File
Qupell_DC_Bot_v1.3__x86_.exe ricevuto il 2010.04.26 19:52:10 (UTC)
Stato corrente: finito
Risultato: 9/40 (22.50%)
Formattato Formattato
Stampa risultati Stampa risultati
Antivirus Versione Ultimo aggiornamento Risultato
a-squared 4.5.0.50 2010.04.26 -
AhnLab-V3 5.0.0.2 2010.04.26 -
AntiVir 8.2.1.224 2010.04.26 -
Antiy-AVL 2.0.3.7 2010.04.26
Trojan/Win32.Midgare.gen
Authentium 5.2.0.5 2010.04.26 -
Avast 4.8.1351.0 2010.04.26 -
Avast5 5.0.332.0 2010.04.26 -
AVG 9.0.0.787 2010.04.26
Packed.AutoIt
BitDefender 7.2 2010.04.26 -
CAT-QuickHeal 10.00 2010.04.26 -
ClamAV 0.96.0.3-git 2010.04.26
PUA.Script.Packed-3
Comodo 4684 2010.04.26 -
DrWeb 5.0.2.03300 2010.04.26 -
eSafe 7.0.17.0 2010.04.26 -
eTrust-Vet 35.2.7452 2010.04.26 -
F-Prot 4.5.1.85 2010.04.26 -
F-Secure 9.0.15370.0 2010.04.26 -
Fortinet 4.0.14.0 2010.04.26 -
GData 21 2010.04.26 -
Ikarus T3.1.1.80.0 2010.04.26 -
Jiangmin 13.0.900 2010.04.26
Trojan/Midgare.dtp
Kaspersky 7.0.0.125 2010.04.26 -
McAfee 5.400.0.1158 2010.04.26
W32/Autorun.worm.zf.gen
McAfee-GW-Edition 6.8.5 2010.04.26 -
Microsoft 1.5703 2010.04.26 -
NOD32 5063 2010.04.26
Win32/Packed.Autoit.Gen
Norman 6.04.11 2010.04.26 -
nProtect 2010-04-26.01 2010.04.26 -
Panda 10.0.2.7 2010.04.26
Suspicious file
PCTools 7.0.3.5 2010.04.26 -
Prevx 3.0 2010.04.26 -
Rising 22.45.00.04 2010.04.26 -
Sophos 4.53.0 2010.04.26 -
Sunbelt 6224 2010.04.26 -
Symantec 20091.2.0.41 2010.04.26 -
TheHacker 6.5.2.0.269 2010.04.26
Trojan/Midgare.akhk
TrendMicro 9.120.0.1004 2010.04.26 -
VBA32 3.12.12.4 2010.04.26
Trojan.Win32.Midgare.akvf
ViRobot 2010.4.26.2294 2010.04.26 -
VirusBuster 5.0.27.0 2010.04.26 -
Informazioni addizionali
File size: 471994 bytes
MD5 : 6a2cc0c145a3bfdfe9ff46985e76417a
SHA1 : e3cb215f573f97a7caadb8ef842949c7a41b5735
SHA256: eacb9ca1ffff54796fce7a662fa3c7f0c592254ec1ed791388 760b946bc42339
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0xB5ED0
timedatestamp.....: 0x4B509352 (Fri Jan 15 17:09:54 2010)
machinetype.......: 0x14C (Intel I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x73000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x74000 0x43000 0x42200 7.93 2e4f93db385f525592d4d4ec00ddab6b
.rsrc 0xB7000 0x8000 0x7400 5.91 e903a5a4d9817078387ff29e5abf575b
( 16 imports )
> advapi32.dll: GetAce
> comctl32.dll: ImageList_Remove
> comdlg32.dll: GetSaveFileNameW
> gdi32.dll: LineTo
> kernel32.dll: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> mpr.dll: WNetGetConnectionW
> ole32.dll: CoInitialize
> oleaut32.dll: -
> psapi.dll: EnumProcesses
> shell32.dll: DragFinish
> user32.dll: GetDC
> userenv.dll: LoadUserProfileW
> version.dll: VerQueryValueW
> wininet.dll: FtpOpenFileW
> winmm.dll: timeGetTime
> wsock32.dll: -
( 0 exports )
TrID : File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
Symantec reputation: Suspicious.Insight

ssdeep: 12288:UzYwKuEYUhoMO+xxmYrkwDDV69XeU7P5Ja7lTz/ar7:csZYUhoM/LmKokumlTzC3
sigcheck: publisher....: n/a
copyright....: n/a
product......: n/a
description..:
original name: n/a
internal name: n/a
file version.: 3, 3, 4, 0
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned