644.tmp

The file 644.tmp has been detected as a potentially unwanted program by 16 anti-malware scanners.
MD5:
b13615fefabe74911579e23845d21487

SHA-1:
3dc4acd1aab5350b8261b5b57e9f9198833292e5

SHA-256:
3a5e1405206304a31a2736c251f778978202d455e2e5812313442c563c2d3b75

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 8:54:58 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1898437
827

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

Agnitum Outpost
PUA.NaviPromo
7.1.1

Avira AntiVirus
Adware/NaviPromo.E.Z
7.11.182.116

AVG
Generic5
2015.0.3305

Baidu Antivirus
Adware.Win32.NaviPromo
4.0.3.141031

Bitdefender
Trojan.GenericKD.1898437
1.0.20.1520

Emsisoft Anti-Malware
Trojan.GenericKD.1898437
8.14.10.31.04

ESET NOD32
Win32/AdWare.NaviPromo.AZ (variant)
8.10646

Fortinet FortiGate
Riskware/NaviPromo
10/31/2014

F-Secure
Trojan.GenericKD.1898437
11.2014-31-10_6

G Data
Trojan.GenericKD.1898437
14.10.24

IKARUS anti.virus
PUA.NaviPromo
t3scan.1.8.3.0

MicroWorld eScan
Trojan.GenericKD.1898437
15.0.0.912

nProtect
Trojan.GenericKD.1898437
14.10.30.01

Trend Micro House Call
TROJ_GEN.R02SH09JR14
7.2.304

File size:
1.7 MB (1,819,648 bytes)

Common path:
C:\users\{user}\appdata\local\temp\644.tmp

File PE Metadata
Compilation timestamp:
10/1/2014 3:25:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:D3h3jjd7/Pa6X4uUAjwCFPjCyGYGP0GwcG+tJzF:7h3jp7/Pa6X3UAjXpjCyG1sGwcG+t

Entry address:
0x1722EA

Entry point:
E8, 20, A0, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, EC, 10, FF, 75, 0C, 8D, 4D, F0, E8, 54, E2, FF, FF, 8B, 4D, F0, 83, 79, 74, 01, 7E, 18, 8D, 45, F0, 50, 68, 07, 01, 00, 00, FF, 75, 08, E8, 76, A1, 00, 00, 83, C4, 0C, 8B, C8, EB, 13, 8B, 89, 90, 00, 00, 00, 8B, 45, 08, 0F, B7, 0C, 41, 81, E1, 07, 01, 00, 00, 80, 7D, FC, 00, 74, 07, 8B, 45, F8, 83, 60, 70, FD, 8B, C1, 8B, E5, 5D, C3, 55, 8B, EC, 83, EC, 10, FF, 75, 0C, 8D, 4D, F0, E8, FC, E1, FF, FF, 8B, 4D, F0, 83, 79, 74, 01, 7E, 15, 8D, 45, F0, 50...
 
[+]

Code size:
1.6 MB (1,637,888 bytes)

Remove 644.tmp - Powered by Reason Core Security