File name:
000057721_FOUND.000.exe
Submission date:
2010-04-05 03:53:08 (UTC)
Current status:
finished
Result:
39 /42 (92.9%)
VT Community
not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.04.05 IM-Worm.Win32.VB!IK
AhnLab-V3 5.0.0.2 2010.04.03 Win32/Cogduni.worm.61440
AntiVir 7.10.6.24 2010.04.03 BDS/Pakes
Antiy-AVL 2.0.3.7 2010.04.02 -
Authentium 5.2.0.5 2010.04.04 W32/Lurka.A
Avast 4.8.1351.0 2010.04.04 Win32:Trojan-gen
Avast5 5.0.332.0 2010.04.04 Win32:Trojan-gen
AVG 9.0.0.787 2010.04.04 BackDoor.Bifrose.EU
BitDefender 7.2 2010.04.05 Backdoor.Agent.YPB
CAT-QuickHeal 10.00 2010.04.03 Worm.SillyFDC.gen
ClamAV 0.96.0.0-git 2010.04.03 W32.Virut.Gen.D-61
Comodo 4502 2010.04.05 Worm.Win32.VB.NJO0
DrWeb 5.0.2.03300 2010.04.05 Trojan.MulDrop.8034
eSafe 7.0.17.0 2010.04.01 Win32.WormWinNTLurka
eTrust-Vet 35.2.7405 2010.04.02 Win32/Lurka.A
F-Prot 4.5.1.85 2010.04.04 W32/Lurka.A
F-Secure 9.0.15370.0 2010.04.05 Backdoor.Agent.YPB
Fortinet 4.0.14.0 2010.04.04 W32/Lurker.A
GData 19 2010.04.05 Backdoor.Agent.YPB
Ikarus T3.1.1.80.0 2010.04.05 IM-Worm.Win32.VB
Jiangmin 13.0.900 2010.04.04 Win32/lurker.a
K7AntiVirus 7.10.1004 2010.03.22 Virus.Win32.Virut.Generic
Kaspersky 7.0.0.125 2010.04.05 -
McAfee 5937 2010.03.31 W32/Lurka.a
McAfee+Artemis 5937 2010.03.31 W32/Lurka.a
McAfee-GW-Edition 6.8.5 2010.04.03 Trojan.Backdoor.Pakes
Microsoft 1.5605 2010.04.04 Virus:Win32/Lurka.A
NOD32 4999 2010.04.04 a variant of Win32/VB.NJO
Norman 6.04.10 2010.04.03 W32/Lurker.B
nProtect 2009.1.8.0 2010.04.04 Backdoor.Agent.YPB
Panda 10.0.2.2 2010.04.04 -
PCTools 7.0.3.5 2010.04.05 Malware.Lurkasys
Prevx 3.0 2010.04.05 High Risk Cloaked Malware
Rising 22.41.04.05 2010.04.02 Worm.VB.aii
Sophos 4.52.0 2010.04.05 W32/Lurka-A
Sunbelt 6138 2010.04.05 Virus.Win32.Virut.b (v)
Symantec 20091.2.0.41 2010.04.05 W32.Lurkasys.A!inf
TheHacker 6.5.2.0.252 2010.04.05 W32/Lurka.A
TrendMicro 9.120.0.1004 2010.04.04 PE_LURKER.A
VBA32 3.12.12.4 2010.04.02 SScope.Backdoor.Bifrose.ago
ViRobot 2010.4.3.2259 2010.04.04 I-Worm.Win32.Generic.61440
VirusBuster 5.0.27.0 2010.04.04 Win32.Lurka.H
Additional information
Show all
MD5 : db8ecedc7b0080d146f21308a6fe019a
SHA1 : 4bd76d23077d0ce35668843bb3eec270a8d95852
SHA256: 1e281ae1c8cfb658222b3f3948fdf9b7b529d6a9ed5df0295a 34ad9c67808ae7
ssdeep: 6144

87jogxu/xzDegxu/xzDWGd6gxu/xzDocNgxu/xzDPfyFmL6wgxu/xzD:HniniDnPNnLf4
2/n
File size : 831488 bytes
First seen: 2010-04-05 03:53:08
Last seen : 2010-04-05 03:53:08
Magic: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
TrID:
Win32 Executable MS Visual C++ (generic) (75.0%)
Win32 Executable Generic (16.9%)
Generic Win/DOS Executable (3.9%)
DOS Executable Generic (3.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: v
copyright....: n/a
product......: v
description..: n/a
original name: windown_update.exe
internal name: windown_update
file version.: 1.00
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
PEiD: -
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x10EC
timedatestamp....: 0x1A197200 (Thu Nov 17 00:00:00 1983)
machinetype......: 0x14C (Intel I386)
[[ 3 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0xB10C, 0xC000, 4.97, dc120d6c2d669975993d9735d751d60c
.data, 0xD000, 0x14D8, 0x0, 0.0, d41d8cd98f00b204e9800998ecf8427e
.rsrc, 0xF000, 0xBD125, 0xBE000, 4.06, d97386c600d5b7ae518d4cebf82e2ec4
[[ 1 import(s) ]]
msvbvm60.dll: MethCallEngine, -, -, -, EVENT_SINK_AddRef, -, -, DllFunctionCall, EVENT_SINK_Release, -, EVENT_SINK_QueryInterface, __vbaExceptHandler, -, -, ProcCallEngine, -, -, -, -, -, -, -, -