| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 131072 |
| N/A | |
| becb9e1e34a9822e1e9ab1964782dd48 | |
| 7039bf917cf9dd339f2b037566e9817716abf7ea | |
| add54bda747b020c1125f7c0e418a4ced24417130f2411e274d1129ddf216031 | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| application/octet-stream | |
| 7.0 | |
| N/A | |
| 102400 | |
| 0.0 | |
| Win32 EXE | |
| 128 kB | |
| Intel 386 or later, and compatibles | |
| 4.0 | |
| Windows GUI | |
| 24576 | |
| 4.0 | |
| 0x1972 | |
| Source: |

| AVG | Dropper.Generic7.APFU |
| Agnitum | Trojan.DR.Necurs!FVlZIY8R6W4 |
| AhnLab-V3 | Trojan/Win32.Necurs |
| AntiVir | TR/Dropper.Gen6 |
| Avast | Win32:Malware-gen |
| BitDefender | Trojan.Generic.KDZ.4667 |
| Comodo | UnclassifiedMalware |
| DrWeb | Trojan.Inject1.16971 |
| ESET-NOD32 | a variant of Win32/Kryptik.ASIO |
| F-Secure | Trojan.Generic.KDZ.4667 |
| Fortinet | W32/FakeAV.KLA!tr |
| GData | Trojan.Generic.KDZ.4667 |
| Ikarus | Trojan-Dropper.Win32.Necurs |
| Jiangmin | TrojanDropper.Necurs.arm |
| K7AntiVirus | Trojan |
| Kaspersky | Trojan-Dropper.Win32.Necurs.dgx |
| Kingsoft | Win32.Troj.Necurs.d.(kcloud) |
| Malwarebytes | Trojan.FakeAlert.PEX |
| McAfee | FakeAlert-FGH!BECB9E1E34A9 |
| McAfee-GW-Edition | Heuristic.BehavesLike.Win32.Dropper.H |
| MicroWorld-eScan | Trojan.Generic.KDZ.4667 |
| Microsoft | Trojan:Win32/Necurs.gen!A |
| Norman | FakeAV.BONJ |
| PCTools | Trojan.Gen |
| Panda | Trj/CI.A |
| SUPERAntiSpyware | Trojan.Agent/Gen-Necurs |
| Sophos | Mal/FakeAV-SD |
| Symantec | Trojan.Gen |
| TheHacker | Trojan/Kryptik.asio |
| TrendMicro | TROJ_GEN.R47Z4AH |
| TrendMicro-HouseCall | TROJ_KREPTK.SM04 |
| VBA32 | Trojan-Dropper.Necurs.dgx |
| VIPRE | Trojan.Win32.FakeAV.gcd (v) |
| nProtect | Trojan/W32.Agent.131072.BRY |