crazya.exe

The executable crazya.exe has been detected as malware by 39 anti-virus scanners.
MD5:
2a16bdce7844b48b0dc8fcb585d8cde4

SHA-1:
91e99ccca25d0b9066f1c90294be5b76e9eb7f9a

SHA-256:
33c467c40736218e33a3cb1163b4ac905670405424c50616a006f4dcd10adb1d

Scanner detections:
39 / 68

Status:
Malware

Analysis date:
4/23/2024 7:00:58 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Worm.Autorun.VJU
833

AegisLab AV Signature
W32.W.AutoRun
2.1.4+

Agnitum Outpost
Worm.AutoRun
7.1.1

AhnLab V3 Security
Worm/Win32.AutoRun
2014.02.04

Avira AntiVirus
TR/Spy.ZBot.KN.1
7.11.128.222

avast!
Win32:AutoRun-VC [Wrm]
2014.9-141025

AVG
Worm/AutoRun
2015.0.3311

Baidu Antivirus
Virus.Win32.AutoIt
4.0.3.141025

Bitdefender
Worm.Autorun.VJU
1.0.20.1490

Bkav FE
W32.CrazyA
1.3.0.4923

Clam AntiVirus
Win.Worm.Autorun-356
0.98/18355

Comodo Security
Worm.Win32.AutoRun.FN
17725

Dr.Web
Win32.HLLW.Autoruner.3906
9.0.1.0298

Emsisoft Anti-Malware
Worm.Autorun.VJU
8.14.10.25.08

ESET NOD32
Win32/AutoRun.FN
8.9376

Fortinet FortiGate
W32/Autorun.BL!tr
10/25/2014

F-Prot
W32/Worm.AVWJ
v6.4.7.1.166

F-Secure
Worm.Autorun.VJU
11.2014-25-10_7

G Data
Worm.Autorun.VJU
14.10.24

IKARUS anti.virus
Backdoor.Win32.IRCBot
t3scan.2.2.29

K7 AntiVirus
EmailWorm
13.175.11046

Kaspersky
Virus.Win32.AutoIt
14.0.0.3048

McAfee
PWS-Zbot.gen.kn
5600.6967

Microsoft Security Essentials
Worm:Win32/Autorun.gen!BA
1.165.247.01

MicroWorld eScan
Worm.Autorun.VJU
15.0.0.894

NANO AntiVirus
Trojan.Win32.Autoruner.idxrq
0.28.0.57630

Norman
Malware
11.20141025

nProtect
Worm.Autorun.VJU
14.02.03.01

Panda Antivirus
W32/Autorun.ASM
14.10.25.08

Qihoo 360 Security
Malware.QVM10.Gen
1.0.0.1015

Quick Heal
Worm.Autorun.BA4
10.14.12.00

Rising Antivirus
PE:Trojan.Win32.Generic.12A5A531!312845617
23.00.65.141023

Sophos
W32/Autorun-AJR
4.97

Total Defense
Win32/SillyAutorun.AY
37.0.10739

Trend Micro House Call
TROJ_GEN.R0CBC0DHP13
7.2.298

Trend Micro
TROJ_GEN.R0CBOC0JC13
10.465.25

Vba32 AntiVirus
Win32.AutoRun
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
26102

ViRobot
Worm.Win32.Autorun.126976.C
2011.4.7.4223

File size:
1.5 MB (1,526,784 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Application data\crazya.exe

File PE Metadata
Compilation timestamp:
11/19/2007 4:59:48 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:tqVFAY7hslYDZ4Ny7SIn9uGBRTgqlyDwNSUbnXTn+ekorDjUwh5VoQ:4AyCM7SI0ann+hoph5Vo

Entry address:
0x7059

Entry point:
E8, 8A, 81, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 1D, EE, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, A4, 3D, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 08, D1, 41, 00, 74, 12, 8B, 0D, 20, D0, 41, 00, 85, 48, 70, 75, 07, E8, 51, 14, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 28, CF, 41, 00, 74, 16, 8B, 46, 08, 8B, 0D, 20, D0, 41, 00...
 
[+]

Entropy:
0.8147

Code size:
88 KB (90,112 bytes)

Remove crazya.exe - Powered by Reason Core Security