Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | English
Virus Total

Virustotal es un servicio de análisis de archivos sospechosos que permite detectar virus, gusanos, troyanos, y malware en general. Más información...

Análisis del archivo postcard.exe recibido el 2008.12.18 18:12:21 (UTC)
Estado actual: análisis terminado
Resultado: 23/38 (60.53%)
Motor antivirus Versión Última actualización Resultado
AhnLab-V3 2008.12.19.0 2008.12.18 -
AntiVir 7.9.0.45 2008.12.18 BDS/Zapchast.PI
Authentium 5.1.0.4 2008.12.18 REG/Zapchast.H
Avast 4.8.1281.0 2008.12.18 VBS:Malware-gen
AVG 8.0.0.199 2008.12.18 BackDoor.Generic_c.CFI
BitDefender 7.2 2008.12.18 Dropped:Backdoor.Zapchast.PI
CAT-QuickHeal 10.00 2008.12.18 -
ClamAV 0.94.1 2008.12.18 Trojan.IRC.Zapchast-16
Comodo 771 2008.12.17 -
DrWeb 4.44.0.09170 2008.12.18 -
eSafe 7.0.17.0 2008.12.18 -
eTrust-Vet 31.6.6267 2008.12.18 -
Ewido 4.0 2008.12.18 -
F-Prot 4.4.4.56 2008.12.18 REG/Zapchast.H
F-Secure 8.0.14332.0 2008.12.18 Client-IRC.Win32.mIRC.603
Fortinet 3.117.0.0 2008.12.18 -
GData 19 2008.12.18 Dropped:Backdoor.Zapchast.PI
Ikarus T3.1.1.45.0 2008.12.18 -
K7AntiVirus 7.10.557 2008.12.18 Non-Virus:Client-IRC.Win32.mIRC.603
Kaspersky 7.0.0.125 2008.12.18 not-a-virus:Client-IRC.Win32.mIRC.603
McAfee 5468 2008.12.18 potentially unwanted program IRC/Client
McAfee+Artemis 5468 2008.12.18 potentially unwanted program IRC/Client
Microsoft 1.4205 2008.12.18 Backdoor:Win32/IRCFlood
NOD32 3703 2008.12.18 REG/RunKeys.NAA
Norman 5.80.02 2008.12.18 -
Panda 9.0.0.4 2008.12.18 BAT/Autorun.TA
PCTools 4.4.2.0 2008.12.18 Trojan.mIRC-Based.AM
Prevx1 V2 2008.12.18 -
Rising 21.08.32.00 2008.12.18 -
SecureWeb-Gateway 6.7.6 2008.12.18 -
Sophos 4.37.0 2008.12.18 Mal/Zapchas-A
Sunbelt 3.2.1801.2 2008.12.11 mIRC based
Symantec 10 2008.12.18 Backdoor.IRC.Aladinz
TheHacker 6.3.1.4.191 2008.12.17 -
TrendMicro 8.700.0.1004 2008.12.18 REG_ZAPCHAST.ED
VBA32 3.12.8.10 2008.12.18 BackDoor.IRC.based
ViRobot 2008.12.18.1525 2008.12.18 -
VirusBuster 4.5.11.0 2008.12.18 Trojan.mIRC-Based.AM
Información adicional
File size: 1281843 bytes
MD5...: 737e10be307601f22a491fd76798cd21
SHA1..: 9523bccfc96fd77228cb6b28dc06466ca2dbb76e
SHA256: ed94789d28aebf7ebf3ca87b4896260ce5e432a68696833df00f2a6652b700af
SHA512: 9eb79c54346f11fdf81fa8354b8202e4e8b7395efc725931418fbc3318cedcc4
080f18a4cc4a5716c22f70e0c15311b126523e78a636fcdd2e984422eae09d54
ssdeep: 24576:1nJ2kPyZvjXamZ4Nj9KRpRoUWmmKKR+Pz3VZcwZ60PX0wS7fLIugqOCpLv
:1J2hZbXnSNj4fWm/KUPDVZnZfPtELPg6
PEiD..: -
TrID..: File type identification
WinRAR Self Extracting archive (96.2%)
Win32 Executable Generic (1.5%)
Win32 Dynamic Link Library (generic) (1.4%)
Generic Win/DOS Executable (0.3%)
DOS Executable Generic (0.3%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x401000
timedatestamp.....: 0x43463a52 (Fri Oct 07 09:05:22 2005)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x13000 0x12600 6.46 bcefd13d879b5aa1628d5731462b1935
.data 0x14000 0x7000 0xa00 4.73 0eb9af4768d13f3fe805922a21fcbf55
.idata 0x1b000 0x1000 0x1000 5.02 7f9440e32acb299f3bda96288136b63a
.rsrc 0x1c000 0x46ce8 0x46e00 6.23 fd5ee05e6e48c036136c72401a64ebfa

