AdvanceBox.exe

AdvanceBox

The executable AdvanceBox.exe has been detected as malware by 39 anti-virus scanners.
Product:
AdvanceBox

Version:
11.0.8.0

MD5:
de12c9d955cbb10343fb9002643ba630

SHA-1:
427a33882136c8a43b4f906b8331a553b9715ec5

SHA-256:
681eef91fb51d1dc4187651054c15fb12363f74945fc2cbaead4c74c562ec3c0

Scanner detections:
39 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/20/2024 1:15:34 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Virtob.Gen.12
5734772

Agnitum Outpost
Win32.Virut.AB.Gen
7.1.1

AhnLab V3 Security
Win32/Virut.F
2015.10.09

Avira AntiVirus
W32/Virut.Gen
7.11.30.172

Arcabit
Win32.Virtob.Gen.12
1.0.0.582

avast!
Win32:Vitro
151004-0

AVG
Win32/Virut
2015.0.4435

Baidu Antivirus
Virus.Win32.Virut.$NBP
4.0.3.15109

Bitdefender
Win32.Virtob.Gen.12
1.0.20.1410

Bkav FE
W32.Vetor.PE
1.3.0.7237

Comodo Security
Virus.Win32.Virut.CE
23382

Dr.Web
Win32.Virut.56
9.0.1.05190

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
10.0.0.5366

ESET NOD32
Win32/Virut.NBP virus
7.0.302.0

Fortinet FortiGate
W32/Virut.CE
10/9/2015

F-Prot
W32/Virut.E.gen
4.6.5.141

F-Secure
Win32.Virtob.Gen.12
5.14.151

G Data
Win32.Virtob.Gen.12
15.10.25

IKARUS anti.virus
Virus.Win32.Virut
t3scan.1.9.5.0

K7 AntiVirus
Virus
13.210.17479

Kaspersky
Virus.Win32.Virut
15.0.0.543

McAfee
Virus.W32/Virut.n.gen
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.207.2059.0

MicroWorld eScan
Win32.Virtob.Gen.12
16.0.0.846

NANO AntiVirus
Virus.Win32.Virut.hpeg
0.30.26.3947

Norman
Win32.Virtob.Gen.12
04.08.2015 10:30:46

nProtect
Virus/W32.Virut.Gen
15.10.08.01

Panda Antivirus
W32/Sality.AO
15.10.09.10

Quick Heal
W32.Virut.G
10.15.14.00

Rising Antivirus
PE:Virus.Virut!1.A08B[F1]
23.00.65.151007

Sophos
Virus 'W32/Scribble-B'
5.15

Total Defense
Win32/Virut.17408
37.1.62.1

Trend Micro House Call
PE_VIRUX.O
7.2.282

Trend Micro
PE_VIRUX.O
10.465.09

Vba32 AntiVirus
Virus.Virut.14
3.12.26.4

VIPRE Antivirus
Threat.4737366
43798

ViRobot
Win32.Virut.AM[h]
2014.3.20.0

Zillya! Antivirus
Virus.Virut.Win32.1938
2.0.0.2435

File size:
6.7 MB (7,005,696 bytes)

Product version:
11.80

Copyright:
AdvanceBox

Trademarks:
AdvanceBox Turbo Flasher

Original file name:
AdvanceBox.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
7/28/2009 12:25:07 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:jl+khGgIS/IACC4cIBkpJxXB1JQv8WfwVMD:jUkJdric2kpJFBEwVy

Entry address:
0x15C389F

Entry point:
83, 3C, 24, FE, 77, FE, 8D, 64, 24, CC, 60, 83, EC, DC, E8, D2, FF, FF, FF, 4B, 66, 4B, 75, FC, 4F, 46, 8B, D4, FF, 73, 3C, 59, 81, E9, FD, FF, FF, 7F, 0F, 83, E7, FF, FF, FF, 81, D9, E6, 13, 00, 00, 71, DF, F6, D2, 40, F9, FF, B4, 19, E4, 13, 00, 80, 83, C4, 04, 66, 81, 44, 24, FC, B0, BA, 75, C8, F7, D6, 96, 90, 68, 23, 26, 59, 02, E8, 41, 00, 00, 00, E9, 97, 00, 00, 00, 83, C4, 08, FF, 71, 02, 5F, 03, FB, 03, D2, 03, D3, 8B, 71, 0A, 66, 8B, 04, 32, C1, E0, 10, C1, E8, 0E, FF, 34, 38, 01, 1C, 24, 8B, 44...
 
[+]

Entropy:
7.9655  (probably packed)

Code size:
8.5 MB (8,912,384 bytes)

Remove AdvanceBox.exe - Powered by Reason Core Security