It is now well detected by Antivirus softwares.
File FlashPlayer10.0.45.2b.exe received on 2010.05.06 07:37:16 (UTC)
Current status: finished
Result: 22/41 (53.66%)
Compact Print results Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.06 P2P-Worm.Win32.Palevo!IK
AhnLab-V3 2010.05.05.00 2010.05.05 Worm/Win32.Palevo
AntiVir 8.2.1.236 2010.05.05 DR/Palevo.aefb
Antiy-AVL 2.0.3.7 2010.05.06 -
Authentium 5.2.0.5 2010.05.06 -
Avast 4.8.1351.0 2010.05.05 -
Avast5 5.0.332.0 2010.05.05 -
AVG 9.0.0.787 2010.05.05 -
BitDefender 7.2 2010.05.06 -
CAT-QuickHeal 10.00 2010.05.04 -
ClamAV 0.96.0.3-git 2010.05.06 Worm.Palevo-7555
Comodo 4777 2010.05.06 Heur.Suspicious
DrWeb 5.0.2.03300 2010.05.06 Win32.HLLW.Lime.307
eSafe 7.0.17.0 2010.05.05 -
eTrust-Vet 35.2.7470 2010.05.05 -
F-Prot 4.5.1.85 2010.05.06 -
F-Secure 9.0.15370.0 2010.05.06 -
Fortinet 4.0.14.0 2010.05.05 W32/Palevo.ACF6!worm
GData 21 2010.05.06 -
Ikarus T3.1.1.84.0 2010.05.06 P2P-Worm.Win32.Palevo
Jiangmin 13.0.900 2010.05.06 Trojan/StartPage.bim
Kaspersky 7.0.0.125 2010.05.06 P2P-Worm.Win32.Palevo.aefb
McAfee 5.400.0.1158 2010.05.06 Generic.dx!spp
McAfee-GW-Edition 2010.1 2010.05.06 Heuristic.BehavesLike.Win32.Trojan.A
Microsoft 1.5703 2010.05.05 Worm:Win32/Rimecud.B
NOD32 5089 2010.05.05 Win32/Peerfrag.GI
Norman 6.04.12 2010.05.06 -
nProtect 2010-05-06.01 2010.05.06 -
Panda 10.0.2.7 2010.05.05 Trj/CI.A
PCTools 7.0.3.5 2010.05.06 -
Prevx 3.0 2010.05.06 Medium Risk Malware
Rising 22.46.03.04 2010.05.06 -
Sophos 4.53.0 2010.05.06 W32/Palevo-O
Sunbelt 6265 2010.05.06 Trojan.Win32.Generic!BT
Symantec 20091.2.0.41 2010.05.06 Trojan.Mdropper
TheHacker 6.5.2.0.276 2010.05.06 -
TrendMicro 9.120.0.1004 2010.05.06 WORM_PEERBOT.B
TrendMicro-HouseCall 9.120.0.1004 2010.05.06 WORM_PEERBOT.SM
VBA32 3.12.12.4 2010.05.05 Trojan.Tasman
ViRobot 2010.5.4.2303 2010.05.06 -
VirusBuster 5.0.27.0 2010.05.05 -
Additional information
File size: 423923 bytes
MD5 : 6d893fe3bd58ba53e37ba89b63f05db3
SHA1 : cab725adb89eaa0fcb0d41c5d9f419209e26adf0
SHA256: 293f9ff4fc56c8d558249f7abaaf39492c64b01229e4f9530525b154f92247fd
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x17D64
timedatestamp.....: 0x2A425E19 (Sat Jun 20 00:22:17 1992)
machinetype.......: 0x14C (Intel I386)
( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0x16DC8 0x16E00 6.47 b770c7f279eb9fc26ac4a87d2b12ac8f
DATA 0x18000 0x700 0x800 3.18 c4c19ca9e500cb531e93a6fc31dcb110
BSS 0x19000 0x8A9 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0x1A000 0x14D0 0x1600 4.79 08b2ec6b7f09cb82de12e663d8041976
.tls 0x1C000 0x8 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 0x1D000 0x18 0x200 0.20 17291f4d14f4488dcc09f44b431f3d22
.reloc 0x1E000 0x11C0 0x1200 6.71 68baacd130dcf39d09b27606b341bb93
.rsrc 0x20000 0x2FC8 0x3000 4.24 a5f09a58f51757f9489ffd6c16b90372
( 10 imports )
> advapi32.dll: RegSetValueExA, RegQueryValueExA, RegQueryInfoKeyA, RegOpenKeyExA, RegEnumKeyExA, RegCreateKeyExA, RegCloseKey, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueA, GetUserNameA, GetTokenInformation, FreeSid, EqualSid, AllocateAndInitializeSid, AdjustTokenPrivileges
> cabinet.dll: FDIDestroy, FDICopy, FDICreate
> comctl32.dll: ImageList_Draw, ImageList_SetBkColor, ImageList_Create, InitCommonControls
> gdi32.dll: StretchDIBits, StretchBlt, SetWindowOrgEx, SetTextColor, SetStretchBltMode, SetRectRgn, SetROP2, SetPixel, SetDIBits, SetBrushOrgEx, SetBkMode, SetBkColor, SelectObject, SaveDC, RestoreDC, OffsetRgn, MoveToEx, IntersectClipRect, GetTextExtentPoint32A, GetStockObject, GetPixel, GetObjectA, GetDIBits, ExtSelectClipRgn, ExcludeClipRect, DeleteObject, DeleteDC, CreateSolidBrush, CreateRectRgn, CreateFontIndirectA, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CombineRgn, BitBlt, AddFontResourceA
