Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File fbi_facebook.exe received on 2008.07.28 17:53:01 (UTC)
Current status: finished
Result: 17/35 (48.57%)
Antivirus Version Last Update Result
AhnLab-V3 2008.7.26.0 2008.07.28 -
AntiVir 7.8.1.12 2008.07.28 Worm/Zhelatin.zk
Authentium 5.1.0.4 2008.07.28 -
Avast 4.8.1195.0 2008.07.28 Win32:Tibs-EIG
AVG 8.0.0.130 2008.07.28 I-Worm/Nuwar.V
BitDefender 7.2 2008.07.28 Trojan.Peed.JPS
CAT-QuickHeal 9.50 2008.07.28 -
ClamAV 0.93.1 2008.07.28 -
DrWeb 4.44.0.09170 2008.07.28 Trojan.Packed.555
eSafe 7.0.17.0 2008.07.28 Suspicious File
eTrust-Vet 31.6.5989 2008.07.28 Win32/Sintun.FK
Ewido 4.0 2008.07.28 -
F-Prot 4.4.4.56 2008.07.28 -
F-Secure 7.60.13501.0 2008.07.28 Packed.Win32.Tibs.kg
Fortinet 3.14.0.0 2008.07.26 -
GData 2.0.7306.1023 2008.07.28 Packed.Win32.Tibs.kg
Ikarus T3.1.1.34.0 2008.07.28 -
Kaspersky 7.0.0.125 2008.07.28 Packed.Win32.Tibs.kg
McAfee 5347 2008.07.25 W32/Nuwar@MM
Microsoft 1.3704 2008.07.28 Backdoor:Win32/Nuwar.gen!E
NOD32v2 3304 2008.07.28 a variant of Win32/Nuwar.DF
Norman 5.80.02 2008.07.28 -
Panda 9.0.0.4 2008.07.28 Suspicious file
PCTools 4.4.2.0 2008.07.28 -
Prevx1 V2 2008.07.28 -
Rising 20.55.02.00 2008.07.28 -
Sophos 4.31.0 2008.07.28 Mal/Dorf-O
Sunbelt 3.1.1536.1 2008.07.28 -
Symantec 10 2008.07.28 Trojan.Peacomm.D
TheHacker 6.2.96.389 2008.07.25 -
TrendMicro 8.700.0.1004 2008.07.28 -
VBA32 3.12.8.1 2008.07.28 -
ViRobot 2008.7.26.1311 2008.07.28 -
VirusBuster 4.5.11.0 2008.07.28 -
Webwasher-Gateway 6.6.2 2008.07.28 Worm.Zhelatin.zk
Additional information
File size: 91136 bytes
MD5...: e1b5595e0ed29f2282eaaf1e15627ac6
SHA1..: 896ac20b15ca3fc2bbb1e7787c9b7e4eacdbef1a
SHA256: 313e3f8787c4f52f6d9db065852488b9eac8cd0cdf74f959cbca23daeac67376
SHA512: a0ce3209537b5f2ba261086a0e18695637e88c67a11eb3214e3a14d571abc2c4
814c5a8200ef7ba1cfceb226127b33547179ddf795f9fae3b5285ccdf220c908
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x405565
timedatestamp.....: 0x488d6c3d (Mon Jul 28 06:50:37 2008)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.code 0x1000 0x45d9 0x4600 7.99 06a4cb2bacf717ebc4bee774fbb3bd80
.rdata 0x6000 0x155 0x200 3.41 2f6a1b85323467f110ed50ea4fa80032
.data 0x7000 0x7e0 0x800 7.74 662a04d013a7653c17d0d5ba839740a0
.mdata 0x8000 0x10edd 0x11000 7.99 68fe29cab03fdc2f5c592fc2aaf27c7a

( 1 imports )
> KERNEL32.dll: GetProcAddress, GetModuleHandleW, VirtualAlloc, GetLastError

( 3 exports )
ewxcv, qazed, rfgni

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file