90896.exe

The executable 90896.exe has been detected as malware by 34 anti-virus scanners.
MD5:
bed780ed1f0091815c571f4b15d37cd8

SHA-1:
97717812021966f22211a42ac7a6a4622608c232

SHA-256:
22a504441fb7ab3c19927e2de6427068811ff376a8b8945111a89a4f0e8b7a59

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
4/25/2024 10:42:45 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.922
6485650

Agnitum Outpost
Worm.Palevo.Gen
7.1.1

AhnLab V3 Security
Win32/Palevo14.worm.Gen
2015.01.31

Avira AntiVirus
TR/Crypt.ZPACK.Gen
7.11.206.0

avast!
Win32:Morphex [Cryp]
150101-1

AVG
Win32/Cryptor
2014.0.4257

Bitdefender
Gen:Variant.Kazy.922
1.0.20.150

Comodo Security
TrojWare.Win32.Kryptik.KAU
20900

Dr.Web
Trojan.Packed.21635
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Kazy.922
9.0.0.4799

ESET NOD32
Win32/Bflient.Z worm
7.0.302.0

Fortinet FortiGate
W32/Palevo.A!tr
1/30/2015

F-Prot
W32/SmallTrojan.V.gen
4.6.5.141

F-Secure
Gen:Variant.Kazy.922
5.13.68

G Data
Gen:Variant.Kazy.922
15.1.25

IKARUS anti.virus
Trojan.Win32.Rimecud
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.193.14814

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2563

Malwarebytes
Worm.Autorun
v2015.01.30.11

McAfee
Virus.W32/Rimecud.gen.ay
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.191.3639.0

MicroWorld eScan
Gen:Variant.Kazy.922
16.0.0.90

NANO AntiVirus
Trojan.Win32.SmallTrojan.vkjjm
0.30.0.65070

Norman
Gen:Variant.Kazy.922
02.01.2015 13:58:24

Panda Antivirus
Trj/Rimecud.a
15.01.30.11

Qihoo 360 Security
Win32/Trojan.6b9
1.0.0.1015

Quick Heal
Trojan.Rimecud.BB
1.15.14.00

Sophos
Virus 'Mal/Palevo-A'
5.09

Total Defense
Win32/Rimecud.P!generic
37.0.11411

Trend Micro House Call
WORM_PALEVO.SMGL
7.2.30

Trend Micro
WORM_PALEVO.SMGL
10.465.30

Vba32 AntiVirus
BScope.P2P-Worm.Palevo
3.12.26.3

VIPRE Antivirus
Threat.4736480
36666

Zillya! Antivirus
Worm.Palevo.Win32.95977
2.0.0.2049

File size:
167 KB (171,008 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\90896.exe

File PE Metadata
Compilation timestamp:
2/1/2010 9:46:48 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:IOefHrxz7Vh2GRNMZu8Qe6Jbc2uXU2X6BL:7efHdHHv/leObNuXc

Entry address:
0x2743

Entry point:
8B, FF, 55, 8B, EC, 81, EC, 6C, 02, 00, 00, 53, 56, 57, 6A, 00, E8, BF, 13, 00, 00, 66, 89, 3D, 00, D3, 40, 00, 8B, 55, FC, E8, 52, 14, 00, 00, C6, 45, F8, FF, 6A, 80, 6A, 66, 57, E8, 72, 13, 00, 00, 0A, 75, FC, 8A, 65, F8, 89, 55, FC, 66, 8B, 45, F4, 68, 1B, 53, 40, 00, E8, 91, 13, 00, 00, 88, 5D, F0, 68, 4A, 01, 00, 00, 6A, 82, 51, E8, 57, 13, 00, 00, 85, C0, 0F, 84, 29, F0, 01, 00, 8D, 45, D4, 50, E8, BC, 12, 00, 00, 29, 35, B7, D5, 40, 00, 23, DE, 3C, 7D, 75, 0D, F7, D9, 83, F1, FF, 88, 5D, D0, E8, AB...
 
[+]

Entropy:
6.1374

Code size:
11 KB (11,264 bytes)

Remove 90896.exe - Powered by Reason Core Security