× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: dd3a3e494c0b81e289befb9aea3e0c80ee46dda3620dcca63617d15198678ff2
File name: vti-rescan
Detection ratio: 47 / 54
Analysis date: 2014-06-28 10:36:41 UTC ( 3 years, 2 months ago )
Antivirus Result Update
Ad-Aware Trojan.Generic.KD.13667 20140628
Yandex Trojan.VB!xaHZn6lofZY 20140627
AhnLab-V3 Trojan/Win32.VB 20140627
AntiVir TR/PSW.Dybalom.gap 20140628
Antiy-AVL Worm/Win32.VBNA 20140628
Avast Win32:VB-QSB [Drp] 20140628
AVG Cryptic.YG 20140628
Baidu-International Trojan.Win32.VB.Am 20140628
BitDefender Trojan.Generic.KD.13667 20140628
Bkav W32.SpoolsvHZ.Trojan 20140625
CAT-QuickHeal Trojan.VB.Gen 20140628
ClamAV Win.Trojan.Agent-32198 20140628
Commtouch W32/Risk.PLUN-0691 20140628
Comodo UnclassifiedMalware 20140628
DrWeb Trojan.PWS.Dybalom 20140628
Emsisoft Trojan.Generic.KD.13667 (B) 20140628
ESET-NOD32 Win32/AutoRun.VB.PK 20140628
F-Prot W32/MalwareF.CWUF 20140628
F-Secure Trojan.Generic.KD.13667 20140628
Fortinet W32/Refroso.BLC!tr 20140628
GData Trojan.Generic.KD.13667 20140628
Ikarus Worm.Win32.VBNA 20140628
Jiangmin Worm/VBNA.ftjs 20140628
K7AntiVirus Trojan ( 001718431 ) 20140627
K7GW Trojan ( 001718431 ) 20140627
Kaspersky Worm.Win32.VBNA.b 20140628
Kingsoft Win32.Troj.Generic.(kcloud) 20140628
McAfee Artemis!424AD30CC3E5 20140628
McAfee-GW-Edition Artemis!424AD30CC3E5 20140627
Microsoft VirTool:Win32/VBInject.HH 20140628
eScan Trojan.Generic.KD.13667 20140628
NANO-Antivirus Trojan.Win32.VB.bshot 20140628
Norman VBTroj.CXQM 20140628
nProtect Trojan.Generic.KD.13667 20140627
Panda W32/VB.ALH 20140627
Qihoo-360 HEUR/Malware.QVM03.Gen 20140628
Sophos AV Mal/VB-BL 20140628
Symantec Spyware.Keylogger 20140628
Tencent Win32.Worm.Vbna.Paby 20140628
TheHacker Trojan/AutoRun.VB.pk 20140624
TotalDefense Win32/Tnega.CZC 20140627
TrendMicro TROJ_VB.JMC 20140628
TrendMicro-HouseCall TROJ_VB.JMC 20140628
VBA32 SScope.Malware-Cryptor.VBCR.1841 20140627
VIPRE LooksLike.Win32.Malware!vb (v) 20140628
ViRobot Worm.Win32.A.VBNA.323584.S 20140628
Zillya Trojan.VB.Win32.38366 20140627
AegisLab 20140628
ByteHero 20140628
CMC 20140627
Malwarebytes 20140628
Rising 20140623
SUPERAntiSpyware 20140628
Zoner 20140626
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright © RealVNC Ltd. 2002-2008

Publisher RealVNC Ltd.
Product VNC Viewer Free Edition
Original name vncviewer.exe
Internal name free4/vncviewer/win
File version 4.1.3
Description VNC Viewer Free Edition for Win32
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2010-05-19 14:10:30
Entry Point 0x000010EC
Number of sections 4
PE sections
PE imports
EVENT_SINK_QueryInterface
Ord(537)
Ord(648)
Ord(570)
Ord(685)
EVENT_SINK_AddRef
Ord(712)
Ord(717)
__vbaExceptHandler
MethCallEngine
DllFunctionCall
Ord(100)
Ord(526)
Ord(573)
Ord(711)
EVENT_SINK_Release
Ord(529)
Ord(716)
Ord(644)
Ord(631)
Ord(579)
Ord(621)
Ord(619)
Number of PE resources by type
RT_ICON 3
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 4
ENGLISH UK 1
PE resources
ExifTool file metadata
LegalTrademarks
RealVNC

FileDescription
VNC Viewer Free Edition for Win32

InitializedDataSize
8192

ImageVersion
15.8

ProductName
VNC Viewer Free Edition

FileVersionNumber
4.1.3.0

LanguageCode
English (British)

FileFlagsMask
0x003f

CharacterSet
Unicode

LinkerVersion
6.0

OriginalFilename
vncviewer.exe

MIMEType
application/octet-stream

Subsystem
Windows GUI

FileVersion
4.1.3

TimeStamp
2010:05:19 15:10:30+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
free4/vncviewer/win

SubsystemVersion
4.0

FileAccessDate
2014:06:28 11:37:04+01:00

ProductVersion
4.1.3

UninitializedDataSize
0

OSVersion
4.0

FileCreateDate
2014:06:28 11:37:04+01:00

FileOS
Windows NT 32-bit

LegalCopyright
Copyright RealVNC Ltd. 2002-2008

MachineType
Intel 386 or later, and compatibles

CompanyName
RealVNC Ltd.

CodeSize
122880

FileSubtype
0

ProductVersionNumber
4.1.3.0

EntryPoint
0x10ec

ObjectFileType
Executable application

File identification
MD5 424ad30cc3e582eae47f61b67bb8da5c
SHA1 37d74c41f58032df93be62f46f8a18c3d5550f91
SHA256 dd3a3e494c0b81e289befb9aea3e0c80ee46dda3620dcca63617d15198678ff2
ssdeep
3072:2belqeD0PdS9346HxRCjuiRn6nQNKMczBP+lApUvTFWMoMGHjn:2bBWBEqiRnHK9BGlV7FWMoB

imphash 9d05b712abc2ba30177a6226cda01735
File size 200.0 KB ( 204800 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable Microsoft Visual Basic 6 (90.5%)
Win32 Executable (generic) (4.9%)
Generic Win/DOS Executable (2.2%)
DOS Executable Generic (2.2%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
Tags
peexe

VirusTotal metadata
First submission 2010-05-25 00:13:40 UTC ( 7 years, 4 months ago )
Last submission 2014-06-28 10:36:41 UTC ( 3 years, 2 months ago )
File names PCgH.html
vncviewer.exe
vti-rescan
BOT.exe-EumZmR
424AD30CC3E582EAE47F61B67BB8DA5C
win
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!