i scan with virustotal.com:
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.9.5.1 2008.09.05 -
AntiVir 7.8.1.28 2008.09.05 -
Authentium 5.1.0.4 2008.09.05 W32/Heuristic-THX!********
Avast 4.8.1195.0 2008.09.05 -
AVG 8.0.0.161 2008.09.05 SHeur.CHFU
BitDefender 7.2 2008.09.05 -
CAT-QuickHeal 9.50 2008.09.02 -
ClamAV 0.93.1 2008.09.05 -
DrWeb 4.44.0.09170 2008.09.05 -
eSafe 7.0.17.0 2008.09.03 -
eTrust-Vet 31.6.6071 2008.09.05 -
Ewido 4.0 2008.09.05 -
F-Prot 4.4.4.56 2008.09.04 W32/Heuristic-THX!********
F-Secure 8.0.14332.0 2008.09.05 -
Fortinet 3.14.0.0 2008.09.03 -
GData 19 2008.09.05 -
Ikarus T3.1.1.34.0 2008.09.05 -
K7AntiVirus 7.10.443 2008.09.05 -
Kaspersky 7.0.0.125 2008.09.05 -
McAfee 5378 2008.09.05 -
Microsoft 1.3903 2008.09.05 -
NOD32v2 3419 2008.09.05 -
Norman 5.80.02 2008.09.05 -
Panda 9.0.0.4 2008.09.04 -
PCTools 4.4.2.0 2008.09.05 -
Prevx1 V2 2008.09.05 -
Rising 20.60.42.00 2008.09.05 -
Sophos 4.33.0 2008.09.05 Mal/Behav-285
Sunbelt 3.1.1610.1 2008.09.05 -
Symantec 10 2008.09.05 -
TheHacker 6.3.0.8.072 2008.09.04 -
TrendMicro 8.700.0.1004 2008.09.05 -
VBA32 3.12.8.5 2008.09.05 -
ViRobot 2008.9.5.1365 2008.09.05 -
VirusBuster 4.5.11.0 2008.09.05 -
Webwasher-Gateway 6.6.2 2008.09.05 Win32.EPO.gen (suspicious)
weitere Informationen
File size: 6874983 bytes
MD5...: 3e948a25f16bc4abe98f4fa50a503238
SHA1..: c8a716bd03d24c78f733912e882f48241abdef47
SHA256: c298efe92aa34a683bd9c83e0113287450de240001396f9322 3c3ee653185954
SHA512: ac085b41b1d5b83395e5d27df745353cd2e575909bbaf7bb65 4f998fa33b6e33
2fe1187630cb862202abf6be4e1b65edb1dd8af7a3665509d9 a6da4fdf76ff19
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (58.3%)
Win16/32 Executable Delphi generic (14.1%)
Generic Win/DOS Executable (13.7%)
DOS Executable Generic (13.6%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0xb92014
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
0x1000 0x12d000 0x83e00 7.98 2ffcc1acc6be4494f9e611596bd1bd2f
.rsrc 0x12e000 0x662200 0x55a800 7.81 4652c8396861d6a0aee7116255e9a6ac
.idata 0x791000 0x1000 0x200 1.43 76009eeba0252dc1798374219901cd7c
WinLicen 0x792000 0x142000 0x88a00 7.89 05ec6e40de7d27aee34d50798a140eb6
( 2 imports )
> KERNEL32.dll: CreateFileA, ExitProcess
> COMCTL32.dll: InitCommonControls
( 0 exports )
packers (Authentium): Themida
packers (F-Prot): Themida
[Only registered and activated users can see links. Click Here To Register...]