kapef.exe

The executable kapef.exe has been detected as malware by 32 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘kapef’.
MD5:
ee7068f515a3f42a9583ddd680575b26

SHA-1:
e3eb05a81be10ec183f90187c20c16986472d87a

SHA-256:
1595963cd8de0e4a7eca66ab7b725bbaec1828e2c38bccbbbb959c28107f2dbf

Scanner detections:
32 / 68

Status:
Malware

Analysis date:
4/28/2024 6:52:40 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/Vbna.worm.40960
2011.02.06

Avira AntiVirus
Worm/VBNA.iby
7.11.2.92

avast!
Win32:VB-NIK
2014.9-170310

AVG
Worm/AutoRun
2018.0.2444

Bitdefender
Trojan.VB.Chinky.U
1.0.20.345

Clam AntiVirus
Trojan.Chinky-1
0.98/17411

Comodo Security
Worm.Win32.VBNA.~gen
7611

Dr.Web
Trojan.MulDrop.34673
9.0.1.069

Emsisoft Anti-Malware
Worm.Win32.Vobfus!IK
8.17.03.10.04

ESET NOD32
Win32/AutoRun.VB.GE
11.5854

Fortinet FortiGate
W32/VBNA.D!tr
3/10/2017

F-Prot
W32/Vobfus.C.gen
v6.4.6.2.117

F-Secure
Worm:W32/Vinkus.gen!A
11.2017-10-03_6

G Data
Trojan.VB.Chinky
17.3.21

IKARUS anti.virus
Worm.Win32.Vobfus
t3scan.1.1.97.0

K7 AntiVirus
EmailWorm
13.81.3771

Kaspersky
Worm.Win32.VBNA
14.0.0.-1286

McAfee
Downloader-CJX.gen.g
5600.6100

Microsoft Security Essentials
Worm:Win32/Vobfus.C
1.163.1557.0

Norman
VBNA.F
11.20170310

nProtect
Trojan/W32.Agent.45056.VV
11.01.27.01

Panda Antivirus
W32/Vobfus.gen.worm
17.03.10.04

Prevx
High Risk Cloaked Malware
3.0

Quick Heal
Trojan.Vobfus.gen
3.17.11.00

Rising Antivirus
Trojan.Win32.VBCode.anx
23.00.65.17308

Sophos
W32/Autorun-ARS
4.61

SUPERAntiSpyware
Trojan.Agent/Gen-NameThief
8545

Trend Micro House Call
WORM_VB.SMP
7.2.69

Trend Micro
WORM_VB.SMP
10.465.10

Vba32 AntiVirus
SScope.Trojan.VB.Svchorse.026
3.12.14.3

VIPRE Antivirus
Worm.Win32.Vobfus.gen
8342

ViRobot
Worm.Win32.VBNA.45056.PB
2011.2.7.4297

File size:
44 KB (45,056 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\rehan cell\kapef.exe

File PE Metadata
Compilation timestamp:
12/31/1999 4:00:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1184

Entry point:
68, 4C, 12, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, A4, 69, B7, 3F, C2, 25, 55, 40, 82, DA, E9, 55, 68, 6A, 6B, 45, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 6F, 72, 6D, 3D, 46, 6F, 43, 4E, 77, 76, 69, 56, 77, 53, 00, 74, 57, 61, 6F, 3D, 46, 6F, 00, 00, 00, 00, 01, 00, 03, 00, 80, 22, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 64, 23, 40, 00, 4C, A2, 40, 00, 00, 00, 00, 00, 68, FF, 21, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.6366

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
36 KB (36,864 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
kapef

Command:
C:\users\rehan cell\kapef.exe


Remove kapef.exe - Powered by Reason Core Security