4811_offer.exe

The application 4811_offer.exe has been detected as a potentially unwanted program by 19 anti-malware scanners.
MD5:
a0b7b46ea0e0f36cf548ba0586f951f4

SHA-1:
b81444b45aeafd3ce834ae05a068ef8746868761

SHA-256:
50f330a2a7563066f4aff44b28cd9de0fb73917c376ea7197e1ebb288e40a686

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 11:27:11 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.PHI
6542620

Avira AntiVirus
Adware/Gertokr.879104.1
7.11.206.68

avast!
Win32:Malware-gen
150101-1

AVG
Adware Generic6.LJE
2014.0.4257

Baidu Antivirus
Adware.Win32.Gertokr
4.0.3.1532

Bitdefender
Adware.Agent.PHI
1.0.20.285

Comodo Security
ApplicUnwnt
20920

Dr.Web
Adware.Gertokr.1
9.0.1.05190

Emsisoft Anti-Malware
Adware.Agent.PHI
9.0.0.4799

ESET NOD32
Win32/Adware.Gertokr.B application
7.0.302.0

F-Secure
Adware.Agent.PHI
5.13.68

G Data
Adware.Agent.PHI
15.2.25

IKARUS anti.virus
PUA.Gertokr
t3scan.1.8.6.0

MicroWorld eScan
Adware.Agent.PHI
16.0.0.171

NANO AntiVirus
Trojan.Win32.RYSJ1244.dhgboy
0.30.0.296

nProtect
Adware.Agent.PHI
15.02.26.01

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.2.0

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

Zillya! Antivirus
Adware.Agent.Win32.26757
2.0.0.2083

File size:
855.5 KB (876,072 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\4811_offer.exe

File PE Metadata
Compilation timestamp:
10/14/2014 10:38:46 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:dh77yi4TPdhp+aKKGshjIlhPjLZOH8EAzcLLGIlP5EbUdwceDQ:dd74FhsaKKBjIlZLZOHLAzcHjt5gHDQ

Entry address:
0x9024A

Entry point:
E8, B1, FB, 00, 00, E9, 7F, FE, FF, FF, E8, 94, 6A, 00, 00, 85, C0, 75, 06, B8, 14, 36, 4C, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, 60, 6A, 00, 00, 85, C0, 75, 06, B8, 10, 36, 4C, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, A8, 34, 4C, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
6.6299

Code size:
687.5 KB (704,000 bytes)

Remove 4811_offer.exe - Powered by Reason Core Security