board 1388.exe

The executable board 1388.exe has been detected as malware by 40 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Msn Messsenger’.
MD5:
3b8d27c7291589bd794491959892b2e8

SHA-1:
f8c8debdece9eba63e96a55a56abcac10c4c52cc

SHA-256:
8313c0a7757bec2daf80553dfaacf48decc65c06eff863cadb6380df1e95fa16

Scanner detections:
40 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/23/2024 5:12:15 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Worm.Sohanad.NBN
888

Agnitum Outpost
Trojan.Autoit.DX
7.1.1

AhnLab V3 Security
Win32/Virut.F
2014.08.31

Avira AntiVirus
W32/Virut.Gen
7.11.30.172

avast!
Malware-gen
140813-1

AVG
Autoit.DB
2014.0.4015

Baidu Antivirus
Virus.Win32.Virut.$NBP
4.0.3.14831

Bitdefender
Win32.Worm.Sohanad.NBN
1.0.20.1215

Bkav FE
W32.Vetor.PE
1.3.0.4959

Clam AntiVirus
Trojan.Siggen-7
0.98/19316

Comodo Security
TrojWare.Win32.Trojan.Autoit.ci0
19373

Dr.Web
Win32.Virut.56
9.0.1.05190

Emsisoft Anti-Malware
Win32.Worm.Sohanad.NBN
9.0.0.4324

ESET NOD32
Win32/Virut.NBP virus
7.0.302.0

Fortinet FortiGate
W32/Autorun.HNW!tr
8/31/2014

F-Prot
W32/Trojan2.DFYJ
4.6.5.141

F-Secure
IM-Worm:W32/Sohanad.HM
11.2014-31-08_1

G Data
Win32.Worm.Sohanad.NBN
14.8.24

IKARUS anti.virus
Trojan.Autoit
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13218

Kaspersky
Worm.Win32.AutoRun
15.0.0.494

McAfee
W32/Virut.n.gen
5600.7022

Microsoft Security Essentials
Threat.Undefined
1.183.900.0

MicroWorld eScan
Win32.Worm.Sohanad.NBN
15.0.0.729

NANO AntiVirus
Virus.Win32.Virut.hpeg
0.28.2.61861

Norman
Sohanad.gen5
11.20140831

nProtect
Virus/W32.Virut.Gen
14.08.31.01

Panda Antivirus
W32/Autorun.IOI
14.08.31.04

Qihoo 360 Security
Worm.Win32.FakeFolder.BV
1.0.0.1015

Quick Heal
W32.Virut.G
8.14.14.00

Rising Antivirus
PE:Malware.FakeFolder@CV!1.6AA9
23.00.65.14829

Sophos
W32/AutoRun-BUC
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Yahlover
10389

Total Defense
Win32/Virut.17408
37.0.11153

Trend Micro House Call
PE_VIRUX.R
7.2.243

Trend Micro
PE_VIRUX.R
10.465.31

Vba32 AntiVirus
Virus.Virut.14
3.12.26.3

VIPRE Antivirus
Threat.4739697
32210

ViRobot
Win32.Virut.AM
2011.4.7.4223

Zillya! Antivirus
Virus.Virut.Win32.1938
2.0.0.1907

File size:
696.5 KB (713,216 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
10/17/1998 4:39:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:J3TdtLW5WIj1YSSdFxskgUKzHeBfgSyd:hDsj1dEcYBYJd

Entry address:
0xD2071

Entry point:
83, 3C, 24, FE, 90, 77, FE, F7, C4, 77, 24, 3F, 33, 8D, 64, 24, CC, 60, 90, 83, EC, DC, E8, 13, 02, 00, 00, 4B, B5, 67, 87, F7, 66, 4B, 75, FC, 34, 00, 39, CE, 90, 42, 8A, C7, FF, 73, 3C, 59, 81, E9, FD, FF, FF, 7F, 87, FF, F6, D4, 73, DF, 0F, 97, C2, FC, 81, D9, E6, 13, 00, 00, 71, D3, A8, 6B, 34, 00, FF, B4, 19, E4, 13, 00, 80, 83, C4, 04, 66, 81, 44, 24, FC, B0, BA, 75, BC, 3C, 5B, 38, C4, 68, 21, D6, 82, CD, E8, 21, 00, 00, 00, 89, 74, 24, 44, FE, C2, E8, 7D, 00, 00, 00, 8D, BA, 43, BC, FE, 92, 89, 44...
 
[+]

Entropy:
7.2616

Code size:
404.5 KB (414,208 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Msn Messsenger

Command:
C:\users\{user}\appdata\roaming\regsvr.exe


Remove board 1388.exe - Powered by Reason Core Security