× Cookies sind ausgeschaltet! Diese Seite erfordert aktivierte Cookies, um vollständig zu funktionieren.
SHA256: 4ecc602d636c2037a2ad63f7515ed430f3d4ababe49e95e47986a19487b22f14
Dateiname: DestroyWindowsSpying.exe
Erkennungsrate: 0 / 55
Analyse-Datum: 2015-08-05 12:49:30 UTC ( vor 1 Jahr, 7 Monate ) Zeige Neueste
Probably harmless! There are strong indicators suggesting that this file is safe to use.
Antivirus Ergebnis Aktualisierung
Ad-Aware 20150805
AegisLab 20150805
Yandex 20150804
AhnLab-V3 20150805
Alibaba 20150803
ALYac 20150805
Antiy-AVL 20150805
Arcabit 20150805
Avast 20150805
AVG 20150805
Avira (no cloud) 20150805
AVware 20150805
Baidu-International 20150805
BitDefender 20150805
Bkav 20150805
ByteHero 20150805
CAT-QuickHeal 20150805
ClamAV 20150805
Comodo 20150805
Cyren 20150805
DrWeb 20150805
Emsisoft 20150805
ESET-NOD32 20150805
F-Prot 20150805
F-Secure 20150805
Fortinet 20150804
GData 20150805
Ikarus 20150805
Jiangmin 20150804
K7AntiVirus 20150805
K7GW 20150805
Kaspersky 20150805
Kingsoft 20150805
Malwarebytes 20150805
McAfee 20150805
McAfee-GW-Edition 20150805
Microsoft 20150805
eScan 20150805
NANO-Antivirus 20150805
nProtect 20150805
Panda 20150805
Qihoo-360 20150805
Rising 20150731
Sophos 20150805
SUPERAntiSpyware 20150805
Symantec 20150805
Tencent 20150805
TheHacker 20150805
TrendMicro 20150805
TrendMicro-HouseCall 20150805
VBA32 20150805
VIPRE 20150805
ViRobot 20150805
Zillya 20150805
Zoner 20150805
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright © 2013

Product DestroyWindowsSpying
Original name DestroyWindowsSpying.exe
Internal name DestroyWindowsSpying.exe
File version 1.0.0.0
Description DestroyWindowsSpying
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2015-08-04 20:45:21
Entry Point 0x007E308E
Number of sections 4
.NET details
Module Version ID aba24480-9bee-40fc-b860-429540fd88e1
TypeLib ID 9006f149-aa49-4b8e-ba69-386d945fa738
PE sections
PE imports
_CorExeMain
Number of PE resources by type
RT_ICON 1
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 4
PE resources
Debug information
ExifTool file metadata
SubsystemVersion
4.0

LinkerVersion
6.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.0.0.0

UninitializedDataSize
0

LanguageCode
Neutral

FileFlagsMask
0x003f

CharacterSet
Unicode

InitializedDataSize
72704

EntryPoint
0x7e308e

OriginalFileName
DestroyWindowsSpying.exe

MIMEType
application/octet-stream

LegalCopyright
Copyright 2013

FileVersion
1.0.0.0

TimeStamp
2015:08:04 21:45:21+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
DestroyWindowsSpying.exe

ProductVersion
1.0.0.0

FileDescription
DestroyWindowsSpying

OSVersion
4.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CodeSize
8262144

ProductName
DestroyWindowsSpying

ProductVersionNumber
1.0.0.0

FileTypeExtension
exe

ObjectFileType
Executable application

AssemblyVersion
1.0.0.0

File identification
MD5 16ee1ef0af4ae7f14e7f986d7e3bbfc5
SHA1 17b61389b0a97fba88f4e1f64b030837b918b15f
SHA256 4ecc602d636c2037a2ad63f7515ed430f3d4ababe49e95e47986a19487b22f14
ssdeep
98304:iSnlJ+s2rwXUrXdsBMnh8Sl+l35NmyV/1r+rbqoWv0fzRpRjdRYInvqkpOTh3/OX:1lJqUySS0Bm6/1CPu4zRfJ5qkEx/Mwg

authentihash 7327066dff5bb633004c52fb1c755434e5f0a129fc0451a8fcdf9c6ca3831505
imphash f34d5f2d4577ed6d9ceec516c1f5a744
File size 7.9 MB ( 8335872 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly

TrID Generic CIL Executable (.NET, Mono, etc.) (49.0%)
Win32 Executable MS Visual C++ (generic) (20.9%)
Win64 Executable (generic) (18.5%)
Win32 Dynamic Link Library (generic) (4.4%)
Win32 Executable (generic) (3.0%)
Tags
peexe assembly

VirusTotal metadata
First submission 2015-08-04 21:07:27 UTC ( vor 1 Jahr, 7 Monate )
Last submission 2015-12-23 00:38:34 UTC ( vor 1 Jahr, 3 Monate )
Dateinamen fce048ce8c41e487eb895ce049a8062ceecbdbef
DestroyWindowsSpying.v1.3.exe
DestroyWindowsSpying.exe
DestroyWindowsSpying.exe
DestroyWindowsSpying.exe
rsload.net.DestroyWindowsSpying 1.3.exe
DestroyWindowsSpying.exe
DestroyWindowsSpying_0.exe
rsload.net.DestroyWindowsSpying.exe
filename
DestroyWindowsSpying 1.4.3.exe
arkslid.exe
DestroyWindowsSpying.exe
DestroyWindowsSpying.exe
DestroyWindowsSpying13.exe
DestroyWindowsSpying.exe
DestroyWindowsSpying.exe
destroywindowsspying.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
Keine Kommentare. Bisher hat kein Mitglied der VirusTotal-Community einen Kommentar zu diesem Punkt verfasst, seien Sie der Erste!

Hinterlassen Sie Ihren Kommentar...

?
Kommentar abschicken

Sie sind nicht angemeldet. Nur registrierte Nutzer können Kommentare hinterlassen, melden Sie sich an und sagen Sie etwas dazu!

Keine Bewertungen. Niemand hat diesen Punkt bisher bewertet, seien Sie der Erste!