Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File fbi_facebook.exe received on 07.28.2008 15:51:50 (CET)
Current status: finished
Result: 18/35 (51.43%)
Antivirus Version Last Update Result
AhnLab-V3 2008.7.26.0 2008.07.28 -
AntiVir 7.8.1.12 2008.07.28 Worm/Zhelatin.zk
Authentium 5.1.0.4 2008.07.28 -
Avast 4.8.1195.0 2008.07.28 Win32:Tibs-EIG
AVG 8.0.0.130 2008.07.28 I-Worm/Nuwar.V
BitDefender 7.2 2008.07.28 Trojan.Peed.JPS
CAT-QuickHeal 9.50 2008.07.25 -
ClamAV 0.93.1 2008.07.28 -
DrWeb 4.44.0.09170 2008.07.28 Trojan.Packed.555
eSafe 7.0.17.0 2008.07.27 Suspicious File
eTrust-Vet 31.6.5989 2008.07.28 Win32/Sintun.FK
Ewido 4.0 2008.07.28 -
F-Prot 4.4.4.56 2008.07.28 -
F-Secure 7.60.13501.0 2008.07.28 Packed.Win32.Tibs.kg
Fortinet 3.14.0.0 2008.07.26 -
GData 2.0.7306.1023 2008.07.28 Packed.Win32.Tibs.kg
Ikarus T3.1.1.34.0 2008.07.28 -
Kaspersky 7.0.0.125 2008.07.28 Packed.Win32.Tibs.kg
McAfee 5347 2008.07.25 W32/Nuwar@MM
Microsoft 1.3704 2008.07.28 Backdoor:Win32/Nuwar.gen!E
NOD32v2 3303 2008.07.28 a variant of Win32/Nuwar.DF
Norman 5.80.02 2008.07.28 -
Panda 9.0.0.4 2008.07.28 Suspicious file
PCTools 4.4.2.0 2008.07.28 -
Prevx1 V2 2008.07.28 -
Rising 20.55.02.00 2008.07.28 -
Sophos 4.31.0 2008.07.28 Mal/Dorf-O
Sunbelt 3.1.1536.1 2008.07.25 -
Symantec 10 2008.07.28 Trojan.Peacomm.D
TheHacker 6.2.96.389 2008.07.25 -
TrendMicro 8.700.0.1004 2008.07.28 -
VBA32 3.12.8.1 2008.07.28 -
ViRobot 2008.7.26.1311 2008.07.28 -
VirusBuster 4.5.11.0 2008.07.28 Worm.DR.Zhelatin.Gen!Pac.12
Webwasher-Gateway 6.6.2 2008.07.28 Worm.Zhelatin.zk
Additional information
File size: 91648 bytes
MD5...: 81ccb4c9358470cb3240209aa1df8b53
SHA1..: 88b7cda6f5dca6547d77fa599b9d034ddd2fe3aa
SHA256: d2dcc20c2f49854983b1afc4b3ccc2402cb566cb89ca103c9aa70486b5c5d606
SHA512: f464cb247c68981d73c0b7cefa8b20be3f240ebd9e413ffad6ea21e31b3a3dbb
3d897865b77383e36c36348c2207ca3a94c1cc0305bfdb89f621ac5afa265124
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4055c6
timedatestamp.....: 0x488d3529 (Mon Jul 28 02:55:37 2008)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.code 0x1000 0x4637 0x4800 7.94 bacfd75a355107768e56be566d043897
.rdata 0x6000 0x155 0x200 3.41 17fdcf90d61687a915618c59a68a479e
.data 0x7000 0x7e0 0x800 7.71 cf389da71e59155568c212a4a3caa5c0
.mdata 0x8000 0x10f01 0x11000 8.00 2fc4374e38b0d97efd7d4f57b49c9b8e

( 1 imports )
> KERNEL32.dll: GetProcAddress, GetModuleHandleW, VirtualAlloc, GetLastError

( 3 exports )
ewxcv, qazed, rfgni

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file