0f64e4.dll

MS

The library 0f64e4.dll has been detected as malware by 11 anti-virus scanners.
Publisher:
MS

Version:
3, 2, 4, 0

MD5:
3cfbb73f9a4c1810718b797c0e4e611f

SHA-1:
6c51e4b398fc2e98252e7364e7f5b9f6e80cef4b

SHA-256:
4af3e3143da74f18e7e950ffae3f85cb8d6b26ffb42b95aa560040948385bbe8

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
4/19/2024 5:43:49 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.VMProtect
7.1.1

Avira AntiVirus
TR/Black.Gen2
7.11.153.220

AVG
Win32/Blacked
2015.0.3281

Baidu Antivirus
Trojan.Win32.VMProtect
4.0.3.141124

Bkav FE
W32.HfsAutoA
1.3.0.4959

ESET NOD32
Win32/Packed.VMProtect.ABD (variant)
8.9909

Fortinet FortiGate
W32/VMProtBad.A!tr
11/24/2014

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2900

McAfee
Artemis!3CFBB73F9A4C
5600.6937

Sophos
Mal/VMProtBad-A
4.98

Trend Micro House Call
TROJ_GEN.R021H08F614
7.2.328

File size:
356 KB (364,544 bytes)

Product version:
3, 2, 4, 0

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\b68e25e1\0f64e4.dll

File PE Metadata
Compilation timestamp:
5/15/2014 4:32:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:v+j3S2guF9opG6qz9E7beeEazaqALQGwm2Vy7wugL0bzlMxsKwwx8f7Q3u++BNEv:mj3R5637XLzohwm3wfelQsPKYYeO

Entry address:
0x7B59F

Entry point:
52, 60, 68, ED, 06, 63, 66, FF, 74, 24, 04, C7, 44, 24, 28, 16, AA, 06, EA, E9, 1B, 16, 03, 00, 61, 99, FF, 15, C4, 91, 52, 15, 3B, C7, 13, F2, FF, FA, BE, 66, 7A, AD, 2A, F5, BA, 68, 5B, A3, C5, 17, D7, 29, 9A, 84, BF, 4D, 8D, 76, 47, 05, E7, D0, 72, C9, 30, C8, 40, C2, 1B, 0A, CE, F4, CC, 50, EC, D2, BB, DE, 1A, E1, E1, 23, 44, BB, 6B, 85, 54, 17, F0, D9, 2F, 97, 91, 90, 56, 18, 6E, 60, 04, 57, CB, 9E, EC, 8C, 9C, 62, F7, B0, 29, A3, 83, 3A, 7B, 71, 2F, D5, 95, 8F, 6C, 91, 6B, 41, 2F, 88, DF, CF, 21, 98...
 
[+]

Entropy:
7.7072  (probably packed)

Code size:
104 KB (106,496 bytes)

Remove 0f64e4.dll - Powered by Reason Core Security