Code:
Antivirus Version Last Update Result
AhnLab-V3 2011.08.17.01 2011.08.17 -
AntiVir 7.11.13.117 2011.08.17 -
Antiy-AVL 2.0.3.7 2011.08.18 -
Avast 4.8.1351.0 2011.08.17 -
Avast5 5.0.677.0 2011.08.17 -
AVG 10.0.0.1190 2011.08.17 -
BitDefender 7.2 2011.08.18 -
ByteHero 1.0.0.1 2011.08.18 -
CAT-QuickHeal 11.00 2011.08.17 -
ClamAV 0.97.0.0 2011.08.18 -
Commtouch 5.3.2.6 2011.08.18 -
Comodo 9786 2011.08.18 -
DrWeb 5.0.2.03300 2011.08.18 -
Emsisoft 5.1.0.10 2011.08.18 -
eSafe 7.0.17.0 2011.08.17 -
eTrust-Vet 36.1.8507 2011.08.17 -
F-Prot 4.6.2.117 2011.08.18 -
F-Secure 9.0.16440.0 2011.08.18 -
Fortinet 4.2.257.0 2011.08.18 -
GData 22 2011.08.18 -
Ikarus T3.1.1.107.0 2011.08.18 -
Jiangmin 13.0.900 2011.08.17 -
K7AntiVirus 9.109.5026 2011.08.17 -
Kaspersky 9.0.0.837 2011.08.18 -
McAfee 5.400.0.1158 2011.08.18 -
McAfee-GW-Edition 2010.1D 2011.08.18 -
Microsoft 1.7604 2011.08.18 -
NOD32 6387 2011.08.18 -
Norman 6.07.10 2011.08.17 -
nProtect 2011-08-18.01 2011.08.18 -
Panda 10.0.3.5 2011.08.17 -
PCTools 8.0.0.5 2011.08.18 -
Prevx 3.0 2011.08.18 -
Rising 23.71.02.03 2011.08.17 -
Sophos 4.68.0 2011.08.18 -
SUPERAntiSpyware 4.40.0.1006 2011.08.17 -
Symantec 20111.2.0.82 2011.08.18 -
TheHacker 6.7.0.1.279 2011.08.18 -
TrendMicro 9.500.0.1008 2011.08.17 -
TrendMicro-HouseCall 9.500.0.1008 2011.08.18 -
VBA32 3.12.16.4 2011.08.17 Exploit.IMGWMF.cuw
VIPRE 10197 2011.08.18 -
ViRobot 2011.8.18.4626 2011.08.18 -
VirusBuster 14.0.174.0 2011.08.17 -
Additional information
MD5 : e043495e5c20b379a081cb735dc58405
SHA1 : 95dd7fe2ee8c1b6bbc7c9696db41f56fd6a950f3
SHA256: 620d2d06d248850da8e9852119d4f1d55cb7c949e8f3fcfa0ca1a25635ac6332
ssdeep: 192:NzH6edhu3yqn0BMr3FuWF4QkjyFNrncCDq:vaCqnr3F14hebrnrG
File size : 16654 bytes
First seen: 2011-08-18 09:04:29
Last seen : 2011-08-18 09:04:29
TrID:
Win32 Executable Generic (38.3%)
Win32 Dynamic Link Library (generic) (34.1%)
Win16/32 Executable Delphi generic (9.3%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
PEiD: Dev-C++ 4.9.9.2 -> Bloodshed Software
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x1220
timedatestamp....: 0x4D9A0193 (Mon Apr 04 17:36:19 2011)
machinetype......: 0x14c (I386)
[[ 5 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x924, 0xA00, 5.26, 35afadfe0397092a3d9ef89e3465000b
.data, 0x2000, 0x40, 0x200, 0.24, f081acecff69010ebd0759e60ea6e953
.rdata, 0x3000, 0xF0, 0x200, 3.11, 015e41636d10bc3cd8d2a258f0b865cf
.bss, 0x4000, 0xB0, 0x0, 0.00, d41d8cd98f00b204e9800998ecf8427e
.idata, 0x5000, 0x2F8, 0x400, 3.24, 20b13bb68c0ba834f25e87a0b6352706
[[ 3 import(s) ]]
KERNEL32.dll: AddAtomA, ExitProcess, FindAtomA, GetAtomNameA, SetUnhandledExceptionFilter
msvcrt.dll: __getmainargs, __p__environ, __p__fmode, __set_app_type, _cexit, _iob, _onexit, _setmode, abort, atexit, fflush, fprintf, free, malloc, printf, signal, system
USER32.dll: GetCursorPos
ExifTool:
file metadata
CodeSize: 2560
EntryPoint: 0x1220
FileSize: 16 kB
FileType: Win32 EXE
ImageVersion: 1.0
InitializedDataSize: 4608
LinkerVersion: 2.56
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
PEType: PE32
Subsystem: Windows command line
SubsystemVersion: 4.0
TimeStamp: 2011:04:04 19:36:19+02:00
UninitializedDataSize: 512
Symantec reputation:Suspicious.Insight