be8d4204a364b6d3316cf7c4422d4812_26624.npb

The file be8d4204a364b6d3316cf7c4422d4812_26624.npb has been detected as malware by 13 anti-virus scanners. According to AVG, this software downloads additional adware offers during setup.
MD5:
be8d4204a364b6d3316cf7c4422d4812

SHA-1:
66e0ef8df606b25409ab412c62282d7e7e28b92c

SHA-256:
6481e8b668c04b922e8e523ac65c313e3c82b0014c79db19a816c6b1799f771b

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/19/2024 12:13:46 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-150907

AVG
Trojan horse Downloader.Generic_r
2016.0.2994

Dr.Web
Trojan.MulDrop4.25343
9.0.1.0250

Emsisoft Anti-Malware
Gen:Variant.Zusy.36950
8.15.09.07.09

ESET NOD32
Win32/Bundpil.D worm
9.7.0.302.0

F-Prot
W32/Agent.RD.gen
v6.4.6.5.141

herdProtect (fuzzy)
2015.9.7.9

Microsoft Security Essentials
Threat.Undefined
1.185.2411.0

MicroWorld eScan
Gen:Variant.Zusy.36950
16.0.0.750

nProtect
Trojan/W32.Agent.26624.QX
14.10.06.01

Quick Heal
Trojan.Agent.WL
9.15.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
15.8.2.15

VIPRE Antivirus
Threat.4780893
33706

File size:
26 KB (26,624 bytes)

Common path:
C:\ProgramData\application data\net protector\npbkp\be8d4204a364b6d3316cf7c4422d4812_26624.npb

File PE Metadata
Compilation timestamp:
2/8/2013 1:14:07 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:tn9opvGMutW+7Qta+dK+5DUod7COE9tzf/V:tngeW+ctaSK+5wtOkbV

Entry address:
0x12E70

Entry point:
80, 7C, 24, 08, 01, 0F, 85, B9, 01, 00, 00, 60, BE, 00, D0, 00, 10, 8D, BE, 00, 40, FF, FF, 57, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB...
 
[+]

Entropy:
7.7153  (probably packed)

Code size:
28 KB (28,672 bytes)

Remove be8d4204a364b6d3316cf7c4422d4812_26624.npb - Powered by Reason Core Security