CryptDeriveKey, CryptDestroyHash, CryptDestroyKey, CryptReleaseContext, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, CryptEncrypt, RegDeleteKeyW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegQueryValueExW, RegEnumKeyExW, RegCreateKeyW, RegQueryInfoKeyW, RegSetValueExW, RegOpenKeyExW, CryptAcquireContextW
> hpcommon.dll: __1CNPConfigMgr@@UAE@XZ, __0CNPConfigMgr@@QAE@XZ
> kernel32.dll: CloseHandle, ExitThread, SetEvent, Sleep, WaitForSingleObject, GetExitCodeProcess, TerminateThread, CreateProcessW, GetModuleHandleW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, FreeLibrary, CreateThread, GetModuleFileNameW, FindFirstFileW, DeleteFileW, FindNextFileW, FindClose, RemoveDirectoryW, OutputDebugStringW, DebugBreak, lstrlenA, lstrcmpiW, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, RaiseException, MultiByteToWideChar, CreateEventW, DisableThreadLibraryCalls, WideCharToMultiByte, InterlockedIncrement, GetLastError, InterlockedDecrement, lstrlenW, WaitForMultipleObjects, GetExitCodeThread, ResetEvent, CreateMutexW, ReleaseMutex, GlobalFree, GlobalAlloc, InterlockedExchange, GetACP, GetLocaleInfoA, GetThreadLocale, GetVersionExA, RtlUnwind, HeapFree, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapAlloc, MoveFileW, HeapReAlloc, GetSystemTimeAsFileTime, GetCurrentThreadId, GetCommandLineA, GetProcessHeap, LCMapStringA, LCMapStringW, GetCPInfo, GetProcAddress, GetModuleHandleA, ExitProcess, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, WriteFile, GetStdHandle, GetModuleFileNameA, SetHandleCount, GetFileType, GetStartupInfoA, GetConsoleCP, GetConsoleMode, FlushFileBuffers, SetFilePointer, GetOEMCP, IsValidCodePage, HeapSize, GetTimeZoneInformation, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetStringTypeA, GetStringTypeW, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, LoadLibraryA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetStdHandle, GetLocaleInfoW, CreateFileA, CompareStringA, CompareStringW, SetEnvironmentVariableA, GetVersionExW, LoadLibraryW
> ole32.dll: CoTaskMemAlloc, StringFromGUID2, CoTaskMemRealloc, CoCreateInstance, CoTaskMemFree
> oleaut32.dll: -, -, -, -, -, -, -, -, -, -, -
> shell32.dll: SHGetFolderPathW
> shlwapi.dll: UrlGetPartW
> urlmon.dll: URLDownloadToFileW
> user32.dll: wvsprintfW, wsprintfW, CharLowerW, UnregisterClassA, CharNextW, LoadStringW
> version.dll: VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
> wininet.dll: HttpQueryInfoW, InternetConnectW, HttpOpenRequestW, HttpSendRequestW, InternetCloseHandle, InternetOpenW

( 1 exports )

> DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer
TrID  : File type identification
DirectShow filter (52.6%)
Windows OCX File (32.2%)
Win32 Executable MS Visual C++ (generic) (9.8%)
Win32 Executable Generic (2.2%)
Win32 Dynamic Link Library (generic) (1.9%)
ssdeep: 3072:vf+pPeDQ/fiby5S9GBaBkEQyemOZGhQpkCIGtjdPlTOY:vfWmxjGweDUSkCd9T
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=90735E72004905D2602F0391351F1B003DE14E5D
PEiD  : -
RDS   : NSRL Reference Data Set
-

Importante IMPORTANTE: VirusTotal es un servicio gratuito ofrecido por Hispasec Sistemas, quien no garantiza la disponibilidad y continuidad de funcionamiento de éste. Pese a que el índice de detección ofrecido por el análisis simultáneo de múltiples motores antivirus es muy superior al de un sólo producto, los resultados NO garantizan la inocuidad de un archivo. No existe solución que pueda ofrecer un 100% de efectividad en el reconocimiento de virus y malware en general.

Analizar otro archivo