> kernel32.dll: GetCurrentThreadId, WideCharToMultiByte, ExitProcess, UnhandledExceptionFilter, RtlUnwind, RaiseException, TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA, FreeLibrary, HeapFree, HeapReAlloc, HeapAlloc, GetProcessHeap, WritePrivateProfileStringA, WriteFile, WinExec, WaitForSingleObject, TerminateProcess, Sleep, SetFileTime, SetFilePointer, SetFileAttributesA, SetErrorMode, SetEndOfFile, SetCurrentDirectoryA, RemoveDirectoryA, ReadFile, OpenProcess, MultiByteToWideChar, LocalFileTimeToFileTime, LoadLibraryA, GlobalFree, GlobalAlloc, GetWindowsDirectoryA, GetVersionExA, GetVersion, GetUserDefaultLangID, GetTimeFormatA, GetTempPathA, GetSystemDirectoryA, GetShortPathNameA, GetProcAddress, GetPrivateProfileStringA, GetModuleHandleA, GetModuleFileNameA, GetLastError, GetFullPathNameA, GetFileTime, GetFileSize, GetFileAttributesA, GetExitCodeProcess, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThread, GetCurrentProcess, GetComputerNameA, GetCommandLineA, FreeLibrary, FormatMessageA, FindNextFileA, FindFirstFileA, FindClose, FileTimeToSystemTime, FileTimeToLocalFileTime, ExpandEnvironmentStringsA, DosDateTimeToFileTime, DeleteFileA, CreateFileA, CreateDirectoryA, CompareStringA, CloseHandle
> ole32.dll: OleInitialize, OleInitialize, CoTaskMemFree, CoCreateInstance, CoUninitialize, CoInitialize
> oleaut32.dll: SysFreeString, SysReAllocStringLen, SysAllocStringLen
> shell32.dll: SHGetFileInfoA, ShellExecuteExA, ShellExecuteA, SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHGetMalloc, SHChangeNotify, SHBrowseForFolderA
> user32.dll: wvsprintfA, WaitMessage, ValidateRect, TranslateMessage, ShowWindow, SetWindowPos, SetWindowLongA, SetTimer, SetPropA, SetParent, SetForegroundWindow, SetFocus, SetCursor, SendMessageA, ScreenToClient, RemovePropA, ReleaseDC, RegisterClassA, PostQuitMessage, PostMessageA, PeekMessageA, OffsetRect, MessageBoxA, LoadIconA, LoadCursorA, KillTimer, IsZoomed, IsWindowVisible, IsWindowEnabled, IsWindow, IsIconic, InvalidateRect, GetWindowTextLengthA, GetWindowTextA, GetWindowRgn, GetWindowRect, GetWindowLongA, GetWindowDC, GetUpdateRgn, GetSystemMetrics, GetSystemMenu, GetSysColor, GetPropA, GetParent, GetWindow, GetKeyState, GetFocus, GetDCEx, GetDC, GetCursorPos, GetClientRect, GetClassLongA, GetClassInfoA, GetCapture, FindWindowA, FillRect, ExitWindowsEx, EnumWindows, EndPaint, EnableWindow, EnableMenuItem, DrawTextA, DrawIcon, DispatchMessageA, DestroyWindow, DestroyIcon, DeleteMenu, DefWindowProcA, CopyImage, ClientToScreen, CheckRadioButton, CallWindowProcA, BeginPaint, CharLowerBuffA, CreateWindowExA
> winmm.dll: timeKillEvent, timeSetEvent
( 0 exports )
TrID : File type identification
Win32 Executable Delphi generic (39.8%)
Win32 Executable Generic (23.1%)
Win32 Dynamic Link Library (generic) (20.5%)
Win16/32 Executable Delphi generic (5.6%)
Generic Win/DOS Executable (5.4%)
ThreatExpert:
http://www.threatexpert.com/report.aspx ... 9b63f05db3 Symantec reputation: Suspicious.Insight
http://www.symantec.com/security_respon ... 23-0550-99 ssdeep: 12288:fU9Xiuizjk4OZRxT1ZSQzCcdCkh9RA4Mw/7E:fUdHudODZlG+dRAHiE
sigcheck: publisher....: Adobe Systems Incorporated
copyright....: Adobe Systems Incorporated
product......: n/a
description..: Adobe Flash_ Player 10.0.45.2 Installation
original name: n/a
internal name: n/a
file version.: 10.0.45.2
comments.....:
signers......: -
signing date.: -
verified.....: Unsigned
Prevx Info:
http://info.prevx.com/aboutprogramtext. ... 00CA9B6B56 PEiD : -
packers (Kaspersky): MoleboxUltraPatch
RDS : NSRL Reference Data Set
-
ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.