4914

The Witcher 3

Acunetix Ltd.

The file 4914 has been detected as malware by 25 anti-virus scanners.
Publisher:
CD Projekt Red  (signed by Acunetix Ltd.)

Product:
The Witcher 3

Version:
3.0.0

MD5:
c51e2f3ef1a4e6561082bf2fc2fe769a

SHA-1:
9757eaafa29b8d07b8ecec019948d5b0499ebb3c

SHA-256:
99d03121bf063a2c1dd48b48b349d23576469e6a41821381f10cbbbbd5e19254

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
5/7/2024 8:55:41 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.MSIL.Agent.BAK
203

AegisLab AV Signature
Troj.Dropper.W32.Injector.lBZu
2.1.4+

AhnLab V3 Security
Trojan/Win32.Agent
2016.05.08

Avira AntiVirus
BDS/Androm.vkln
8.3.3.4

Arcabit
Trojan.MSIL.Agent.BAK
1.0.0.672

avast!
Win32:Malware-gen
2014.9-160715

AVG
MSIL10
2017.0.2681

Bitdefender
Trojan.MSIL.Agent.BAK
1.0.20.985

Dr.Web
Trojan.PWS.Multi.911
9.0.1.0197

ESET NOD32
MSIL/Injector.PAP (variant)
10.13455

Fortinet FortiGate
MSIL/Injector.PAP!tr
7/15/2016

F-Prot
W32/MSIL_Injector.CE.gen
v6.4.7.1.166

F-Secure
Trojan.MSIL.Agent.BAK
11.2016-15-07_6

G Data
Trojan.MSIL.Agent.BAK
16.7.25

Kaspersky
Backdoor.Win32.Androm
14.0.0.-99

McAfee
Artemis!C51E2F3EF1A4
5600.6337

Microsoft Security Essentials
Trojan:MSIL/Injector.Y
1.1.12706.0

MicroWorld eScan
Trojan.MSIL.Agent.BAK
17.0.0.591

NANO AntiVirus
Trojan.Win32.Multi.ebyuui
1.0.30.8213

Panda Antivirus
Trj/GdSda.A
16.07.15.08

Qihoo 360 Security
Win32/Backdoor.97f
1.0.0.1120

Quick Heal
TrojanPWS.ZBot
7.16.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R00JC0DE516
10.465.15

VIPRE Antivirus
Trojan.Win32.Generic
49222

File size:
520.7 KB (533,224 bytes)

Product version:
3.0.0

Copyright:
Copyright © 2012 CD Projekt Red

Original file name:
order11.exe

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\4914

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/26/2014 2:00:00 AM

Valid to:
6/26/2016 1:59:59 AM

Subject:
CN=Acunetix Ltd., OU=Acunetix Development Department, O=Acunetix Ltd., L=Ta' Xbiex, S=Malta, C=MT

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
500BD1BC380359C65E4FB982FD87B14F

File PE Metadata
Compilation timestamp:
5/3/2016 11:28:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:RZVdyiZrnnMAr9FoUPGp4N4oUrmd0AJMWCRT7O:RfdyuDMEGwomd0DfO

Entry address:
0x717AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 48, 00, 00, 80, 10, 00, 00, 00, 60, 00, 00, 80, 18, 00, 00, 00, 78, 00...
 
[+]

Entropy:
7.6283

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
446 KB (456,704 bytes)

Remove 4914 - Powered by Reason Core Security