× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: ffb0cdb9c7fa8f9700a18be4f2633eb3f76f70355d7a06898fb62544ce624840
File name: Apps.exe
Detection ratio: 0 / 42
Analysis date: 2010-12-18 13:48:24 UTC ( 3 years, 4 months ago ) View latest
Probably harmless! There are strong indicators suggesting that this file is safe to use.
Antivirus Result Update
AVG 20101218
AhnLab-V3 20101217
AntiVir 20101217
Antiy-AVL 20101218
Avast 20101217
Avast5 20101217
BitDefender 20101218
CAT-QuickHeal 20101218
ClamAV 20101217
Command 20101218
Comodo 20101218
DrWeb 20101218
F-Prot 20101217
F-Secure 20101218
Fortinet 20101218
GData 20101218
Ikarus 20101218
Jiangmin 20101218
K7AntiVirus 20101218
Kaspersky 20101218
McAfee 20101218
McAfee-GW-Edition 20101217
Microsoft 20101218
NOD32 20101218
Norman 20101218
PCTools 20101218
Panda 20101218
Prevx 20101218
Rising 20101218
SUPERAntiSpyware 20101218
Sophos 20101218
Symantec 20101218
TheHacker 20101215
TrendMicro 20101218
TrendMicro-HouseCall 20101218
VBA32 20101217
VIPRE 20101218
ViRobot 20101218
VirusBuster 20101217
eSafe 20101216
eTrust-Vet 20101217
nProtect 20101218
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2006-03-03 19:53:50
Link date 8:53 PM 3/3/2006
Entry Point 0x00001366
Number of sections 4
PE sections
PE imports
GetCurrentProcess
TerminateProcess
QueryPerformanceCounter
GetCurrentProcessId
InterlockedExchange
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
GetTickCount
GetStartupInfoW
GetSystemTimeAsFileTime
Sleep
GetCurrentThreadId
InterlockedCompareExchange
__p__fmode
__wgetmainargs
__dllonexit
_controlfp_s
_invoke_watson
_cexit
_lock
_onexit
exit
_XcptFilter
_encode_pointer
__setusermatherr
_initterm_e
__p__commode
_wcmdln
_adjust_fdiv
_amsg_exit
_unlock
_crt_debugger_hook
_except_handler4_common
_initterm
_decode_pointer
_configthreadlocale
_exit
__set_app_type
FindWindowA
ShowWindow
IsWindowVisible
GetWindow
Number of PE resources by type
RT_ICON 8
RT_DIALOG 1
RT_MANIFEST 1
RT_STRING 1
RT_MENU 1
RT_ACCELERATOR 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH UK 13
ENGLISH US 1
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

TimeStamp
2006:03:03 20:53:50+01:00

FileType
Win32 EXE

PEType
PE32

CodeSize
4096

LinkerVersion
8.0

FileAccessDate
2014:02:27 03:06:30+01:00

EntryPoint
0x1366

InitializedDataSize
172032

SubsystemVersion
4.0

ImageVersion
0.0

OSVersion
4.0

FileCreateDate
2014:02:27 03:06:30+01:00

UninitializedDataSize
0

File identification
MD5 123a46742d83b82080d096040598fd27
SHA1 041d2a609ba672438318855955c36b8d03f174ce
SHA256 ffb0cdb9c7fa8f9700a18be4f2633eb3f76f70355d7a06898fb62544ce624840
ssdeep
1536:+jCZCp7psYC4qA7jiZBsb4/SJi2+5AOL37nFx3LN6aiPGivnvJDLENtyHogba:ksa7itjAv4sUAi2POrFFtsbviyHogba

imphash c14e34be85945f5efacc6a3cff82871f
File size 176.0 KB ( 180224 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Dynamic Link Library (generic) (43.5%)
Win32 Executable (generic) (29.8%)
Generic Win/DOS Executable (13.2%)
DOS Executable Generic (13.2%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
Tags
peexe mz

VirusTotal metadata
First submission 2009-06-17 01:55:50 UTC ( 4 years, 10 months ago )
Last submission 2013-12-29 23:55:52 UTC ( 3 months, 3 weeks ago )
File names smona131554951957925708055
HideDesktopIcons.exe
smona131991699773386369236
Apps.exe
smona131052870738019828189
"Apps.exe"
smona131488298543493466848
smona131233119543837235498
file-3199857_exe
smona131828414613948052012
file-539833_exe
smona_ffb0cdb9c7fa8f9700a18be4f2633eb3f76f70355d7a06898fb62544ce624840.bin
smona132752006002744431928
smona132476281683958306252
smona131483363023183553054
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!