This is the result from Virus Total
I will try to follow Tech advice and get back to you with the result
Thanks a lot
Antivirus Version Last Update Result
AhnLab-V3 2008.7.11.0 2008.07.11 Win-Trojan/Xema.variant
AntiVir 7.8.0.64 2008.07.11 -
Authentium 5.1.0.4 2008.07.11 -
Avast 4.8.1195.0 2008.07.12 -
AVG 7.5.0.516 2008.07.12 -
BitDefender 7.2 2008.07.12 -
CAT-QuickHeal 9.50 2008.07.11 -
ClamAV 0.93.1 2008.07.11 -
DrWeb 4.44.0.09170 2008.07.12 -
eSafe 7.0.17.0 2008.07.10 -
eTrust-Vet 31.6.5949 2008.07.12 -
Ewido 4.0 2008.07.12 -
F-Prot 4.4.4.56 2008.07.11 -
F-Secure 7.60.13501.0 2008.07.12 -
Fortinet 3.14.0.0 2008.07.12 -
GData 2.0.7306.1023 2008.07.12 -
Ikarus T3.1.1.26.0 2008.07.12 Trojan.NtRootKit.270
Kaspersky 7.0.0.125 2008.07.12 -
McAfee 5337 2008.07.11 -
Microsoft 1.3704 2008.07.12 -
NOD32v2 3263 2008.07.11 -
Norman 5.80.02 2008.07.11 -
Panda 9.0.0.4 2008.07.12 -
Prevx1 V2 2008.07.12 -
Compact
VirusTotal - Free Online Virus and Malware Scan - Result
http://www.virustotal.com/analisis/0b79460eb08db5c3ee9f148840f3f0e81 of 3 12/07/2008 12:42 PM
Rising 20.52.52.00 2008.07.12 -
Sophos 4.31.0 2008.07.12 -
Sunbelt 3.1.1536.1 2008.07.12 -
Symantec 10 2008.07.12 -
TheHacker 6.2.96.376 2008.07.10 -
TrendMicro 8.700.0.1004 2008.07.11 -
VBA32 3.12.6.9 2008.07.12 Trojan.NtRootKit.270
VirusBuster 4.5.11.0 2008.07.12 -
Webwasher-Gateway 6.6.2 2008.07.11 -
Additional information
File size: 642560 bytes
MD5...: 7f6b041e60fe153e7584aeb9d708570c
SHA1..: e1af10fe8e95d8a932ce04b1fb6f1230b6a98c4e
SHA256: e5c5fd8402996d42fcdbf9e57cfb60f95c52c663c8d9aff7fcb4e5b479104cfb
SHA512: 53e4e35bf9564171a76fdcbb2e66ca2cd827fa10a2fdb329268737371f2e97a3
6bea09b9db209c55367120d69e9561e069f0346ec95504eb3f96e3c5834a22d8
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4016ce
timedatestamp.....: 0x46130dca (Wed Apr 04 02:30:34 2007)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x9ce 0xa00 6.08 f189542e08c559931787766ce6450847
.cdata 0x2000 0x4400 0x4400 6.00 69746fe74257d029d538c3b8429ea0f4
.mdata 0x7000 0x300 0x400 1.94 aadc0c535edf312205c3a2153c4a3283
.reloc 0x8000 0x60 0x200 1.51 737c7c8641e2692a26d3adfc985b4135
( 1 imports )
> ntdll.dll: NtCreateKey, NtOpenProcessToken, NtCreateFile, NtClose,
NtAdjustPrivilegesToken, NtDeleteFile, NtWriteFile, RtlInitUnicodeString,
NtSetSecurityObject, NtTerminateProcess, NtSetValueKey,
NtQuerySecurityObject, NtReadFile, RtlQueryEnvironmentVariable_U,
NtQueryInformationToken, RtlUnwind, wcscpy
( 0 exports )
packers (F-Prot): embedded