netui2.dll

Операционная система Microsoft Windows

Корпорация Майкрософт

The file netui2.dll, “Общие классы GUI для NT LM” has been detected as malware by 21 anti-virus scanners.
Publisher:
Корпорация Майкрософт

Product:
Операционная система Microsoft® Windows®

Description:
Общие классы GUI для NT LM

Version:
5.1.2600.0 (xpclient.010817-1148)

MD5:
a0ba4c701b25ca93de1193fa32089212

SHA-1:
4f09e403ab7e426aa590d786ac1c6f13d851a0f7

SHA-256:
1dfc8ecaeab24d1e98825e80299d31849873e7984e30eeba5bffd81bf164fea5

Scanner detections:
21 / 68

Status:
Malware

Analysis date:
4/25/2024 10:36:22 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.625832
577

Agnitum Outpost
Backdoor.Papras
7.1.1

Avira AntiVirus
TR/Vawtrak.A.138
8.3.1.6

Arcabit
Trojan.Kazy.D98CA8
1.0.0.425

AVG
Crypt4
2016.0.3055

Baidu Antivirus
Backdoor.Win32.Papras
4.0.3.1577

Bitdefender
Gen:Variant.Kazy.625832
1.0.20.940

Emsisoft Anti-Malware
Gen:Variant.Kazy.625832
8.15.07.07.03

ESET NOD32
Win32/Kryptik.DKLQ (variant)
9.11765

Fortinet FortiGate
W32/Papras.DKLQ!tr.bdr
7/7/2015

F-Secure
Gen:Variant.Kazy.625832
11.2015-07-07_3

G Data
Gen:Variant.Kazy.625832
15.7.25

K7 AntiVirus
Trojan
13.204.16204

Kaspersky
Backdoor.Win32.Papras
14.0.0.1772

Malwarebytes
Trojan.FakeMS
v2015.07.07.03

MicroWorld eScan
Gen:Variant.Kazy.625832
16.0.0.564

Panda Antivirus
Trj/Genetic.gen
15.07.07.03

Qihoo 360 Security
Win32/Trojan.891
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R00JH09F515
7.2.188

VIPRE Antivirus
Trojan.Win32.Generic
41008

File size:
560 KB (573,440 bytes)

Product version:
5.1.2600.0

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
netui2.dll

Language:
Russian (Russia)

Common path:
C:\users\{user}\appdata\local\temp\a43b.tmp

File PE Metadata
Compilation timestamp:
6/2/2015 11:45:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:wTxbvdwjDmH1RV/bP/fBUP1B3ThzYJI2Fp+qWJg9Ji4YweSGe899uiIp:ClndPWtBhzWIA1WJzweFesIp

Entry address:
0x70D0

Entry point:
55, 89, E5, 83, EC, 04, E9, D5, FE, FF, FF, C6, 45, F3, F5, 8B, 45, FC, C3, 47, A8, 29, 2A, 56, 53, F2, 4B, 7B, 52, 56, 6F, 6E, C2, 9B, 11, D2, B6, A3, 18, 17, A9, 58, E0, 99, C8, 38, 0B, 33, 9D, 8F, E4, C8, 5E, 44, DC, ED, 61, EB, D8, 55, 06, 57, 15, 72, 8A, FA, 48, EC, 0D, 77, D5, FE, 79, 57, 1B, 00, CC, 92, 41, 06, 3F, 41, E1, 26, BC, E2, 99, 21, F3, AD, 07, 2D, 79, 86, 00, 00, 00, 00, 00, 00, 00, 10, C1, 38, 3C, CF, B5, 5C, 6F, 73, 3C, 4F, F7, F8, F6, BC, AE, 44, 36, FD, FA, E8, B7, DC, 6F, 73, 7C, 0C...
 
[+]

Entropy:
6.2886

Code size:
252 KB (258,048 bytes)

Remove netui2.dll - Powered by Reason Core Security