Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | English
Virus Total

Virustotal es un servicio de análisis de archivos sospechosos que permite detectar virus, gusanos, troyanos, y malware en general. Más información...

Análisis del archivo KukuTimer.exe recibido el 2009.01.04 09:15:44 (UTC)
Estado actual: análisis terminado
Resultado: 1/38 (2.63%)
Motor antivirus Versión Última actualización Resultado
a-squared 4.0.0.73 2009.01.03 -
AhnLab-V3 2008.12.31.0 2009.01.03 -
AntiVir 7.9.0.45 2009.01.03 -
Authentium 5.1.0.4 2009.01.03 -
Avast 4.8.1281.0 2009.01.03 -
AVG 8.0.0.199 2009.01.03 Logger.GCV
BitDefender 7.2 2009.01.04 -
CAT-QuickHeal 10.00 2009.01.03 -
ClamAV 0.94.1 2009.01.04 -
Comodo 869 2009.01.03 -
DrWeb 4.44.0.09170 2009.01.04 -
eTrust-Vet 31.6.6289 2009.01.02 -
Ewido 4.0 2008.12.31 -
F-Prot 4.4.4.56 2009.01.03 -
F-Secure 8.0.14470.0 2009.01.04 -
Fortinet 3.117.0.0 2009.01.04 -
GData 19 2009.01.04 -
Ikarus T3.1.1.45.0 2009.01.03 -
K7AntiVirus 7.10.575 2009.01.03 -
Kaspersky 7.0.0.125 2009.01.04 -
McAfee 5483 2009.01.03 -
McAfee+Artemis 5483 2009.01.03 -
Microsoft 1.4205 2009.01.04 -
NOD32 3734 2009.01.03 -
Norman 5.80.02 2009.01.02 -
Panda 9.0.0.4 2009.01.03 -
PCTools 4.4.2.0 2009.01.03 -
Prevx1 V2 2009.01.04 -
Rising 21.10.62.00 2009.01.04 -
SecureWeb-Gateway 6.7.6 2009.01.03 -
Sophos 4.37.0 2009.01.04 -
Sunbelt 3.2.1809.2 2008.12.22 -
Symantec 10 2009.01.04 -
TheHacker 6.3.1.4.204 2009.01.02 -
TrendMicro 8.700.0.1004 2009.01.04 -
VBA32 3.12.8.10 2009.01.03 -
ViRobot 2009.1.3.1541 2009.01.03 -
VirusBuster 4.5.11.0 2009.01.03 -
Información adicional
File size: 826100 bytes
MD5...: ea01938182c4320f141744daee951fbd
SHA1..: 9a4eea108088b7f55153ba47a4067628eb22e239
SHA256: 510a31e01fadb9fbbc4c4cd9adcabefcf3b2bc4cc1fa2734f494b93d260a5992
SHA512: dff93d9943703aa71b2f2c7272f28f096775585609ec4116162653601c357477
5b94c8d133c74648257d835c38135ad39c3ad118ee500b2094a8547b7c114a21
ssdeep: 12288:uhXYR6onRZt5RquwADt+w5bDDcN4DENmVFaJSk7ODEGSA:monRHrqGd5PA
e4sVoJ37o
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (29.4%)
UPX compressed Win32 Executable (23.8%)
Win32 EXE Yoda's Crypter (20.7%)
Windows Screen Saver (10.2%)
Win32 Executable Generic (6.6%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4184cb
timedatestamp.....: 0x46aae3d1 (Sat Jul 28 06:36:01 2007)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1eaca 0x1f000 6.53 92c00f64087b0d5e6c6ad6b9445008c6
.rdata 0x20000 0x2ab6 0x3000 4.84 54eb09df53af92a5f1a951db220ef30e
.data 0x23000 0x2b98 0x1000 2.98 aaacdfff8d6dbd06487e2a5e8aa3dcb8
.rsrc 0x26000 0x41d4 0x5000 4.43 0c90e858151b8cbf0dbe728f0d8cc06b

