Antivirus Version Last Update Result AhnLab-V3 2008.9.4.2 2008.09.04 - AntiVir 7.8.1.28 2008.09.04 - Authentium 5.1.0.4 2008.09.03 - Avast 4.8.1195.0 2008.09.04 - AVG 8.0.0.161 2008.09.04 - BitDefender 7.2 2008.09.04 - CAT-QuickHeal 9.50 2008.09.02 - ClamAV 0.93.1 2008.09.04 - DrWeb 4.44.0.09170 2008.09.04 - eSafe 7.0.17.0 2008.09.03 Suspicious File eTrust-Vet 31.6.6069 2008.09.04 - Ewido 4.0 2008.09.03 - F-Prot 4.4.4.56 2008.09.03 - F-Secure 8.0.14332.0 2008.09.04 - Fortinet 3.14.0.0 2008.09.03 - GData 19 2008.09.04 - Ikarus T3.1.1.34.0 2008.09.04 - K7AntiVirus 7.10.441 2008.09.04 - Kaspersky 7.0.0.125 2008.09.04 - McAfee 5376 2008.09.03 - Microsoft 1.3903 2008.09.04 - NOD32v2 3415 2008.09.04 - Norman 5.80.02 2008.09.04 - Panda 9.0.0.4 2008.09.03 - PCTools 4.4.2.0 2008.09.04 - Prevx1 V2 2008.09.04 - Rising 20.60.31.00 2008.09.04 - Sophos 4.33.0 2008.09.04 - Sunbelt 3.1.1582.1 2008.09.02 - Symantec 10 2008.09.04 - TheHacker 6.3.0.8.072 2008.09.04 - TrendMicro 8.700.0.1004 2008.09.04 - VBA32 3.12.8.5 2008.09.04 - ViRobot 2008.9.4.1363 2008.09.04 - VirusBuster 4.5.11.0 2008.09.04 - Webwasher-Gateway 6.6.2 2008.09.04 - Additional information File size: 1288188 bytes MD5...: c2dbaccd1c21c00273820d0ffabe23e8 SHA1..: 3ad052244c5c1dbf350334f7be2bc926f89fa5f9 SHA256: 63d7b28386c77c55cc312ec6876472f9e209fc57341a8352a36f9e43d4169af8 SHA512: 9a07b64ad99694ea78e17f22efdcd32b876edbbc045e63e6f244e5c079ed15b8
29e14329fe795d9d5629e7ba58aa2acd44a1b6a7d4ab773ea7310f0dc2a15879 PEiD..: - TrID..: File type identification
UPX compressed Win32 Executable (38.5%)
Win32 EXE Yoda's Crypter (33.4%)
Win32 Executable Generic (10.7%)
Win32 Dynamic Link Library (generic) (9.5%)
Win16/32 Executable Delphi generic (2.6%) PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x7df0f0
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x2b3000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x2b4000 0x12c000 0x12b400 7.91 413731c157e07b76a8b8f3c0aab109c4
.rsrc 0x3e0000 0x8000 0x7c00 3.86 f058e6c0458ca444d22898dab2092395
( 16 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> advapi32.dll: FreeSid
> comctl32.dll: ImageList_Add
> comdlg32.dll: PrintDlgA
> gdi32.dll: SaveDC
> icmp.dll: IcmpSendEcho
> ole32.dll: OleRun
> oleaut32.dll: VarNot
> shell32.dll: DragFinish
> URLMON.DLL: HlinkNavigateString
> user32.dll: GetDC
> version.dll: VerQueryValueA
> wininet.dll: InternetOpenA
> winmm.dll: mmioSeek
> winspool.drv: OpenPrinterA
> wsock32.dll: send
( 0 exports )
packers (Kaspersky): UPX packers (F-Prot): UPX