× ¡Las cookies están desactivadas! Esta página requiere que las cookies estén activadas para funcionar correctamente
SHA256: 1f9f1d84bb82916bd7f7a77d7f3bda4aa71aa331fc058037fc1499c60330cc82
Nombre: DestroyWindowsSpying.exe
Detecciones: 1 / 55
Fecha de análisis: 2015-08-06 05:13:48 UTC ( hace 1 año, 7 meses ) Ver el más reciente
Probablemente inofensivo Todo indica que este archivo es seguro.
Antivirus Resultado Actualización
Qihoo-360 HEUR/QVM03.0.Malware.Gen 20150806
Ad-Aware 20150806
AegisLab 20150805
Yandex 20150805
AhnLab-V3 20150806
Alibaba 20150803
ALYac 20150806
Antiy-AVL 20150806
Arcabit 20150806
Avast 20150806
AVG 20150806
Avira (no cloud) 20150806
AVware 20150806
Baidu-International 20150805
BitDefender 20150806
Bkav 20150805
ByteHero 20150806
CAT-QuickHeal 20150806
ClamAV 20150805
Comodo 20150806
Cyren 20150806
DrWeb 20150806
Emsisoft 20150806
ESET-NOD32 20150806
F-Prot 20150806
F-Secure 20150806
Fortinet 20150804
GData 20150806
Ikarus 20150806
Jiangmin 20150804
K7AntiVirus 20150805
K7GW 20150806
Kaspersky 20150806
Kingsoft 20150806
Malwarebytes 20150805
McAfee 20150806
McAfee-GW-Edition 20150805
Microsoft 20150805
eScan 20150806
NANO-Antivirus 20150806
nProtect 20150805
Panda 20150805
Rising 20150731
Sophos 20150806
SUPERAntiSpyware 20150805
Symantec 20150806
Tencent 20150806
TheHacker 20150805
TrendMicro 20150806
TrendMicro-HouseCall 20150806
VBA32 20150805
VIPRE 20150806
ViRobot 20150806
Zillya 20150805
Zoner 20150806
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright © 2015

Product DestroyWindowsSpying
Original name DestroyWindowsSpying.exe
Internal name DestroyWindowsSpying.exe
File version 1.4.1.0
Description DestroyWindowsSpying
Comments Windows spy destroy
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2015-08-05 22:17:11
Entry Point 0x009C520E
Number of sections 4
.NET details
Module Version ID a28eb0a2-e250-4ad3-8298-9d010ca751f8
TypeLib ID 9006f149-aa49-4b8e-ba69-386d945fa738
PE sections
PE imports
_CorExeMain
Number of PE resources by type
RT_ICON 1
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 4
PE resources
Debug information
ExifTool file metadata
LegalTrademarks
Nummer

SubsystemVersion
4.0

Comments
Windows spy destroy

LinkerVersion
6.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.4.1.0

LanguageCode
Neutral

FileFlagsMask
0x003f

FileDescription
DestroyWindowsSpying

CharacterSet
Unicode

InitializedDataSize
73216

EntryPoint
0x9c520e

OriginalFileName
DestroyWindowsSpying.exe

MIMEType
application/octet-stream

LegalCopyright
Copyright 2015

FileVersion
1.4.1.0

TimeStamp
2015:08:05 23:17:11+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
DestroyWindowsSpying.exe

ProductVersion
1.4.1.0

UninitializedDataSize
0

OSVersion
4.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
Nummer

CodeSize
10236928

ProductName
DestroyWindowsSpying

ProductVersionNumber
1.4.1.0

FileTypeExtension
exe

ObjectFileType
Executable application

AssemblyVersion
1.4.1.0

Compressed bundles
File identification
MD5 651e5b844cf4a0d43e207ca90ca49ca5
SHA1 1bb1c02e0edeeee2269e424acf99fcba30fab4af
SHA256 1f9f1d84bb82916bd7f7a77d7f3bda4aa71aa331fc058037fc1499c60330cc82
ssdeep
196608:X2x2f7uZx7dxZ+aFXeaADfurvrf48YoCKg6zLL/tr/cnEz7BJ226geCDfpv:y2Wx7dxZLXeaADGrvL485CKgIL/taEvr

authentihash 68b0847b7a4f4ac6492aae74d8741113a79971f4f766db43ac5708c8494b1391
imphash f34d5f2d4577ed6d9ceec516c1f5a744
Tamaño del fichero 9.8 MB ( 10311168 bytes )
Tipo Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly

TrID Generic CIL Executable (.NET, Mono, etc.) (49.0%)
Win32 Executable MS Visual C++ (generic) (20.9%)
Win64 Executable (generic) (18.5%)
Win32 Dynamic Link Library (generic) (4.4%)
Win32 Executable (generic) (3.0%)
Tags
peexe assembly via-tor

VirusTotal metadata
First submission 2015-08-05 22:49:03 UTC ( hace 1 año, 7 meses )
Last submission 2016-11-13 16:36:14 UTC ( hace 4 meses, 1 semana )
Nombres DestroyWindowsSpying141.exe
Destroy Windows Spyingg.exe
DestroyWindowsSpying.exe
DestroyWindowsSpying.exe
DestroyWindowsSpying.exe
DestroyWindowsSpying.exe
Destroy_Windows_10_Spying_1.4.1.exe
DestroyWindowsSpying-1.4.1-Admin.exe
DestroyWindowsSpying.exe
Destroy Windows Spying v1.4.1.0.exe
filename
Destroy_Windows_10_Spying_1.4.1.exe
DestroyWindowsSpying.exe
Destroy Windows 10 Spying 1.4.1.exe
DestroyWindowsSpying.exe
Advanced heuristic and reputation engines
TrendMicro-HouseCall
TrendMicro's heuristic engine has flagged this file as: Suspicious_GEN.F47V0807.

Symantec reputation Suspicious.Insight
No hay comentarios. Ningún usuario ha comentado aún. ¡Sea el primero en hacerlo!

Deje su comentario...

?
Enviar comentario

No ha iniciado sesión. Solo los usuarios registrados pueden escribir comentarios.

No hay votos. Nadie ha votado aún. ¡Sea el primero!