( 10 imports )
> COMCTL32.dll: -
> KERNEL32.dll: SetEndOfFile, GetEnvironmentStrings, FreeEnvironmentStringsA, UnhandledExceptionFilter, VirtualQuery, VirtualProtect, GetCPInfo, GetOEMCP, GetACP, HeapSize, WriteFile, GetFileType, GetStdHandle, SetHandleCount, IsBadWritePtr, VirtualAlloc, VirtualFree, HeapCreate, HeapDestroy, ReadFile, CloseHandle, LCMapStringW, LCMapStringA, SetFilePointer, GetCurrentProcess, TerminateProcess, ExitProcess, SetUnhandledExceptionFilter, GetVersionExA, GetStartupInfoA, GetModuleHandleA, SetCurrentDirectoryA, SetEnvironmentVariableA, CreateDirectoryA, GetLastError, HeapReAlloc, GetFullPathNameA, GetCurrentDirectoryA, GetDriveTypeA, HeapFree, HeapAlloc, RtlUnwind, RaiseException, GetEnvironmentStringsW, IsBadReadPtr, IsBadCodePtr, SetStdHandle, FlushFileBuffers, CreateFileA, GetLocaleInfoA, GetStringTypeA, GetLocalTime, FindFirstFileA, FindNextFileA, FindClose, DeleteFileA, GetShortPathNameA, GlobalLock, GlobalUnlock, MulDiv, GlobalAlloc, GlobalFree, GetCommandLineA, Sleep, GetTickCount, GetSystemInfo, GlobalMemoryStatus, GetVersion, GetComputerNameA, GetWindowsDirectoryA, GetSystemDirectoryA, WinExec, FreeLibrary, WideCharToMultiByte, MultiByteToWideChar, LoadLibraryA, InterlockedExchange, GetSystemTimeAsFileTime, GetCurrentProcessId, GetProcAddress, GetModuleFileNameA, GetStringTypeW, QueryPerformanceCounter, GetCurrentThreadId, FreeEnvironmentStringsW
> USER32.dll: IsWindowEnabled, PostMessageA, GetSystemMetrics, ReleaseDC, SetFocus, GetFocus, GetDlgItemTextA, GetDlgCtrlID, IsDlgButtonChecked, CallWindowProcA, IsWindowVisible, UnregisterClassA, GetDC, LoadCursorA, RegisterClassA, DefWindowProcA, SetWindowLongA, InvalidateRect, BeginPaint, EndPaint, GetClientRect, FillRect, TabbedTextOutA, GetSysColor, MoveWindow, SetWindowTextA, GetActiveWindow, GetWindowLongA, FindWindowA, MsgWaitForMultipleObjects, PeekMessageA, GetMessageA, TranslateMessage, DispatchMessageA, MapVirtualKeyA, GetWindowRect, SetActiveWindow, SetWindowPos, GetAsyncKeyState, GetCursorPos, SetCursorPos, ShowCursor, MessageBoxA, EnumDisplaySettingsA, ChangeDisplaySettingsA, CreateWindowExA, ShowWindow, SendMessageA, DestroyWindow, LoadIconA
> GDI32.dll: CreateDIBSection, CreateCompatibleDC, Rectangle, DeleteDC, SetStretchBltMode, StretchBlt, Ellipse, MoveToEx, LineTo, SetPixel, GetPixel, GetTextExtentPoint32A, SetDIBColorTable, CreatePalette, SetBkMode, SetTextColor, CreateSolidBrush, CreatePen, GetStockObject, CreateFontIndirectA, GetTextMetricsA, SelectObject, DeleteObject, SelectPalette, RealizePalette, BitBlt, GetDeviceCaps
> comdlg32.dll: GetSaveFileNameA, ChooseColorA, GetOpenFileNameA
> ADVAPI32.dll: GetUserNameA
> SHELL32.dll: ShellExecuteExA, SHGetSpecialFolderPathA, ShellExecuteA
> ole32.dll: OleInitialize, IIDFromString, CLSIDFromProgID, OleUninitialize, CreateStreamOnHGlobal, CoInitializeEx, CoUninitialize, CoCreateInstance
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> WINMM.dll: sndPlaySoundA, mciSendStringA

( 0 exports )
packers (Kaspersky): PE_Patch.UPX, UPX

Importante IMPORTANTE: VirusTotal es un servicio gratuito ofrecido por Hispasec Sistemas, quien no garantiza la disponibilidad y continuidad de funcionamiento de éste. Pese a que el índice de detección ofrecido por el análisis simultáneo de múltiples motores antivirus es muy superior al de un sólo producto, los resultados NO garantizan la inocuidad de un archivo. No existe solución que pueda ofrecer un 100% de efectividad en el reconocimiento de virus y malware en general.

Analizar otro archivo