DavidR and Maxx_original, thank you very much.
In the meantime, I took a chance, and extracted the setup.exe from the archive, but not runing it. Instead, I used some zip utility to read the archive, and extracted just the setup.exe. Since I have Avast also configured to check any task done by the zip utility, again a message about the trojan pop up, as I expected.
I then move the setup.exe file to the c:\suspect folder, and took its hash info. I checked this in VT as before. This file is way smaller than the whole archive. Here the relevants results of VT:
File Setup.exe received on 08.17.2008 03:32:18 (CET)Antivirus Version Last Update Result
Avast 4.8.1195.0 2008.08.15 Win32:Trojan-gen {Other}
BitDefender 7.2 2008.08.17 DeepScan:Generic.Malware.P!Pk.F2DDCE78
Fortinet 3.14.0.0 2008.08.16 PossibleThreat
GData 2.0.7306.1023 2008.08.16 Win32:Trojan-gen
Ikarus T3.1.1.34.0 2008.08.17 Win32.SuspectCrc
Norman 5.80.02 2008.08.15 W32/Agent.GQGL
Sunbelt 3.1.1546.1 2008.08.15 Trojan.Agent
Additional information
File size: 211464 bytes
MD5…: 7a046dc9d808a0002396a686063dc6bb
SHA1…: ffdd6ac0528da60a0b8a8ca2e4c09be96156bbc6
SHA256: 527d02f13c1648657795c305c2048833bb8c614637e1731912334478b5e21388
SHA512: 0e8351a1820af129fe4647e0be4e432b444518e080ff5d77a6fc7009d6ad87e5
6e89e04329386b59879e713743ad32dbe66fa352b24baec9944faf72fd67ba4a
PEiD…: Armadillo v1.71
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x409ec3
timedatestamp…: 0x467b9618 (Fri Jun 22 09:27:52 2007)
machinetype…: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x20786 0x21000 6.55 428a2ae430e6ccaa2db47388ea7962c9
.rdata 0x22000 0x842a 0x9000 4.55 77aafdeedd4bc0f593dafe179fc8ecbc
.data 0x2b000 0x6548 0x3000 3.31 478f458e2048021ad74d89185d160b57
.rsrc 0x32000 0x3e20 0x4000 4.30 511d16a3188ec9a90cc093b359606298
( 11 imports )
> KERNEL32.dll: TerminateProcess, GetStartupInfoA, ExitProcess, RtlUnwind, GetCommandLineA, HeapAlloc, RaiseException, HeapFree, HeapReAlloc, GetACP, GetTimeZoneInformation, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, HeapSize, SetHandleCount, GetEnvironmentStringsW, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, IsBadWritePtr, LCMapStringA, LCMapStringW, GlobalHandle, LeaveCriticalSection, GlobalUnlock, IsBadReadPtr, IsBadCodePtr, SetStdHandle, SizeofResource, CompareStringW, SetEnvironmentVariableA, FileTimeToSystemTime, GetTickCount, FileTimeToLocalFileTime, GetCPInfo, GetOEMCP, SetErrorMode, GetFileTime, GetProcessVersion, GetFileSize, GetFileAttributesA, GlobalAddAtomA, GetVersion, GlobalGetAtomNameA, GlobalFindAtomA, GetModuleHandleA, GlobalFlags, lstrcatA, WritePrivateProfileStringA, LocalReAlloc, MulDiv, TlsGetValue, GlobalReAlloc, TlsSetValue, EnterCriticalSection, GetStdHandle, TlsFree, lstrcmpiA, GetCurrentThread, GetCurrentThreadId, CreateToolhelp32Snapshot, Process32First, Process32Next, GetLastError, OpenProcess, CloseHandle, LoadLibraryA, GetProcAddress, GetCurrentProcess, FreeLibrary, GetVersionExA, GetModuleFileNameA, SetCurrentDirectoryA, WinExec, GetStringTypeA, DeleteCriticalSection, TlsAlloc, GetProfileStringA, InitializeCriticalSection, LocalAlloc, GetThreadLocale, GetFullPathNameA, GetVolumeInformationA, FindFirstFileA, FindClose, lstrcpyA, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, CreateFileA, DuplicateHandle, lstrcpynA, SetLastError, FindResourceA, LoadResource, LockResource, GlobalFree, FormatMessageA, LocalFree, MultiByteToWideChar, WideCharToMultiByte, lstrlenA, InterlockedDecrement, InterlockedIncrement, GlobalLock, GlobalAlloc, GlobalDeleteAtom, lstrcmpA, GetStringTypeW, SetUnhandledExceptionFilter, GetFileType, CompareStringA, Sleep
