chrome.exe

The executable chrome.exe has been detected as malware by 14 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘chrome’.
MD5:
bb160d7805a51cacdbc53fd3a8bf238b

SHA-1:
4356987716070ff613351a9b64acfa9b4a8754c2

SHA-256:
b858b8a96f2ee7de1692f4f4567859217dfd31eccda813b4178a08d306837d09

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
4/27/2024 3:07:58 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.357518
1018

Avira AntiVirus
TR/Dropper.MSIL.Gen
7.11.141.52

avast!
Win32:Malware-gen
2014.9-140423

AVG
ILCrypt
2015.0.3496

Baidu Antivirus
Trojan.MSIL.Kryptik
4.0.3.14423

Bitdefender
Gen:Variant.Kazy.357518
1.0.20.565

Comodo Security
TrojWare.MSIL.Crypted.fu
18044

Emsisoft Anti-Malware
Gen:Variant.Kazy.357518
8.14.04.23.07

ESET NOD32
MSIL/Kryptik.RV (variant)
8.9635

F-Secure
Gen:Variant.Kazy.357518
11.2014-23-04_4

G Data
Gen:Variant.Kazy.357518
14.4.24

Malwarebytes
Backdoor.Bot
v2014.04.23.07

MicroWorld eScan
Gen:Variant.Kazy.357518
15.0.0.339

Qihoo 360 Security
Malware.QVM03.Gen
1.0.0.1015

File size:
340 KB (348,160 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\google \chrome.exe

File PE Metadata
Compilation timestamp:
3/27/2014 8:38:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:SxLhxAqxs0UYRXS5r+sNrkD0ug3OK8srQ4HCPEkx0YAaJWEgVqioAospx0tHt:SxAqxs0UY5S4ws++JYWPlxRAgEWjAet

Entry address:
0x55A5E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8487

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
335 KB (343,040 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
chrome

Command:
C:\users\{user}\appdata\roaming\google \chrome.exe


Remove chrome.exe - Powered by Reason Core Security