× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 6e4b0a685ef7ab03295f5c55a5825ace98889858bca0364441d1ae5878717aeb
File name: Antivirus Remover.exe
Detection ratio: 0 / 46
Analysis date: 2013-09-12 16:13:02 UTC ( 7 months, 1 week ago ) View latest
Antivirus Result Update
AVG 20130912
Agnitum 20130912
AhnLab-V3 20130912
AntiVir 20130912
Antiy-AVL 20130912
Avast 20130912
Baidu-International 20130912
BitDefender 20130912
ByteHero 20130903
CAT-QuickHeal 20130912
ClamAV 20130912
Commtouch 20130912
Comodo 20130912
DrWeb 20130912
ESET-NOD32 20130912
Emsisoft 20130912
F-Prot 20130912
Fortinet 20130912
GData 20130912
Ikarus 20130912
Jiangmin 20130903
K7AntiVirus 20130911
K7GW 20130911
Kaspersky 20130912
Kingsoft 20130829
Malwarebytes 20130912
McAfee 20130912
McAfee-GW-Edition 20130912
MicroWorld-eScan 20130912
Microsoft 20130912
NANO-Antivirus 20130911
Norman 20130912
PCTools 20130912
Panda 20130912
Rising 20130912
SUPERAntiSpyware 20130912
Sophos 20130912
Symantec 20130912
TheHacker 20130912
TotalDefense 20130911
TrendMicro 20130912
TrendMicro-HouseCall 20130912
VBA32 20130912
VIPRE 20130912
ViRobot 20130912
nProtect 20130912
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file.
Authenticode signature block
Copyright
Copyright © 2013

Product Antivirus Remover
Version 1.17
Original name Antivirus Remover.exe
Internal name Antivirus Remover.exe
File version 1.17
Description Antivirus Remover
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2013-09-11 17:13:40
Entry Point 0x0005473E
Number of sections 4
PE sections
PE imports
_CorExeMain
Number of PE resources by type
RT_ICON 1
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 4
File identification
MD5 bdc9fa44326de46504d4fc67078a1df6
SHA1 6a8ca04aacb340b319051f40857b2b9e15c14bdd
SHA256 6e4b0a685ef7ab03295f5c55a5825ace98889858bca0364441d1ae5878717aeb
ssdeep
3072:Zt7Hg9mpTw2pt7MUcvSpfFyb39l8jKE7Vat7/A:Zt0Eq2ptQULLj54t7A

File size 401.5 KB ( 411136 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly

TrID Generic CIL Executable (.NET, Mono, etc.) (55.8%)
Win64 Executable (generic) (21.0%)
Windows Screen Saver (9.9%)
Win32 Dynamic Link Library (generic) (5.0%)
Win32 Executable (generic) (3.4%)
Tags
peexe assembly

VirusTotal metadata
First submission 2013-09-12 16:13:02 UTC ( 7 months, 1 week ago )
Last submission 2013-09-12 16:13:02 UTC ( 7 months, 1 week ago )
File names Antivirus Remover.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!