× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: affed4b34c63f8f65dfc532fb6337401389a109ce3dbeecdb499edd64dfe669b
File name: ea36b11d35fccd60defb5cc6c7e4bc495e18154d
Detection ratio: 27 / 54
Analysis date: 2014-09-04 08:32:55 UTC ( 4 years, 6 months ago )
Antivirus Result Update
Ad-Aware Trojan.GenericKD.1836653 20140904
AhnLab-V3 Trojan/Win32.Necurs 20140903
Avast Win32:Dropper-gen [Drp] 20140904
AVG Zbot.NKX 20140904
Avira (no cloud) TR/Crypt.Xpack.87552 20140904
Baidu-International Trojan.Win32.Zbot.BABX 20140904
BitDefender Trojan.GenericKD.1836653 20140904
Emsisoft Trojan.GenericKD.1836653 (B) 20140904
ESET-NOD32 Win32/Spy.Zbot.ABX 20140904
F-Secure Trojan.GenericKD.1836653 20140904
GData Trojan.GenericKD.1836653 20140904
Ikarus Trojan.SuspectCRC 20140904
Kaspersky Trojan-Spy.Win32.Zbot.tzei 20140904
Kingsoft Win32.Troj.Zbot.tz.(kcloud) 20140904
Malwarebytes Spyware.Pony 20140904
McAfee Artemis!7B6906EB625E 20140904
McAfee-GW-Edition BehavesLike.Win32.BadFile.gh 20140903
Microsoft Trojan:Win32/Malagent!gmb 20140904
eScan Trojan.GenericKD.1836653 20140904
Norman Troj_Generic.VPTME 20140904
nProtect Trojan.GenericKD.1836653 20140903
Panda Trj/CI.A 20140903
Qihoo-360 Win32/Trojan.Dropper.c9f 20140904
Sophos AV Mal/Yakes-F 20140904
Symantec WS.Reputation.1 20140904
Tencent Win32.Trojan.Bp-qqthief.Iqpl 20140904
TrendMicro-HouseCall TROJ_GEN.R011H09I214 20140904
AegisLab 20140904
Yandex 20140903
AVware 20140904
Bkav 20140903
ByteHero 20140904
CAT-QuickHeal 20140904
ClamAV 20140903
CMC 20140904
Comodo 20140904
Cyren 20140904
DrWeb 20140904
F-Prot 20140904
Fortinet 20140904
Jiangmin 20140903
K7AntiVirus 20140903
K7GW 20140903
NANO-Antivirus 20140904
Rising 20140903
SUPERAntiSpyware 20140904
TheHacker 20140904
TotalDefense 20140903
TrendMicro 20140904
VBA32 20140903
VIPRE 20140904
ViRobot 20140903
Zillya 20140903
Zoner 20140901
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file.
FileVersionInfo properties
LG Electronics (c) All rights reserved.

Publisher LG Electronics
Product Dual Smart Solution
Original name Dual Smart Solution.exe
Internal name Dual Smart Solution.exe
File version
Description Dual Smart Solution
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2014-09-02 08:18:20
Entry Point 0x00008000
Number of sections 5
PE sections
Number of PE resources by type
Number of PE resources by language
PE resources
File identification
MD5 7b6906eb625e1d819811e1b9a1fc8bd4
SHA1 98dfcb0860c7d77b5d4c20b4284485bc0f0145b8
SHA256 affed4b34c63f8f65dfc532fb6337401389a109ce3dbeecdb499edd64dfe669b

imphash 15a813c790cda6c7100a28e73f36a9b4
File size 408.5 KB ( 418304 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable MS Visual C++ (generic) (42.1%)
Win64 Executable (generic) (37.3%)
Win32 Dynamic Link Library (generic) (8.8%)
Win32 Executable (generic) (6.0%)
Generic Win/DOS Executable (2.7%)

VirusTotal metadata
First submission 2014-09-03 19:01:31 UTC ( 4 years, 6 months ago )
Last submission 2014-09-03 19:01:31 UTC ( 4 years, 6 months ago )
File names ea36b11d35fccd60defb5cc6c7e4bc495e18154d
Dual Smart Solution.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Written files
Copied files
Deleted files
Created processes
Code injections in the following processes
Created mutexes
Opened mutexes
Searched windows
Opened service managers
Opened services
Runtime DLLs
Additional details
The file sends control codes directly to certain device drivers making use of the DeviceIoControl Windows API function.
UDP communications