00929021.exe

Symantec Shared Component

OpenVPN Technologies, Inc.

The executable 00929021.exe has been detected as malware by 40 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
CJSC "Computing Forces"  (signed by OpenVPN Technologies, Inc.)

Product:
Symantec Shared Component

Version:
7.6.7.9

MD5:
02a67d6127285449157d13c220b2a68a

SHA-1:
6f53b241ca7879f5504bbf4c6f6108e78fb4af62

SHA-256:
cf5b0cb5d6707ae8243637ad0373b2e1bde364cd186bba6cda82b58a1d29e4f5

Scanner detections:
40 / 68

Status:
Malware

Analysis date:
4/26/2024 9:13:10 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.KDV.660612
59

Agnitum Outpost
TrojanSpy.Zbot
7.1.1

AhnLab V3 Security
Spyware/Win32.Zbot
2015.07.28

Avira AntiVirus
TR/Spy.ZBot.eawf
8.3.1.6

Arcabit
Trojan.Generic.KDV.DA1484
1.0.0.425

avast!
Win32:Spyware-gen [Spy]
2014.9-161207

AVG
PSW.Generic9
2017.0.2537

Baidu Antivirus
Trojan.Win32.Zbot
4.0.3.16127

Bitdefender
Trojan.Generic.KDV.660612
1.0.20.1710

Bkav FE
HW32.Packed
1.3.0.6979

Clam AntiVirus
WIN.Spy.Zbot-975
0.98/21511

Comodo Security
UnclassifiedMalware
22874

Dr.Web
Trojan.PWS.Panda.2000
9.0.1.0342

Emsisoft Anti-Malware
Trojan.Generic.KDV.660612
8.16.12.07.12

ESET NOD32
Win32/Spy.Zbot.AAO
10.12000

Fortinet FortiGate
W32/Zbot.AAO!tr
12/7/2016

F-Prot
W32/Pws.CFKF
v6.4.7.1.166

F-Secure
Trojan.Generic.KDV.660612
11.2016-07-12_4

G Data
Trojan.Generic.KDV.660612
16.12.25

IKARUS anti.virus
Trojan-Spy.Win32.Zbot
t3scan.1.9.5.0

K7 AntiVirus
Spyware
13.207.16692

Kaspersky
Trojan-Spy.Win32.Zbot
14.0.0.-820

Malwarebytes
Spyware.Zbot.CF
v2016.12.07.12

McAfee
PWS-Zbot.gen.agz
5600.6193

Microsoft Security Essentials
PWS:Win32/Zbot
1.1.11903.0

MicroWorld eScan
Trojan.Generic.KDV.660612
17.0.0.1026

NANO AntiVirus
Trojan.Win32.Zbot.tqfva
0.30.24.2668

nProtect
Trojan.Generic.KDV.660612
15.07.27.01

Panda Antivirus
Generic Malware
16.12.07.12

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Quick Heal
TrojanPWS.Zbot.Gen
12.16.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.12E48BA0!316967840
23.00.65.161205

Sophos
Troj/Zbot-CDG
4.98

Total Defense
Win32/Tnega.ANLY
37.1.62.1

Trend Micro House Call
TSPY_ZBOT.KIB
7.2.342

Trend Micro
TSPY_ZBOT.KIB
10.465.07

Vba32 AntiVirus
TrojanSpy.Zbot
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
42376

ViRobot
Trojan.Win32.A.Zbot.184928[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Zbot.Win32.63610
2.0.0.2317

File size:
180.6 KB (184,928 bytes)

Product version:
3.1.0.8

Copyright:
Copyright © 2010 Symantec Corporation. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\00929021.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/14/2010 3:00:00 AM

Valid to:
4/15/2011 2:59:59 AM

Subject:
CN="OpenVPN Technologies, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="OpenVPN Technologies, Inc.", L=Pleasanton, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
172A567C6032E50F8631150E61EDFE5E

File PE Metadata
Compilation timestamp:
11/12/2000 5:25:04 PM

OS version:
2.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x1000

Entry point:
55, 8B, EC, 83, EC, 44, 53, 89, 5D, F4, 56, 8B, D2, 89, 15, DF, 81, 40, 00, 57, 8B, DB, 8B, F6, E8, 63, 1F, 00, 00, E8, 8E, 26, 00, 00, E8, 2D, 24, 00, 00, E8, 04, 24, 00, 00, 81, 35, 14, 84, 40, 00, 4A, C4, 00, 00, 68, 4D, 84, 40, 00, FF, 15, C0, 71, 44, 00, A3, EA, 86, 40, 00, 68, 15, 66, 40, 00, FF, 15, 1C, 71, 44, 00, A3, 04, 8A, 40, 00, 83, 35, 76, 81, 40, 00, 31, 29, 45, F8, 81, 35, F7, 86, 40, 00, 93, E6, 00, 00, 68, 94, 66, 40, 00, FF, 15, 1C, 71, 44, 00, A3, A6, 86, 40, 00, C7, 05, 5F, 87, 40, 00...
 
[+]

Entropy:
7.6506

Developed / compiled with:
Microsoft Visual C++

Code size:
19.5 KB (19,968 bytes)

Remove 00929021.exe - Powered by Reason Core Security