3742_offer.exe

The application 3742_offer.exe has been detected as a potentially unwanted program by 19 anti-malware scanners.
MD5:
000b9da061218a2710ae0555d4c178f7

SHA-1:
22564586e9a02c9ef30dd9e6a777a9c31874f068

SHA-256:
d48ce487bf89bd5992413ff880ede7a2a70412fac7b29631759c3fe953c6c14b

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 1:32:04 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.PHI
6542620

Avira AntiVirus
Adware/Gertokr.879104.1
7.11.206.68

avast!
Win32:Malware-gen
150101-1

AVG
Adware Generic6.LJE
2014.0.4257

Baidu Antivirus
Adware.Win32.Gertokr
4.0.3.1532

Bitdefender
Adware.Agent.PHI
1.0.20.285

Comodo Security
ApplicUnwnt
20920

Dr.Web
Adware.Gertokr.1
9.0.1.05190

Emsisoft Anti-Malware
Adware.Agent.PHI
9.0.0.4799

ESET NOD32
Win32/Adware.Gertokr.B application
7.0.302.0

F-Secure
Adware.Agent.PHI
5.13.68

G Data
Adware.Agent.PHI
15.2.25

IKARUS anti.virus
PUA.Gertokr
t3scan.1.8.6.0

MicroWorld eScan
Adware.Agent.PHI
16.0.0.171

NANO AntiVirus
Trojan.Win32.RYSJ1244.dhgboy
0.30.0.296

nProtect
Adware.Agent.PHI
15.02.26.01

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.2.0

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

Zillya! Antivirus
Adware.Agent.Win32.26757
2.0.0.2050

File size:
857.7 KB (878,248 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\3742_offer.exe

File PE Metadata
Compilation timestamp:
10/14/2014 10:38:46 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:dh77yi4TPdhp+aKKGshjIlhPjLZOH8EAzcLLGIlP5EbUdwceDh:dd74FhsaKKBjIlZLZOHLAzcHjt5gHDh

Entry address:
0x9024A

Entry point:
E8, B1, FB, 00, 00, E9, 7F, FE, FF, FF, E8, 94, 6A, 00, 00, 85, C0, 75, 06, B8, 14, 36, 4C, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, 60, 6A, 00, 00, 85, C0, 75, 06, B8, 10, 36, 4C, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, A8, 34, 4C, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
6.6343

Code size:
687.5 KB (704,000 bytes)

Remove 3742_offer.exe - Powered by Reason Core Security