{87ab06a1-1a86-4f8a-b022-666cd0d4f31b}.exe

The application {87ab06a1-1a86-4f8a-b022-666cd0d4f31b}.exe has been detected as a potentially unwanted program by 6 anti-malware scanners.
Remove {87ab06a1-1a86-4f8a-b022-666cd0d4f31b}.exe - Powered by Reason Core Security
MD5:
2f6390e6f405661e87ea8b4af6815006

SHA-1:
f4c3d7aab51b510dcfb04500e73dab6c1d12a142

SHA-256:
7c1f0bcb0d278c4abbf9c9fde6aee60d438302c3e5a8cf21ca79cb0a0eafbdc4

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
12/10/2016 8:00:26 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
Win32/Wajam.B potentially unwanted application
7.0.302.0

Kingsoft AntiVirus
VIRUS_UNKNOWN
331020.49267

Malwarebytes
PUP.Optional.Wajam.A
v2014.06.10.11

Vba32 AntiVirus
TrojanDownloader.Genome
3.12.26.0

VIPRE Antivirus
Wajam
30154

Remove {87ab06a1-1a86-4f8a-b022-666cd0d4f31b}.exe - Powered by Reason Core Security
File size:
41.6 KB (42,580 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\roaming\iolo\safetynet\manual\{b0b40951-9dc1-4b3f-99f7-361045ab9ad1}\{87ab06a1-1a86-4f8a-b022-666cd0d4f31b}.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
768:DqgIWKbgMumF/3R3ah/Q8AKkzg3JpfjUKxd1EZK7XnBPoQ6floQcZ/f4yO:Doze4p3ah3AK2qJpJsKnBUS/AyO

Entry point:
50, 4B, 03, 04, 14, 00, 00, 00, 08, 00, A8, 54, AE, 44, 8C, D0, 26, 19, 9E, A5, 00, 00, C0, F0, 00, 00, 2A, 00, 00, 00, 7B, 38, 37, 41, 42, 30, 36, 41, 31, 2D, 31, 41, 38, 36, 2D, 34, 46, 38, 41, 2D, 42, 30, 32, 32, 2D, 36, 36, 36, 43, 44, 30, 44, 34, 46, 33, 31, 42, 7D, 2E, 65, 78, 65, EC, BD, 7B, 78, 54, D5, B9, 3F, BE, E7, 16, 86, 90, 30, 83, 24, 1A, E4, E2, 00, 41, D1, 00, A2, 21, 4A, 48, D0, 09, 64, 22, 28, C1, 81, 21, 33, A0, 09, 18, 93, 09, 3B, 43, 48, 62, 66, 6F, 2E, 2D, 91, 89, 93, D8, 0C, 9B, B1...
 
[+]

Entropy:
7.9941  (probably packed)

Remove {87ab06a1-1a86-4f8a-b022-666cd0d4f31b}.exe - Powered by Reason Core Security