Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File v2captcha.exe received on 2009.12.25 00:04:55 (UTC)
Current status: finished
Result: 36/39 (92.31%)
Antivirus Version Last Update Result
a-squared 4.5.0.43 2009.12.24 Net-Worm.Win32.Koobface!IK
AhnLab-V3 5.0.0.2 2009.12.24 Win32/Koobface.worm.21504.T
AntiVir 7.9.1.122 2009.12.24 Worm/Koobface.csy
Antiy-AVL 2.0.3.7 2009.12.24 Worm/Win32.Koobface.gen
Authentium 5.2.0.5 2009.12.24 W32/Worm.AXSN
Avast 4.8.1351.0 2009.12.24 Win32:Trojan-gen
AVG 8.5.0.430 2009.12.24 Agent2.QGA
BitDefender 7.2 2009.12.24 Trojan.Koobface.10
CAT-QuickHeal 10.00 2009.12.24 I-Worm.Koobface.brr
ClamAV 0.94.1 2009.12.24 Worm.Koobface-230
Comodo 3355 2009.12.24 TrojWare.Win32.Trojan.Agent.Gen
DrWeb 5.0.1.12222 2009.12.24 Win32.HLLW.Facebook.194
eTrust-Vet None 2009.12.24 Win32/Koobface.IT
F-Prot 4.5.1.85 2009.12.24 W32/Worm.AXSN
F-Secure 9.0.15370.0 2009.12.24 Trojan.Koobface.10
Fortinet 4.0.14.0 2009.12.24 W32/Capper.BRR!worm.im
GData 19 2009.12.25 Trojan.Koobface.10
Ikarus T3.1.1.79.0 2009.12.24 Net-Worm.Win32.Koobface
K7AntiVirus 7.10.929 2009.12.24 Net-Worm.Win32.Koobface.brr
Kaspersky 7.0.0.125 2009.12.25 Net-Worm.Win32.Koobface.brr
McAfee 5842 2009.12.24 Generic.dx!iip
McAfee+Artemis 5842 2009.12.24 Generic.dx!iip
McAfee-GW-Edition 6.8.5 2009.12.24 Worm.Koobface.csy
Microsoft 1.5302 2009.12.24 Trojan:Win32/Koobface.gen!C
NOD32 4715 2009.12.24 Win32/TrojanDropper.Agent.NQX
Norman 6.04.03 2009.12.24 -
nProtect 2009.1.8.0 2009.12.24 Worm/W32.Koobface.21504.I
Panda 10.0.2.2 2009.12.15 W32/Koobface.C.worm
PCTools 7.0.3.5 2009.12.25 Net-Worm.Koobface
Prevx 3.0 2009.12.25 Medium Risk Malware
Rising 22.27.03.04 2009.12.24 Trojan.Win32.Generic.51F37FCA
Sophos 4.49.0 2009.12.24 Troj/Capper-Gen
Sunbelt 3.2.1858.2 2009.12.24 BehavesLike.Win32.Malware (v)
Symantec 1.4.4.12 2009.12.24 W32.Koobface.D
TheHacker 6.5.0.3.110 2009.12.24 W32/Koobface.brr
TrendMicro 9.120.0.1004 2009.12.24 -
VBA32 3.12.12.0 2009.12.24 Net-Worm.Win32.Koobface.brr
ViRobot 2009.12.24.2107 2009.12.24 Worm.Win32.Net-Koobface.21504.G
VirusBuster 5.0.21.0 2009.12.24 -
Additional information
File size: 21504 bytes
MD5   : effcb69928ec344e7be4a30d686f184a
SHA1  : 343e05ef7f83fe337590dfec1f62e8dcc591f5b7
SHA256: 6eca8a05683c104fbd24f8aad106405d9835a6762a025215e87f303202ed939a
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x141F
timedatestamp.....: 0x4B2160E2 (Thu Dec 10 21:58:10 2009)
machinetype.......: 0x14C (Intel I386)

( 2 sections )
name viradd virsiz rawdsiz ntrpy md5
.data 0x1000 0x8A2 0xA00 5.07 a178f3499ca5b7bec867e3d3ec0c0895
.rsrc 0x2000 0x4460 0x4600 7.46 8b9a72d35e7eb0d99d499aeeac4bb37c

( 3 imports )

> kernel32.dll: GetModuleHandleA, GetModuleFileNameA, GetEnvironmentVariableA, FindResourceA, LoadResource, LockResource, SetFileAttributesA, DeleteFileA, CreateFileA, SizeofResource, WriteFile, CloseHandle, CreateProcessA, GetStartupInfoA
> msvcrt.dll: _except_handler3, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _XcptFilter, _exit, sprintf, memset, _controlfp, strlen
> user32.dll: CharToOemA

( 0 exports )
TrID  : File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=effcb69928ec344e7be4a30d686f184a
ssdeep: 384:7ISld1uNT0ALqD7TWlgl6Y2wuknxjGPk9X3GN:73BuNT05D7PXHx19
sigcheck: publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=8B648FD6001266BD546B007BC6723200F9A57EB8
PEiD  : -
packers (F-Prot): UPX, embedded
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file