البو رضا.exe

The executable البو رضا.exe has been detected as malware by 42 anti-virus scanners.
MD5:
007af85de110b38a2cee9d95dfd62624

SHA-1:
f085409897180772ffa08af6db8aad3ac1c81a12

SHA-256:
e03895883aa485efb9835a4476a716544e3e107f88c928879388536cf2c83e51

Scanner detections:
42 / 68

Status:
Malware

Analysis date:
5/7/2024 6:13:16 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Agent.AQNV
674

Agnitum Outpost
Trojan.Agent2
7.1.1

AhnLab V3 Security
Win-Trojan/Agent.100616.B
15.04.01

Avira AntiVirus
TR/Patched.Ren.Gen
7.11.148.132

avast!
Win32:Sality
2014.9-150401

AVG
Worm/Generic_r
2016.0.3152

Baidu Antivirus
Trojan.Win32.Autoit
4.0.3.1541

Bitdefender
Trojan.Agent.AQNV
1.0.20.455

Bkav FE
W32.FakeFolderKA
1.3.0.4959

Clam AntiVirus
Trojan.Agent-142577
0.98/213

Comodo Security
Worm.Win32.Agent.NEC1
18240

Dr.Web
Trojan.MulDrop4.55815
9.0.1.091

Emsisoft Anti-Malware
Trojan.Agent.AQNV
8.15.04.01.03

ESET NOD32
Win32/Agent.NEC
9.9775

Fortinet FortiGate
W32/Rotinom.SME!tr
4/1/2015

F-Prot
W32/Trojan2.MGVM
v6.4.7.1.166

F-Secure
Trojan.Agent.AQNV
11.2015-01-04_4

G Data
Trojan.Agent.AQNV
15.4.24

herdProtect (fuzzy)
2015.7.6.11

IKARUS anti.virus
Trojan.Win32.Agent2
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.177.12013

Kaspersky
Trojan-Dropper.Win32.Autoit
14.0.0.2257

Malwarebytes
Worm.Viking
v2015.04.01.03

McAfee
W32/Rotinom
5600.6808

Microsoft Security Essentials
Worm:Win32/Folstart.A
1.10502

MicroWorld eScan
Trojan.Agent.AQNV
16.0.0.273

NANO AntiVirus
Trojan.Win32.Agent2.bvovk
0.28.0.59608

Norman
Malware
11.20150401

nProtect
Worm/W32.Agent.243976
14.05.07.01

Panda Antivirus
W32/FakeFolder.Q.worm
15.04.01.03

Qihoo 360 Security
Worm.Win32.FakeFolder.BF
1.0.0.1015

Quick Heal
Worm.Folstart.A2
4.15.14.00

Rising Antivirus
PE:Malware.FakeFolder@CV!1.6AA9
23.00.65.15330

Sophos
Mal/Autorun-T
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Virut
9962

Total Defense
Win32/Folstart.A
37.0.10925

Trend Micro House Call
WORM_AUTORUN.SMI
7.2.91

Trend Micro
WORM_AUTORUN.SMI
10.465.01

Vba32 AntiVirus
Trojan.Autorun.0472
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Rotinom.b
29014

ViRobot
Trojan.Win32.Agent.178440
2011.4.7.4223

Zillya! Antivirus
Trojan.Agent2.Win32.9090
2.0.0.1781

File size:
174.5 KB (178,688 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\s-1-5-31-1286970278978-5713669491-166975984-320\rotinom\???? ???.exe

File PE Metadata
Compilation timestamp:
6/3/2009 4:09:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:MrKR9ieUOc+/RAhDcaPLXbbsAyQIrZBQlgSJ0TWS:6KR8Y6hDaAyQIrZBbSJK

Entry address:
0x4189

Entry point:
E8, 58, 35, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, F8, 0F, 41, 00, 89, 0D, F4, 0F, 41, 00, 89, 15, F0, 0F, 41, 00, 89, 1D, EC, 0F, 41, 00, 89, 35, E8, 0F, 41, 00, 89, 3D, E4, 0F, 41, 00, 66, 8C, 15, 10, 10, 41, 00, 66, 8C, 0D, 04, 10, 41, 00, 66, 8C, 1D, E0, 0F, 41, 00, 66, 8C, 05, DC, 0F, 41, 00, 66, 8C, 25, D8, 0F, 41, 00, 66, 8C, 2D, D4, 0F, 41, 00, 9C, 8F, 05, 08, 10, 41, 00, 8B, 45, 00, A3, FC, 0F, 41, 00, 8B, 45, 04, A3, 00, 10, 41, 00, 8D, 45, 08, A3, 0C, 10, 41...
 
[+]

Entropy:
3.7607

Code size:
46.5 KB (47,616 bytes)

Remove البو رضا.exe - Powered by Reason Core Security