{3b7599cf-63ea-42d4-b20c-66f059ff8e28}

Tools

datap - www.datap.com

The file {3b7599cf-63ea-42d4-b20c-66f059ff8e28}, “Developer Too ls Library” has been detected as malware by 29 anti-virus scanners. This trojon will perform a number of actions that will compromise a PC including changing protected system registry values, hiding in protected operating system locations and downloading and installing additional malware.
Publisher:
datap - www.datap.com

Product:
Tools

Description:
Developer Too ls Library

Version:
1.1

MD5:
4873f863f961c4331c4f029437b38c9f

SHA-1:
ca521eaae7a7f6c7fe76075ddaded05a0f267241

SHA-256:
12b512295f47c2001ee63273e1f74343ae8208a9990f3700dd0f779e89a87786

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
4/27/2024 1:40:21 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Worm.Generic.515971
856

AhnLab V3 Security
Trojan/Win32.Zbot
2014.09.17

Avira AntiVirus
BDS/Bladabindi.ajouc
7.11.172.232

avast!
Win32:Malware-gen
2014.9-141002

AVG
MSIL4
2015.0.3334

Baidu Antivirus
Trojan.MSIL.Inject
4.0.3.14102

Bitdefender
Worm.Generic.515971
1.0.20.1375

Comodo Security
UnclassifiedMalware
19540

Dr.Web
Tool.PassView.849
9.0.1.0275

Emsisoft Anti-Malware
Trojan-Dropper.MSIL.Agent
8.14.10.02.04

ESET NOD32
MSIL/Autorun.Spy.Agent.AU
8.10429

Fortinet FortiGate
W32/Inject.AGMX!tr
10/2/2014

F-Secure
Worm.Generic.515971
11.2014-02-10_5

G Data
Worm.Generic.515971
14.10.24

IKARUS anti.virus
Trojan.MSIL.Inject
t3scan.1.7.8.0

K7 AntiVirus
Riskware
13.183.13393

Kaspersky
Trojan.MSIL.Inject
14.0.0.3164

Malwarebytes
Trojan.Dropper
v2014.10.02.04

McAfee
RDN/Generic PWS.y!bbb
5600.6990

Microsoft Security Essentials
Trojan:Win32/Malagent!gmb
1.11005

MicroWorld eScan
Worm.Generic.515971
15.0.0.825

nProtect
Worm.Generic.515971
14.09.16.01

Panda Antivirus
Trj/CI.A
14.10.02.04

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Total Defense
Win32/SillyAutorun.OdJHAf
37.0.11184

Trend Micro House Call
TROJ_GEN.R0C2C0DIF14
7.2.275

Trend Micro
TROJ_GEN.R0C2C0DIF14
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
33190

File size:
780.5 KB (799,232 bytes)

Product version:
1.1

Copyright:
Copyright (C) 2010-2013

Original file name:
WindowsFormsApplication2.exe

File PE Metadata
Compilation timestamp:
9/12/2014 4:58:07 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:/YS50KKJcP78I0LVF070OSr6R0KAfBvsl46RzT/kQYge07eZSShAHq:/nz4cPYI0LVML0pBslvh/kQ607e6H

Entry address:
0x9791E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
598.5 KB (612,864 bytes)

Remove {3b7599cf-63ea-42d4-b20c-66f059ff8e28} - Powered by Reason Core Security