netui2.dll

Операционная система Microsoft Windows

Корпорация Майкрософт

The file netui2.dll, “Общие классы GUI для NT LM” has been detected as malware by 28 anti-virus scanners.
Publisher:
Корпорация Майкрософт

Product:
Операционная система Microsoft® Windows®

Description:
Общие классы GUI для NT LM

Version:
5.1.2600.0 (xpclient.010817-1148)

MD5:
a1a48511d4355d4094153733bc6f98bc

SHA-1:
76fd65dfa1d99f5e2d8b2b5a36b0e15e8f395a3a

SHA-256:
1daa71f15f09eb481d7ca7e26791e0ed019339aa4f098aa86f8748f2279927ae

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/24/2024 3:08:57 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2459869
577

Agnitum Outpost
Backdoor.Papras
7.1.1

Avira AntiVirus
TR/Obfuscate.557056
8.3.1.6

Arcabit
Trojan.Generic.D2588DD
1.0.0.425

avast!
Win32:Malware-gen
2014.9-150707

AVG
PSW.Generic12
2016.0.3055

Baidu Antivirus
Backdoor.Win32.Papras
4.0.3.1577

Bitdefender
Trojan.GenericKD.2459869
1.0.20.940

Emsisoft Anti-Malware
Trojan.GenericKD.2459869
8.15.07.07.03

ESET NOD32
Win32/PSW.Papras.DT
9.11761

Fortinet FortiGate
W32/Papras.DT!tr.pws
7/7/2015

F-Secure
Trojan.GenericKD.2459869
11.2015-07-07_3

G Data
Trojan.GenericKD.2459869
15.7.25

IKARUS anti.virus
Trojan.Win32.PSW
t3scan.1.9.5.0

K7 AntiVirus
Password-Stealer
13.204.16191

Kaspersky
Backdoor.Win32.Papras
14.0.0.1772

Malwarebytes
Trojan.FakeMS
v2015.07.07.03

McAfee
Artemis!A1A48511D435
5600.6711

Microsoft Security Essentials
VirTool:Win32/Obfuscator.ALB
1.1.11701.0

MicroWorld eScan
Trojan.GenericKD.2459869
16.0.0.564

NANO AntiVirus
Trojan.Win32.Papras.dsojmj
0.30.24.2086

nProtect
Trojan.GenericKD.2459869
15.06.09.01

Panda Antivirus
Trj/Genetic.gen
15.07.07.03

Qihoo 360 Security
HEUR/QVM40.1.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R021C0EF915
7.2.188

Trend Micro
TROJ_GEN.R021C0EF915
10.465.07

VIPRE Antivirus
Trojan.Win32.Generic
40986

File size:
544 KB (557,056 bytes)

Product version:
5.1.2600.0

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
netui2.dll

Language:
Russian (Russia)

Common path:
C:\users\{user}\appdata\local\temp\672a.tmp

File PE Metadata
Compilation timestamp:
6/2/2015 8:28:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:Dy+rYxRgW+ITh0GGOJohUfzVzgpK9TGGwF/VobijvNx4MJoYoj7IFz:+4YbgW+IKqohUfzaKJ4Rv3J7oQ

Entry address:
0x6F00

Entry point:
55, 89, E5, 83, EC, 04, E9, B5, FE, FF, FF, 8B, 45, F0, C6, 45, FF, DC, C3, 45, 85, 4C, 37, 95, 0F, 0B, 3F, 7D, 27, 28, 4E, 6C, 9F, BE, 1E, 11, 72, BC, 0C, 19, 7E, 2A, BF, 97, A5, 5B, 18, 72, 59, A8, D8, CA, 33, 16, BB, EB, 3E, 0E, E5, 94, C2, 70, 09, 74, 5F, CC, 27, EA, EA, 9A, E2, 3D, 35, 70, 0F, 02, A1, 64, 20, 04, 1C, 64, EE, 65, 78, FB, 8D, 23, C8, 7F, E6, 2B, 56, A9, 47, AD, 41, 45, 0C, A9, 47, 2A, CC, CC, CC, CC, CC, 00, 37, 34, 43, F4, 2F, AF, F4, B9, 88, F3, DF, D2, AC, AF, D0, 6C, AA, 35, 44, 81...
 
[+]

Entropy:
6.2662

Code size:
236 KB (241,664 bytes)

Remove netui2.dll - Powered by Reason Core Security