VT Community Sign in ▼ Languages ▼
VirusTotal's website has changed, we need new translations, do you feel like helping the community?
Sign in to VT Community

Safety ratings and user comments (disinfection, in-the-wild locations, reverse engineering reports, etc.) on malware and URLs, free and easy.

email
password
Keep me logged in
Forgot your password? Create an account
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
Stopuhr.exe
Submission date:
2010-04-29 22:20:48 (UTC)
Current status:
finished
Result:
18 /41 (43.9%)
VT Community

not reviewed
 Safety score: - 
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.04.29 -
AhnLab-V3 2010.04.29.05 2010.04.29 Packed/Upack
AntiVir 8.2.1.224 2010.04.29 -
Antiy-AVL 2.0.3.7 2010.04.29 -
Authentium 5.2.0.5 2010.04.29 W32/Heuristic-210!Eldorado
Avast 4.8.1351.0 2010.04.29 -
Avast5 5.0.332.0 2010.04.29 -
AVG 9.0.0.787 2010.04.29 Suspicion: unknown virus
BitDefender 7.2 2010.04.29 -
CAT-QuickHeal 10.00 2010.04.29 (Suspicious) - DNAScan
ClamAV 0.96.0.3-git 2010.04.29 PUA.Packed.Upack39
Comodo 4712 2010.04.29 TrojWare.Win32.TrojanDownloader.Agent.~d018
DrWeb 5.0.2.03300 2010.04.29 -
eSafe 7.0.17.0 2010.04.29 Suspicious File
eTrust-Vet 35.2.7457 2010.04.29 -
F-Prot 4.5.1.85 2010.04.29 W32/Heuristic-210!Eldorado
F-Secure 9.0.15370.0 2010.04.29 Suspicious:W32/Malware!Gemini
Fortinet 4.0.14.0 2010.04.27 -
GData 21 2010.04.29 -
Ikarus T3.1.1.80.0 2010.04.29 -
Jiangmin 13.0.900 2010.04.29 -
Kaspersky 7.0.0.125 2010.04.29 -
McAfee 5.400.0.1158 2010.04.29 Suspect-26!D3F10617D89B
McAfee-GW-Edition 6.8.5 2010.04.29 -
Microsoft 1.5703 2010.04.29 -
NOD32 5073 2010.04.29 -
Norman 6.04.12 2010.04.29 W32/Packed_Upack.A
nProtect 2010-04-29.01 2010.04.29 -
Panda 10.0.2.7 2010.04.29 -
PCTools 7.0.3.5 2010.04.29 Packed/Upack
Prevx 3.0 2010.04.29 -
Rising 22.45.03.03 2010.04.29 -
Sophos 4.53.0 2010.04.29 Mal/Behav-024
Sunbelt 6237 2010.04.29 Trojan.Win32.Packer.Upack0.3.9 (v)
Symantec 20091.2.0.41 2010.04.29 -
TheHacker 6.5.2.0.273 2010.04.29 W32/Behav-Heuristic-060
TrendMicro 9.120.0.1004 2010.04.29 Cryp_Xed-12
VBA32 3.12.12.4 2010.04.29 -
ViRobot 2010.4.27.2295 2010.04.28 -
VirusBuster 5.0.27.0 2010.04.29 Packed/Upack
Additional information
MD5   : d3f10617d89b2d9f20e3c5d4e33aa8eb
SHA1  : d380c1c2c7de5b236fe2ca84269cd99b57cfbea0
SHA256: 8f28fbd07c73d33414ef3ca7fe5caee7daa60c73f285bf3085f3ea2d9a9d88d1
ssdeep: 12288:iUkal/V7rEOvKRpjRhF3/rS6JTjp32ycecDXCCWFngCvhasgnPdtxymOmAPi:iUPtXEOS[*lb*]RdRLDS6pjp3fceWCCW9gC5kT
File size : 538400 bytes
First seen: 2010-04-29 22:20:48
Last seen : 2010-08-12 09:27:30
Magic: MS-DOS executable, MZ for MS-DOS
TrID:
DOS Executable Generic (100.0%)
sigcheck:
publisher....: MATHEsoft (R)[*lb*]copyright....: 2000-2010[*lb*]product......: Stop-Uhr Pro[*lb*]description..: Stopuhr Pro[*lb*]original name: stopuhr.exe[*lb*]internal name: STU[*lb*]file version.: 3.2.4.16[*lb*]comments.....: http://www.mathesoft.de[*lb*]signers......: -[*lb*]signing date.: -[*lb*]verified.....: Unsigned[*lb*]
PEiD: -
packers (Authentium): UPack, UPack, UPack
packers (F-Prot): UPack
packers (Kaspersky): PE_Patch, UPack
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x1018
timedatestamp....: 0x4011B0BE (Fri Jan 23 23:39:42 2004)
machinetype......: 0x14C (Intel I386)

[[ 3 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
PS, 0x1000, 0x1AC000, 0x1F0, 5.47, 60a70cbc57a8930e3f7b1ef25c5d5383
@c, 0x1AD000, 0x8B000, 0x83520, 7.98, 690ce30b894f9c81c02ef29955f56e90
Z@, 0x238000, 0x1000, 0x1F0, 5.47, 60a70cbc57a8930e3f7b1ef25c5d5383
Symantec reputation:Suspicious.Insight

VT Community

This file has never been reviewed by any VT Community member. Be the first one to comment on it!
VirusTotal Team
Add your comment... Remember that when you write comments as an anonymous user they receive the lowest possible reputation. So if you have not signed in yet don't forget to do so. How to markup your comments?
You can add basic styles to your comments using the following accepted bbcode tags:

[b]text[/b] -- bold
[i]text[/i] -- italics
[u]text[/u] -- underline
[s]text[/s] -- strikethrough
[code]text[/code] - preformatted text

You can also address comments to particular users using the "@" twitter-like mode. By prepending a "#" symbol to a word you can add custom tags to your comment, tags that can then be searched for.
Goodware
Malware
Spam attachment/link

P2P download
Propagating via IM
Network worm

Drive-by-download






ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.