here is a virus scan
Antivirus Version Last Update Result
AhnLab-V3 2008.7.29.1 2008.08.04 -
AntiVir 7.8.1.15 2008.08.04 ADSPY/EShoper.AX
Authentium 5.1.0.4 2008.08.03 -
Avast 4.8.1195.0 2008.08.04 -
AVG 8.0.0.156 2008.08.04 -
BitDefender 7.2 2008.08.04 -
CAT-QuickHeal 9.50 2008.08.02 AdWare.EShoper.h (Not a Virus)
ClamAV 0.93.1 2008.08.04 -
DrWeb 4.44.0.09170 2008.08.04 -
eSafe 7.0.17.0 2008.08.03 Suspicious File
eTrust-Vet 31.6.6007 2008.08.04 -
Ewido 4.0 2008.08.04 -
F-Prot 4.4.4.56 2008.08.03 -
F-Secure 7.60.13501.0 2008.08.04 AdWare.Win32.EShoper.ax
Fortinet 3.14.0.0 2008.08.04 Adware/EShoper
GData 2.0.7306.1023 2008.08.04 -
Ikarus T3.1.1.34.0 2008.08.04 AdWare.Win32.EShoper.h
K7AntiVirus 7.10.402 2008.08.02 not-a-virus:AdWare.Win32.EShoper.h
Kaspersky 7.0.0.125 2008.08.04 not-a-virus:AdWare.Win32.EShoper.ax
McAfee 5352 2008.08.01 -
Microsoft 1.3807 2008.08.04 -
NOD32v2 3324 2008.08.04 -
Norman 5.80.02 2008.08.04 -
Panda 9.0.0.4 2008.08.03 -
PCTools 4.4.2.0 2008.08.04 -
Prevx1 V2 2008.08.04 Suspicious
Rising 20.56.02.00 2008.08.04 -
Sophos 4.31.0 2008.08.04 -
Sunbelt 3.1.1537.1 2008.08.01 AdWare.Win32.EShoper.ax
Symantec 10 2008.08.04 -
TheHacker 6.2.96.393 2008.08.04 Adware/EShoper.h
TrendMicro 8.700.0.1004 2008.08.04 PAK_Generic.001
VBA32 3.12.8.2 2008.08.04 AdWare.Win32.EShoper.h
ViRobot 2008.8.4.1322 2008.08.04 -
VirusBuster 4.5.11.0 2008.08.03 -
Webwasher-Gateway 6.6.2 2008.08.04 Ad-Spyware.EShoper.AX
Additional information
File size: 136435 bytes
MD5...: 47aa375010c4388688e19bbb3df969e2
SHA1..: 25ff8414b83a176738c429874424f182fbb2cc8b
SHA256: 331258d101b2a59ac5060ad484b8b49d58c4d3b378d772f3b7 ed2acb3dfbadef
SHA512: c50d10f4987ca4506cd6244f40fcea4cd4a01f79b75ee2f2ab 70c05291244534
b93704b6270e346f879ee15bd384dec5e006b287ac9ad3a5d2 fc4aa1e8417305
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x430de0
timedatestamp.....: 0x47543e98 (Mon Dec 03 17

24 2007)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x1d000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x1e000 0x13000 0x13000 7.92 e3a5549bf2a3638346bd406e339ad340
.rsrc 0x31000 0x3000 0x2e00 4.86 340aa9692f17c64e92c6f3b7e8e9c603
( 9 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> ADVAPI32.dll: RegCloseKey
> COMCTL32.dll: -
> comdlg32.dll: GetOpenFileNameA
> GDI32.dll: BitBlt
> ole32.dll: CoGetMalloc
> SHELL32.dll: DragFinish
> USER32.dll: IsIconic
> VERSION.dll: VerFindFileA
( 0 exports )
Prevx info:
INET INSTALLER.EXE - Prevx
packers (F-Prot): UPX