detour.dll

The library detour.dll has been detected as malware by 40 anti-virus scanners. According to the AV engines that detect this, it is a detection for a file infected by members of the Win32/Ramnit malware family and may drop and load other malware.
MD5:
7c16cca70b2a1e5fbf37c7fadaa653ce

SHA-1:
fc2db8690f2de098bb8bb0b086d02f3a5b562b84

SHA-256:
39d959ff9aa486127e2424d99dc338019448846d4ef491d0bf7a0e7b9cc46ff4

Scanner detections:
40 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/23/2024 11:44:56 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Ramnit
827

AegisLab AV Signature
W32.Nimnul
2.1.4+

Agnitum Outpost
Win32.Ramnit.Gen.3
7.1.1

AhnLab V3 Security
Win32/Ramnit.B
2014.10.31

Avira AntiVirus
W32/Ramnit.A
7.11.30.172

avast!
Win32:RmnDrp
141025-0

AVG
Win32/Ramnit.A
2014.0.4189

Baidu Antivirus
Virus.Win32.Nimnul.$a
4.0.3.141031

Bitdefender
Win32.Ramnit
1.0.20.1520

Bkav FE
W32.RammitNNA.PE
1.3.0.6185

Clam AntiVirus
W32.Ramnit-1
0.98/21411

Comodo Security
Virus.Win32.Ramnit.A
19950

Dr.Web
Win32.Rmnet
9.0.1.05190

Emsisoft Anti-Malware
Win32.Ramnit
14.10.30

ESET NOD32
Win32/Ramnit.A virus
7.0.302.0

Fortinet FortiGate
W32/Ramnit.C
10/31/2014

F-Prot
W32/Ramnit.B
4.6.5.141

F-Secure
Win32.Ramnit
11.2014-31-10_6

G Data
Win32.Ramnit
14.10.24

IKARUS anti.virus
Virus.Win32.Ramnit
t3scan.1.8.3.0

K7 AntiVirus
Virus
13.185.13853

Kaspersky
Virus.Win32.Nimnul
15.0.0.494

Malwarebytes
Virus.Ramnit
v2014.10.31.04

McAfee
W32/Ramnit.a
5600.6961

Microsoft Security Essentials
Threat.Undefined
1.187.957.0

MicroWorld eScan
Win32.Ramnit
15.0.0.912

NANO AntiVirus
Virus.Win32.Nimnul.bpchjo
0.28.6.62995

Norman
Ramnit.AS
11.20141031

nProtect
Win32.Ramnit
14.10.30.01

Qihoo 360 Security
Virus.Win32.Ramnit.B
1.0.0.1015

Quick Heal
W32.Ramnit.A
10.14.14.00

Rising Antivirus
PE:Win32.Ramnit.a!1590234
23.00.65.141029

Sophos
W32/Patched-I
4.98

Total Defense
Win32/Ramnit.A
37.0.11256

Trend Micro House Call
PE_RAMNIT.H
7.2.304

Trend Micro
PE_RAMNIT.H
10.465.31

Vba32 AntiVirus
Virus.Win32.Nimnul.a
3.12.26.3

VIPRE Antivirus
Threat.4726519
34232

ViRobot
Win32.Ramnit.E
2011.4.7.4223

Zillya! Antivirus
Virus.Nimnul.Win32.2
2.0.0.1973

File size:
114.5 KB (117,248 bytes)

File type:
Dynamic link library (Win32 DLL)

File PE Metadata
Compilation timestamp:
8/20/2009 7:43:14 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:S6Lr1ukp9dxRuvuIoThafsXIt/Ead5nJ:HLsy7uGIokoIpx1J

Entry address:
0x13000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 8B, C5, 81, ED, 32, 6F, 01, 20, 2B, 85, 50, 72, 01, 20, 89, 85, 4C, 72, 01, 20, B0, 00, 86, 85, 9E, 74, 01, 20, 3C, 01, 0F, 85, DE, 02, 00, 00, 8B, 85, 4C, 72, 01, 20, 2B, 85, 58, 72, 01, 20, 8B, 00, 89, 85, EA, 73, 01, 20, 8B, 85, 4C, 72, 01, 20, 2B, 85, 5C, 72, 01, 20, 8B, 00, 89, 85, F2, 73, 01, 20, 83, BD, F2, 73, 01, 20, 00, 0F, 84, A9, 02, 00, 00, 83, BD, EA, 73, 01, 20, 00, 0F, 84, 9C, 02, 00, 00, 8D, 85, 8D, 74, 01, 20, 50, FF, 95, EA, 73, 01, 20, 83, F8, 00, 0F, 84, 86...
 
[+]

Entropy:
7.3268

Packer / compiler:
ASPack v1.08.04

Code size:
32.5 KB (33,280 bytes)

Remove detour.dll - Powered by Reason Core Security