|
VirusTotal je servis, ki analizira sumljive datoteke in omogoča hitro prepoznavanje virusov, črvov, trojanov in vseh ostalih zlonamernih programov katere prepoznajo antivirusni programi. Več informacij... |
| Antivirus | Verzija | Zadnja posodobitev | Rezultat |
|---|---|---|---|
| AhnLab-V3 | 2008.4.12.0 | 2008.04.14 | - |
| AntiVir | 7.6.0.85 | 2008.04.14 | HEUR/Malware |
| Authentium | 4.93.8 | 2008.04.13 | Possibly a new variant of W32/Blocker-based!Maximus |
| Avast | 4.8.1169.0 | 2008.04.14 | - |
| AVG | 7.5.0.516 | 2008.04.14 | - |
| BitDefender | 7.2 | 2008.04.14 | - |
| CAT-QuickHeal | 9.50 | 2008.04.12 | - |
| ClamAV | 0.92.1 | 2008.04.14 | - |
| DrWeb | 4.44.0.09170 | 2008.04.14 | - |
| eSafe | 7.0.15.0 | 2008.04.09 | - |
| eTrust-Vet | 31.3.5697 | 2008.04.14 | - |
| Ewido | 4.0 | 2008.04.14 | - |
| F-Prot | 4.4.2.54 | 2008.04.14 | W32/Blocker-based!Maximus |
| F-Secure | 6.70.13260.0 | 2008.04.14 | W32/Malware |
| FileAdvisor | 1 | 2008.04.14 | - |
| Fortinet | 3.14.0.0 | 2008.04.14 | - |
| Ikarus | T3.1.1.26.0 | 2008.04.14 | Trojan-Downloader.Win32.DlRhifrem.A |
| Kaspersky | 7.0.0.125 | 2008.04.14 | - |
| McAfee | 5272 | 2008.04.11 | - |
| Microsoft | 1.3408 | 2008.04.14 | TrojanDownloader:Win32/DlRhifrem.gen!A |
| NOD32v2 | 3024 | 2008.04.14 | probably unknown NewHeur_PE virus |
| Norman | 5.80.02 | 2008.04.12 | W32/Malware |
| Panda | 9.0.0.4 | 2008.04.13 | Suspicious file |
| Prevx1 | V2 | 2008.04.14 | - |
| Rising | 20.39.62.00 | 2008.04.13 | - |
| Sophos | 4.28.0 | 2008.04.14 | Mal/DllHook-A |
| Sunbelt | 3.0.1041.0 | 2008.04.12 | - |
| Symantec | 10 | 2008.04.14 | Trojan.Dropper |
| TheHacker | 6.2.92.276 | 2008.04.12 | - |
| VBA32 | 3.12.6.4 | 2008.04.14 | - |
| VirusBuster | 4.3.26:9 | 2008.04.13 | - |
| Webwasher-Gateway | 6.6.2 | 2008.04.14 | Heuristic.Malware |
| Dodatne informacije |
|---|
| File size: 65024 bytes |
| MD5...: c39d4fc8316ccbeeb37e0e336dadadbe |
| SHA1..: f0ea788d1577706d9527a204182ce7cc2a8ac5c2 |
| SHA256: 1dd7b431db43bffca6d8110b247c91ee5ea3667e98a93abc456a2cfb0586235b |
| SHA512: 9ac876dce261ef37e101809595ef6f5915359deb75c8c6678e136ef2f8c915e2 ca1b517364037b5b7431b2b3617a11f2cea706bb5b355756ae336a88b3616961 |
| PEiD..: - |
| PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x401240 timedatestamp.....: 0x47fe1b25 (Thu Apr 10 13:50:29 2008) machinetype.......: 0x14c (I386) ( 6 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x10e0 0x1200 5.01 3d7212ccc7cfe904e946a186435edd1d .data 0x3000 0x160 0x200 0.18 63a5024f142c3538726f972a90ba042f .rdata 0x4000 0x1e0 0x200 5.11 02e2c08c028f799ac4c6d4e70e7fa345 .bss 0x5000 0x60 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e .idata 0x6000 0x610 0x800 3.67 52e3bb7b6093f2dd9ebab7821d967a95 .rsrc 0x7000 0xdbb0 0xdc00 6.13 32d131f2f17c5e95f1637dfb1475802b ( 5 imports ) > ADVAPI32.DLL: RegCloseKey, RegCreateKeyA, RegCreateKeyExA, RegOpenKeyExA, RegSetValueExA, SetNamedSecurityInfoA > KERNEL32.dll: CloseHandle, CreateFileA, CreateToolhelp32Snapshot, ExitProcess, FindResourceA, FreeResource, GetCommandLineA, GetModuleHandleA, GetStartupInfoA, GetSystemDirectoryA, GetSystemTime, LoadResource, LockResource, OpenProcess, Process32Next, SetFileTime, SetUnhandledExceptionFilter, SizeofResource, SystemTimeToFileTime, TerminateProcess, WinExec, WriteFile > msvcrt.dll: _stricmp > msvcrt.dll: __getmainargs, __p__environ, __p__fmode, __set_app_type, _cexit, _iob, _onexit, _setmode, atexit, memcpy, memset, signal, strcat, strlen > USER32.dll: MessageBoxA, wsprintfA ( 0 exports ) |
| Norman Sandbox: [ General information ] * **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**. * File length: 65024 bytes. [ Changes to registry ] * Creates key \"HKCR\CLSID\{BD942DA7-96C8-4342-84C6-E2BCFE69FE11}\". * Sets value \"default\"=\"Adobe Acrobat ActiveX Control\" in key \"HKCR\CLSID\{BD942DA7-96C8-4342-84C6-E2BCFE69FE11}\". * Creates key \"HKCR\CLSID\{BD942DA7-96C8-4342-84C6-E2BCFE69FE11}\InprocServer32\". * Sets value \"default\"=\"C:\WINDOWS\SYSTEM32\acrobat.dll\" in key \"HKCR\CLSID\{BD942DA7-96C8-4342-84C6-E2BCFE69FE11}\InprocServer32\". * Sets value \"ThreadingModel\"=\"Apartment\" in key \"HKCR\CLSID\{BD942DA7-96C8-4342-84C6-E2BCFE69FE11}\InprocServer32\". * Creates key \"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BD942DA7-96C8-4342-84C6-E2BCFE69FE11}\". * Sets value \"NoExplorer\"=\"\" in key \"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BD942DA7-96C8-4342-84C6-E2BCFE69FE11}\". * Accesses Registry key \"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\". [ Process/window information ] * Will automatically restart after boot (I'll be back...). |
| packers (F-Prot): embedded |
POZOR:
VirusTotal je brezplačen servis, ki ga ponuja Hispasec Sistemas. Ni nobenih zagotovil glede razpoložljivosti in stalnosti tega servisa. čeprav je stopnja prepoznavanja nevarnih datotek zaradi uporabe večjega števila antivirusnih programov veliko boljša, kot v primeru uporabe samo enega antivirusnega programa, ti rezultati vseeno NE zagotavljajo varnosti uporabe pregledanih datotek. Trenutno ne obstaja nobena taka rešitev, ki bi nudila 100% učinkovitost pri prepoznavanju virusov in ostalih zlonamernih programov.