× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 0df0d26cbb793ba612236b9750309b3e545fa5339e4da159062abfe6f326b2b7
File name: rncsys32.exe
Detection ratio: 1 / 41
Analysis date: 2009-06-30 23:46:47 UTC ( 5 years ago ) View latest
Antivirus Result Update
eSafe Suspicious File 20090629
AVG 20090630
AhnLab-V3 20090630
AntiVir 20090630
Antiy-AVL 20090630
Authentium 20090630
Avast 20090630
BitDefender 20090630
CAT-QuickHeal 20090629
ClamAV 20090630
Comodo 20090630
DrWeb 20090630
F-Prot 20090630
F-Secure 20090630
Fortinet 20090630
GData 20090630
Ikarus 20090630
Jiangmin 20090630
K7AntiVirus 20090619
Kaspersky 20090630
McAfee 20090630
McAfee+Artemis 20090630
McAfee-GW-Edition 20090630
Microsoft 20090630
NOD32 20090630
Norman 20090630
PCTools 20090630
Panda 20090630
Prevx 20090630
Rising 20090630
Sophos 20090630
Sunbelt 20090630
Symantec 20090630
TheHacker 20090630
TrendMicro 20090630
VBA32 20090630
ViRobot 20090630
VirusBuster 20090630
a-squared 20090630
eTrust-Vet 20090630
nProtect 20090630
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file.
Authenticode signature block
Copyright
Copyright (C) Microsoft Corp. 1981-1999

Publisher Microsoft Corporation
Product Microsoft(R) Windows (R) 2000 Operating System
Original name FIND.EXE
Internal name find
File version 5.00.2195.6605
Description Find String (grep) Utility
Packers identified
PEiD Armadillo v1.71
PE header basic information
Number of sections 5
PE sections
PE imports
ExitProcess
GetLastError
GetModuleFileNameA
GetCurrentThreadId
GetTickCount
LoadLibraryA
GetSystemTimeAsFileTime
GetVersion
GetCommandLineA
GetModuleHandleA
GetCurrentDirectoryA
File identification
MD5 24bd24f8673e3985fc82edb00b24ba73
SHA1 d0c5265de5259a51a44120d095e93ea2046441a9
SHA256 0df0d26cbb793ba612236b9750309b3e545fa5339e4da159062abfe6f326b2b7
ssdeep
384:hAcbU7EaQWK7t91Nt/wVp+323kbVrxdjdNKB29BC1+FMtsvHJS7nV2I/MhX7WXPz:hJU7EaQ5t3NdwVA2srLjSBh1+FX/47np

File size 22.0 KB ( 22528 bytes )
File type Win32 EXE
Magic literal

TrID Win32 Executable MS Visual C++ 4.x (55.5%)
Win64 Executable Generic (35.3%)
Win32 Executable Generic (3.5%)
Win32 Dynamic Link Library (generic) (3.1%)
Win16/32 Executable Delphi generic (0.8%)
VirusTotal metadata
First submission 2009-06-30 19:58:59 UTC ( 5 years ago )
Last submission 2011-08-14 09:27:20 UTC ( 2 years, 11 months ago )
File names 24BD24F8673E3985FC82EDB00B24BA73
rncsys32.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!