doctor.exe

Created By PREDATOR

The executable doctor.exe has been detected as malware by 10 anti-virus scanners.
Publisher:
Created By PREDATOR

Product:
Created By PREDATOR

Version:
Created By PREDATOR

MD5:
9ed0d16528711b8c9115717a2f40a850

SHA-1:
03506d90c6b6a6fc91d8e64e86b3ce4229ec6937

SHA-256:
a65a5c6a37976fd5ddfe440313aa6907ad4b988134b3a5d94eb6dd3e2b13344a

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
4/26/2024 12:15:43 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Rogue.8026168.1
7.11.182.50

Comodo Security
UnclassifiedMalware
19940

IKARUS anti.virus
Trojan.Rogue
t3scan.1.8.3.0

McAfee
RDN/Generic.dx!dg3
5600.6938

NANO AntiVirus
Trojan.Win32.Rogue.cwftjo
0.28.6.62995

Norman
Suspicious_Gen2.VLBLQ
11.20141122

Qihoo 360 Security
Win32/Trojan.230
1.0.0.1015

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.141120

Sophos
Mal/VB-BL
4.98

VIPRE Antivirus
Trojan.Win32.Generic
34360

File size:
408 KB (417,792 bytes)

Product version:
Created By PREDATOR

Original file name:
Created By PREDATOR.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\doctor\photoshop\doctor.exe

File PE Metadata
Compilation timestamp:
4/12/2012 5:30:07 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:cHpdQNRWu6xfQ8Gp+ghbTjpLiKU16L0XFVQIo/X9YtGHlqSso44/D0IYUfIr4I38:cYtXEioSA/4Zc0fPCIq3

Entry address:
0x11C0

Entry point:
68, 14, 7D, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 5F, 20, 37, 6F, 64, 6D, 09, 4C, BC, 90, 03, 87, 12, B1, 87, 09, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 50, 72, 6F, 6A, 65, 63, 74, 31, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 03, AA, 4A, 83, 31, 61, C4, E2, 49, 91, A9, E2, 63, B8, C8, C3, 15, D1, BE, 15, 03, B7, 0A, 1D, 45, 89, 31, E4, FD, 27, CE, C5, 13, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
4.4927

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
36 KB (36,864 bytes)

Remove doctor.exe - Powered by Reason Core Security