> USER32.dll: InvalidateRect, InflateRect, RegisterClipboardFormatA, PostThreadMessageA, CreateDialogIndirectParamA, EndDialog, MessageBeep, GetNextDlgGroupItem, SetRect, CopyAcceleratorTableA, CharNextA, LoadStringA, GetSysColorBrush, LoadIconA, UpdateWindow, MapWindowPoints, GetSysColor, SetActiveWindow, IsWindow, AdjustWindowRectEx, GetClientRect, CopyRect, GetTopWindow, IsChild, WinHelpA, GetClassInfoA, RegisterClassA, GetMenu, GetSubMenu, GetMenuItemID, DefWindowProcA, DestroyWindow, CreateWindowExA, GetClassLongA, SetPropA, GetPropA, CallWindowProcA, GetMessagePos, GetForegroundWindow, SetForegroundWindow, RegisterWindowMessageA, OffsetRect, IntersectRect, SystemParametersInfoA, IsIconic, GetWindowPlacement, SetFocus, ShowWindow, MoveWindow, SetWindowLongA, GetWindowTextLengthA, IsDialogMessageA, SendDlgItemMessageA, GetDlgItem, GrayStringA, DrawTextA, TabbedTextOutA, EndPaint, BeginPaint, GetWindowDC, ReleaseDC, GetDC, GetMenuItemCount, GetWindowTextA, SetWindowTextA, GetDlgCtrlID, GetWindowRect, PtInRect, GetClassNameA, ScreenToClient, ClientToScreen, GetDesktopWindow, LoadCursorA, GetCapture, GetSystemMetrics, CharUpperA, wsprintfA, MapDialogRect, SetWindowPos, GetWindow, SetWindowContextHelpId, DestroyMenu, GetMessageTime, RemovePropA, UnhookWindowsHookEx, GetMenuCheckMarkDimensions, LoadBitmapA, GetMenuState, ModifyMenuA, SetMenuItemBitmaps, CheckMenuItem, EnableMenuItem, GetFocus, GetNextDlgTabItem, GetMessageA, TranslateMessage, DispatchMessageA, GetActiveWindow, GetKeyState, CallNextHookEx, ValidateRect, IsWindowVisible, PeekMessageA, GetCursorPos, SetWindowsHookExA, GetParent, GetLastActivePopup, IsWindowEnabled, GetWindowLongA, EnableWindow, SetCursor, SendMessageA, PostQuitMessage, PostMessageA, MessageBoxA, DrawFocusRect, UnregisterClassA, HideCaret, ShowCaret, ExcludeUpdateRgn, DefDlgProcA, IsWindowUnicode
> GDI32.dll: GetDeviceCaps, GetViewportExtEx, GetWindowExtEx, CreateSolidBrush, PtVisible, RectVisible, TextOutA, ExtTextOutA, Escape, GetObjectA, GetTextColor, GetBkColor, DPtoLP, LPtoDP, GetMapMode, PatBlt, CreateDIBitmap, CreateCompatibleDC, BitBlt, GetTextExtentPointA, IntersectClipRect, GetClipBox, ScaleWindowExtEx, SetWindowExtEx, SetViewportExtEx, OffsetViewportOrgEx, ScaleViewportExtEx, SetMapMode, SetTextColor, SetViewportOrgEx, SetBkColor, SetBkMode, SelectObject, RestoreDC, GetStockObject, DeleteDC, SaveDC, CreateBitmap, DeleteObject
> comdlg32.dll: GetFileTitleA
> WINSPOOL.DRV: ClosePrinter, DocumentPropertiesA, OpenPrinterA
> ADVAPI32.dll: RegCreateKeyExA, RegCloseKey, RegOpenKeyExA, RegSetValueExA
> COMCTL32.dll: -
> oledlg.dll: -
> ole32.dll: CoFreeUnusedLibraries, OleUninitialize, OleInitialize, CoTaskMemFree, CreateILockBytesOnHGlobal, StgCreateDocfileOnILockBytes, CoGetClassObject, CLSIDFromString, CLSIDFromProgID, StgOpenStorageOnILockBytes, CoRegisterMessageFilter, CoRevokeClassObject, OleFlushClipboard, OleIsCurrentClipboard, CoTaskMemAlloc
> OLEPRO32.DLL: -
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -
( 0 exports )
I hope this will help. Keep the good job, and again thank you very much for your help.