24532_offer.exe

The application 24532_offer.exe has been detected as a potentially unwanted program by 19 anti-malware scanners.
MD5:
70be466d2f9eb8e18d94546f88930655

SHA-1:
42dca44a0e463c4627822c226e5d0cf7ab2f9d16

SHA-256:
7aba7c4cc09e3e265d751cafb55c57ee4163cd81c23e0818513cc94b7d154fa9

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 10:39:21 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.PHI
6542620

Avira AntiVirus
Adware/Gertokr.879104.1
7.11.206.68

avast!
Win32:Malware-gen
150101-1

AVG
Generic6
2016.0.3186

Baidu Antivirus
Adware.Win32.Gertokr
4.0.3.1532

Bitdefender
Adware.Agent.PHI
1.0.20.285

Comodo Security
ApplicUnwnt
20920

Dr.Web
Adware.Gertokr.1
9.0.1.05190

Emsisoft Anti-Malware
Adware.Agent.PHI
9.0.0.4799

ESET NOD32
Win32/Adware.Gertokr (variant)
9.11239

F-Secure
Adware.Agent.PHI
5.13.68

G Data
Adware.Agent.PHI
15.2.25

IKARUS anti.virus
PUA.Gertokr
t3scan.1.8.6.0

MicroWorld eScan
Adware.Agent.PHI
16.0.0.171

NANO AntiVirus
Trojan.Win32.RYSJ1244.dhgboy
0.30.0.296

nProtect
Adware.Agent.PHI
15.02.26.01

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.2.0

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

Zillya! Antivirus
Adware.Agent.Win32.26757
2.0.0.2083

File size:
854.5 KB (875,028 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\24532_offer.exe

File PE Metadata
Compilation timestamp:
10/14/2014 10:38:46 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:dh77yi4TPdhp+aKKGshjIlhPjLZOH8EAzcLLGIlP5EbUdwceDj:dd74FhsaKKBjIlZLZOHLAzcHjt5gHDj

Entry address:
0x9024A

Entry point:
E8, B1, FB, 00, 00, E9, 7F, FE, FF, FF, E8, 94, 6A, 00, 00, 85, C0, 75, 06, B8, 14, 36, 4C, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, 60, 6A, 00, 00, 85, C0, 75, 06, B8, 10, 36, 4C, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, A8, 34, 4C, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
6.6277

Code size:
687.5 KB (704,000 bytes)

Remove 24532_offer.exe - Powered by Reason Core Security