Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File Setup.exe received on 2009.06.17 14:59:31 (UTC)
Current status: finished
Result: 14/41 (34.15%)
Antivirus Version Last Update Result
a-squared 4.5.0.18 2009.06.17 Worm.Win32.Koobface!IK
AhnLab-V3 5.0.0.2 2009.06.17 -
AntiVir 7.9.0.187 2009.06.17 -
Antiy-AVL 2.0.3.1 2009.06.17 -
Authentium 5.1.2.4 2009.06.17 -
Avast 4.8.1335.0 2009.06.16 -
AVG 8.5.0.339 2009.06.17 Proxy.AGSF
BitDefender 7.2 2009.06.17 -
CAT-QuickHeal 10.00 2009.06.17 -
ClamAV 0.94.1 2009.06.17 -
Comodo 1351 2009.06.17 -
DrWeb 5.0.0.12182 2009.06.17 -
eSafe 7.0.17.0 2009.06.17 Suspicious File
eTrust-Vet 31.6.6564 2009.06.17 Win32/Koobface.BC
F-Prot 4.4.4.56 2009.06.16 -
F-Secure 8.0.14470.0 2009.06.17 Suspicious:W32/Malware!Gemini
Fortinet 3.117.0.0 2009.06.17 -
GData 19 2009.06.17 -
Ikarus T3.1.1.59.0 2009.06.17 Worm.Win32.Koobface
Jiangmin 11.0.706 2009.06.17 -
K7AntiVirus 7.10.765 2009.06.16 -
Kaspersky 7.0.0.125 2009.06.17 Net-Worm.Win32.Koobface.abl
McAfee 5648 2009.06.16 W32/Koobface.worm
McAfee+Artemis 5648 2009.06.16 W32/Koobface.worm
McAfee-GW-Edition 6.7.6 2009.06.17 -
Microsoft 1.4701 2009.06.17 Worm:Win32/Koobface.gen!D
NOD32 4162 2009.06.17 a variant of Win32/Koobface.NBQ
Norman 6.01.09 2009.06.17 -
nProtect 2009.1.8.0 2009.06.17 -
Panda 10.0.0.14 2009.06.16 -
PCTools 4.4.2.0 2009.06.17 -
Prevx 3.0 2009.06.17 -
Rising 21.34.24.00 2009.06.17 Trojan.PSW.Win32.GameOnline.doz
Sophos 4.42.0 2009.06.17 -
Sunbelt 3.2.1858.2 2009.06.17 -
Symantec 1.4.4.12 2009.06.17 W32.Koobface.A
TheHacker 6.3.4.3.347 2009.06.17 -
TrendMicro 8.950.0.1094 2009.06.17 PAK_Generic.001
VBA32 3.12.10.7 2009.06.17 -
ViRobot 2009.6.17.1792 2009.06.17 -
VirusBuster 4.6.5.0 2009.06.17 -
Additional information
File size: 15360 bytes
MD5   : 72ce12bef0e42028050255c7e108033d
SHA1  : 7bc218c99b0b16f9d0331d144e99ba836b903d28
SHA256: 14af606969c8a8a7c64e008f9ef6623503a5a11fb44771959535b241fb2d8b95
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xA180
timedatestamp.....: 0x4A37FA5C (Tue Jun 16 22:02:36 2009)
machinetype.......: 0x14C (Intel I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x6000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x7000 0x4000 0x3400 7.84 437921d425f275b5e3b8313b1378ae81
UPX2 0xB000 0x1000 0x400 2.68 998e8b5a9e91df60e8aff8f40208a814

( 8 imports )

> kernel32.dll: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> msvcp60.dll: _npos@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@2IB
> msvcrt.dll: rand
> ole32.dll: CoInitialize
> oleaut32.dll: -
> shell32.dll: CommandLineToArgvW
> shlwapi.dll: StrStrA
> ws2_32.dll: -

( 0 exports )
TrID  : File type identification
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
ssdeep: 192:3nfnm0UrEOyostmwhYqy9R67BSpjOW2rw+N8pce/GXCUabwDJ5f+MMSl8RmYsZxf:XfXUTiYqZV42rLNwvOXCIDGSlqsZQ
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=BFBD7FCE00FC7AFF3C9A002565385B00CBBCA0B7
PEiD  : -
packers (F-Prot): UPX
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file