( 8 imports )
> ADVAPI32.DLL: AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA, SetFileSecurityA, SetFileSecurityW
> KERNEL32.DLL: CloseHandle, CompareStringA, CreateDirectoryA, CreateDirectoryW, CreateFileA, CreateFileW, DeleteFileA, DeleteFileW, DosDateTimeToFileTime, ExitProcess, ExpandEnvironmentStringsA, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, FindFirstFileA, FindFirstFileW, FindNextFileA, FindNextFileW, FindResourceA, FreeLibrary, GetCPInfo, GetCommandLineA, GetCurrentDirectoryA, GetCurrentProcess, GetDateFormatA, GetFileAttributesA, GetFileAttributesW, GetFileType, GetFullPathNameA, GetLastError, GetLocaleInfoA, GetModuleFileNameA, GetModuleHandleA, GetNumberFormatA, GetProcAddress, GetProcessHeap, GetStdHandle, GetTempPathA, GetTickCount, GetTimeFormatA, GetVersionExA, GlobalAlloc, HeapAlloc, HeapFree, HeapReAlloc, IsDBCSLeadByte, LoadLibraryA, LocalFileTimeToFileTime, MoveFileA, MoveFileExA, MultiByteToWideChar, ReadFile, SetCurrentDirectoryA, SetEndOfFile, SetEnvironmentVariableA, SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFileTime, SetLastError, Sleep, SystemTimeToFileTime, WaitForSingleObject, WideCharToMultiByte, WriteFile, lstrcmpiA, lstrlenA
> COMCTL32.DLL: -
> COMDLG32.DLL: CommDlgExtendedError, GetOpenFileNameA
> GDI32.DLL: DeleteObject
> SHELL32.DLL: SHBrowseForFolderA, SHChangeNotify, SHFileOperationA, SHGetFileInfoA, SHGetMalloc, SHGetSpecialFolderLocation, ShellExecuteExA, SHGetPathFromIDListA
> USER32.DLL: CharToOemBuffA, CharUpperA, CopyRect, CreateWindowExA, DefWindowProcA, DestroyIcon, DestroyWindow, DialogBoxParamA, DispatchMessageA, EnableWindow, EndDialog, FindWindowExA, GetClassNameA, GetClientRect, GetDlgItem, GetDlgItemTextA, GetMessageA, GetParent, GetSysColor, GetSystemMetrics, GetWindow, GetWindowLongA, GetWindowRect, GetWindowTextA, IsWindow, IsWindowVisible, LoadBitmapA, LoadCursorA, LoadIconA, LoadStringA, MapWindowPoints, MessageBoxA, OemToCharA, OemToCharBuffA, PeekMessageA, PostMessageA, RegisterClassExA, SendDlgItemMessageA, SendMessageA, SetDlgItemTextA, SetFocus, SetMenu, SetWindowLongA, SetWindowPos, SetWindowTextA, ShowWindow, TranslateMessage, UpdateWindow, WaitForInputIdle, wsprintfA, wvsprintfA
> OLE32.DLL: CLSIDFromString, CoCreateInstance, CreateStreamOnHGlobal, OleInitialize, OleUninitialize

( 0 exports )
packers (F-Prot): RAR, Unicode
packers (Authentium): RAR, Unicode, RAR, RAR
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=737e10be307601f22a491fd76798cd21

Importante IMPORTANTE: VirusTotal es un servicio gratuito ofrecido por Hispasec Sistemas, quien no garantiza la disponibilidad y continuidad de funcionamiento de éste. Pese a que el índice de detección ofrecido por el análisis simultáneo de múltiples motores antivirus es muy superior al de un sólo producto, los resultados NO garantizan la inocuidad de un archivo. No existe solución que pueda ofrecer un 100% de efectividad en el reconocimiento de virus y malware en general.

Analizar otro archivo