dotnet_reactor_setup.exe

Eziriz e.K.

The executable dotnet_reactor_setup.exe, “.NET Reactor Installation ” has been detected as malware by 41 anti-virus scanners. This is the uninstaller utility registered in the Windows Control Panel for the program .NET Reactor by Eziriz. The file is most likely infected with the Neshta virus, a Russian virus that gathers system information and send it to a remote command and cotrol server.
Publisher:
Eziriz   (signed by Eziriz e.K.)

Description:
.NET Reactor Installation

Version:
4.9.0.0

MD5:
39fee366c51faec972d19ffa37f030b0

SHA-1:
ea7a262c3fc30ad34742c3812d40f48d82d46ef1

SHA-256:
7eed0929e5239474fd2c4b05d33e2b735a8c1f999b5e15e0f31e5656700bb243

Scanner detections:
41 / 68

Status:
Malware

Explanation:
Infected with the direct-infection Neshta file infector virus.

Analysis date:
4/18/2024 11:26:48 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Neshta.C
876

Agnitum Outpost
Win32.Neshta.A
7.1.1

AhnLab V3 Security
Win32/Neshta
2013.08.22

Avira AntiVirus
W32/Neshta.A
7.11.170.204

avast!
Win32:Apanas [Trj]
2014.9-140912

AVG
Worm/Delf
2015.0.3354

Baidu Antivirus
Virus.Win32.Neshta.$a
4.0.3.14912

Bitdefender
Win32.Neshta.A
1.0.20.1275

Bkav FE
W32.HanGu.PE
1.3.0.4959

Clam AntiVirus
W32.Neshuta.A
0.98/19328

Comodo Security
Win32.Neshta.A
16801

Dr.Web
Win32.HLLP.Neshta
9.0.1.0255

Emsisoft Anti-Malware
Win32.Neshta
8.14.09.12.09

ESET NOD32
Win32/Neshta.A virus
8.7.0.302.0

Fortinet FortiGate
W32/Neshta.A
9/12/2014

F-Prot
W32/HLLP.41472
v6.4.6.5.141

F-Secure
Win32.Neshta.A
11.2014-12-09_6

G Data
Win32.Neshta
14.9.22

IKARUS anti.virus
Virus.Win32.Neshta
t3scan.2.0.127

K7 AntiVirus
Virus
13.170.9337

Kaspersky
Virus.Win32.Neshta
14.0.0.3263

Malwarebytes
Trojan.Agent
v2014.09.12.09

McAfee
W32/HLLP.41472.e
5600.7010

Microsoft Security Essentials
1.163.1557.0

MicroWorld eScan
Win32.Neshta.A
15.0.0.765

NANO AntiVirus
Virus.Win32.Neshta.cdby
0.26.0.53954

Norman
Neshta.C
11.20140912

nProtect
Virus/W32.Neshta
13.08.21.03

Panda Antivirus
W32/Neshta.A
14.09.12.09

Qihoo 360 Security
Virus.Win32.Neshta.B
1.0.0.1015

Quick Heal
W32.Neshta.A
9.14.12.00

Rising Antivirus
Win32.Netsha.a
23.00.65.14910

Sophos
W32/Bloat-A
4.91

SUPERAntiSpyware
Trojan.Agent/Gen-FlyStudio
10364

Total Defense
Win32/Neshta.A
37.0.10498

Trend Micro House Call
PE_NESHTA.A
7.2.255

Trend Micro
PE_NESHTA.A
10.465.12

Vba32 AntiVirus
Virus.Win32.Neshta.a
3.12.22.3

VIPRE Antivirus
Virus.Win32.Neshta.a
20730

ViRobot
Win32.Neshta.B
2011.4.7.4223

Zillya! Antivirus
Virus.Neshta.Win32.1
2.0.0.1911

File size:
3.5 MB (3,688,336 bytes)

Copyright:
All rights reserved

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\{b5b8690c-97c0-41b5-9ede-93d9f44d816f}\dotnet_reactor_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/19/2013 1:00:00 AM

Valid to:
9/20/2015 12:59:59 AM

Subject:
CN=Eziriz e.K., O=Eziriz e.K., STREET=Vogelweg 9, L=Brome, S=Niedersachsen, PostalCode=38465, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CA7FF879A5E31EF522F20CD3ADDA3D18

File PE Metadata
Compilation timestamp:
8/4/2011 1:35:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:cWAMaH3tX1bJrTknbUu4h+S0wH2+Wrt/0Z069e75sNTUjJ7:cWA9H3tX1b3PHfU/Y0gI7

Entry address:
0x219EF8

Entry point:
55, 8B, EC, B9, 27, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, 0C, 52, 61, 00, E8, C3, E5, DE, FF, 33, C0, 55, 68, 63, BA, 61, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, 28, A0, 61, 00, 64, FF, 30, 64, 89, 20, C7, 05, C0, 19, 63, 00, 94, 00, 00, 00, 68, C0, 19, 63, 00, E8, 2B, EF, DE, FF, E8, 3A, 34, FE, FF, 84, C0, 74, 6B, B2, 01, A1, 54, F4, 42, 00, E8, 66, 56, E1, FF, 8B, D8, BA, 00, 00, 00, 80, 8B, C3, E8, 34, 57, E1, FF, 8D, 55, E4, 33, C0, E8, D2, 95, DE, FF, 8B, 45, E4, 8D, 55, E8...
 
[+]

Entropy:
6.5376

Developed / compiled with:
Microsoft Visual C++

Code size:
2.1 MB (2,207,232 bytes)

Program Uninstaller
Program name:
.NET Reactor

Display publisher:
Eziriz

Display version:
4.9.0.0

Uninstall string:
"C:\ProgramData\{B5B8690C-97C0-41B5-9EDE-93D9F44D816F}\dotnet_reactor_setup.exe" REMOVE=TRUE MODIFY=FALSE


Remove dotnet_reactor_setup.exe - Powered by Reason Core Security