destroza_autorun_inf.exe

The executable destroza_autorun_inf.exe has been detected as malware by 15 anti-virus scanners.
MD5:
aee7fe9cc19dc7abbacbb894bd980005

SHA-1:
2334a8ffdd6e5316f7a31473fe00f1d1483ad6f7

SHA-256:
de3487fe4d991d7bad7ad3536c1fe13fb73c22e3a595436b914fbc7a627e37e6

Scanner detections:
15 / 68

Status:
Malware

Explanation:
The software cotains keystroke monitoring/logging capablities which may or may not be installed without the user's knowledge.

Analysis date:
4/25/2024 8:23:27 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-AppCare/NirCmd.26112
2014.02.26

Avira AntiVirus
TR/Drop.Kmat.A
7.11.133.166

Comodo Security
UnclassifiedMalware
17846

Dr.Web
Tool.NirCmd.1
9.0.1.0113

F-Prot
W32/MalwareF.KMAT
v6.4.7.1.166

K7 AntiVirus
Trojan
13.176.11269

McAfee
Generic.dx!vq
5600.7151

Norman
Suspicious_Gen2.ABQWA
11.20140423

Qihoo 360 Security
Win32/Trojan.1c9
1.0.0.1015

Quick Heal
Spyware.Keylogger (Not a Virus)
4.14.12.00

Rising Antivirus
PE:Trojan.Win32.Generic.125DB974!308132212
23.00.65.14421

Sophos
NirCmd
4.98

Trend Micro House Call
TROJ_GEN.R0C1C0EIN13
7.2.113

Trend Micro
TROJ_GEN.R0C1C0EIN13
10.465.23

VIPRE Antivirus
Spyware.Keylogger
26846

File size:
101.5 KB (103,932 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
1/22/2004 8:36:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
3072:eOOiq/olbDFNU7oEV/IN5fCX40aFQLichIBmvX:tdq8bRNU7XVwN5/zfcIwX

Entry address:
0x20A70

Entry point:
60, BE, 00, 60, 41, 00, 8D, BE, 00, B0, FE, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 19, 8B, 1E, 83, EE, FC, 11, DB, 72, 10, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 78, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11...
 
[+]

Entropy:
7.8618

Packer / compiler:
UPX 2.90LZMA]

Code size:
44 KB (45,056 bytes)

Remove destroza_autorun_inf.exe - Powered by Reason Core Security