Antivirus Version Last Update Result a-squared 4.0.0.101 2009.05.05 Trojan-PWS.Win32.Agent.jp!IK AhnLab-V3 5.0.0.2 2009.05.05 Packed/Upack AntiVir 7.9.0.160 2009.05.05 TR/Hijacker.Gen Antiy-AVL 2.0.3.1 2009.05.05 - Authentium 5.1.2.4 2009.05.06 W32/Heuristic-210!Eldorado Avast 4.8.1335.0 2009.05.05 - AVG 8.5.0.327 2009.05.05 Suspicion: unknown virus BitDefender 7.2 2009.05.06 - CAT-QuickHeal 10.00 2009.05.05 - ClamAV 0.94.1 2009.05.05 - Comodo 1151 2009.05.05 - DrWeb 5.0.0.12182 2009.05.06 - eSafe 7.0.17.0 2009.05.05 Suspicious File eTrust-Vet 31.6.6490 2009.05.05 - F-Prot 4.4.4.56 2009.05.05 W32/Heuristic-210!Eldorado F-Secure 8.0.14470.0 2009.05.05 W32/Packed_Upack.H Fortinet 3.117.0.0 2009.05.05 - GData 19 2009.05.06 - Ikarus T3.1.1.49.0 2009.05.05 Trojan-PWS.Win32.Agent.jp K7AntiVirus 7.10.723 2009.05.05 Generic.Packed.Upack Kaspersky 7.0.0.125 2009.05.05 - McAfee 5606 2009.05.05 - McAfee-GW-Edition 6.7.6 2009.05.06 Trojan.Hijacker.Gen Microsoft 1.4602 2009.05.06 VirTool:Win32/Obfuscator.C NOD32 4054 2009.05.05 - Norman 6.01.05 2009.05.05 W32/Packed_Upack.H nProtect 2009.1.8.0 2009.05.04 - Panda 10.0.0.14 2009.05.05 - PCTools 4.4.2.0 2009.05.05 Packed/Upack Prevx1 3.0 2009.05.06 - Rising 21.28.12.00 2009.05.05 - Sophos 4.41.0 2009.05.05 Mal/Packer Sunbelt 3.2.1858.2 2009.05.06 - Symantec 1.4.4.12 2009.05.06 - TheHacker 6.3.4.1.319 2009.05.05 W32/Behav-Heuristic-060 TrendMicro 8.950.0.1092 2009.05.05 Cryp_Upack VBA32 3.12.10.4 2009.05.05 - ViRobot 2009.5.4.1719 2009.05.04 - VirusBuster 4.6.5.0 2009.05.05 Packed/Upack Additional information File size: 72309 bytes MD5...: 0c3b985a74b6fcd3cfad7a63ffc924a5 SHA1..: c2cdad92010dcc26c9eb5b75b6fc81f604d15650 SHA256: 379b5d42ebaa309bf2f3f21518c6827618f1eb9f8aedfa1c1bfc420cb5ee1ffb SHA512: 49440a27bc4b0ee170cff03c077d502de7b2fa05f5500d4322b24f9969e09368 920bbd0a5152612222e6fcaf151db983123860ac2b80c6c8a5d35d36c8b18ce0 ssdeep: 1536:Jdmgdsd0QlwyuhsZcjG09UDZ9JXvd7WcMkiFbksEzALOFu815V:J8gdQVaP h2l09Ut9VvdpMkiF4/z42uAV PEiD..: WinUpack v0.39 final (relocated image base) -> By Dwing (c)2005 (h2) TrID..: File type identification DOS Executable Generic (100.0%) PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x56599 timedatestamp.....: 0x1000 (Thu Jan 01 01:08:16 1970) machinetype.......: 0x14c (I386) ( 2 sections ) name viradd virsiz rawdsiz ntrpy md5 .Upack 0x1000 0x44000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e .rsrc 0x45000 0x19000 0x11875 8.00 482c341b7e80f74f2db261a6f7f6c902 ( 1 imports ) > KERNEL32.DLL: LoadLibraryA, GetProcAddress ( 0 exports ) PDFiD.: - RDS...: NSRL Reference Data Set - packers (Kaspersky): UPack packers (Authentium): UPack packers (F-Prot): UPack