dprotect_setup.exe

The executable dprotect_setup.exe has been detected as malware by 24 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source.
MD5:
ff27a639125b3d21607ea3a4d9dbacaf

SHA-1:
79f678dee994e196353c4770b7631466b3c6bace

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/25/2024 12:34:10 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Zbot
14.04.19

Avira AntiVirus
BDS/Rogue.905651
7.11.149.178

avast!
Win32:Dropper-LTG [Drp]
2014.9-140419

AVG
Win32/DH{ZX18ICIlVw9OADUBNgo}
2015.0.3500

Comodo Security
TrojWare.Win32.Sisron.C
18124

Dr.Web
BackDoor.Bulknet.1328
9.0.1.0109

ESET NOD32
Win32/Webprefix (variant)
8.9693

Fortinet FortiGate
W32/Webprefix.B!tr
4/19/2014

F-Prot
W32/Dlpro.A.gen
v6.4.7.1.166

G Data
Win32.Trojan-Dropper.Dlpro
14.4.24

IKARUS anti.virus
Virus.Win32.Dropper
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.176.11806

Kaspersky
Trojan-Downloader.Win32.Klevate
14.0.0.3995

McAfee
GenericATG-FRW!8B9B760E1CBD
5600.7156

Microsoft Security Essentials
Trojan:Win32/Klevate
1.10502

NANO AntiVirus
Trojan.Win32.Webprefix.crgiyt
0.28.0.59288

Norman
Downloader
11.20140419

nProtect
Trojan-Downloader/W32.Klevate.201610
14.05.14.01

Reason Heuristics
Threat.Win.Reputation.IMP
14.5.1.1

Sophos
Mal/Generic-S
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Klevate
10633

Vba32 AntiVirus
TrojanDownloader.Klevate
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28348

Zillya! Antivirus
Trojan.Webprefix.Win32.62419
2.0.0.1786

File size:
196.9 KB (201,610 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Application data\wwerwerwe\asdasdasd\dprotect_setup.exe

File PE Metadata
Compilation timestamp:
3/19/2014 1:25:02 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:UL65ojxERH9AvfoLC3TKLzsDLLumtPuH9smVkl1vH7+EW:wVd20foW3mHsDLLZtPy98H7I

Entry address:
0x2678F

Entry point:
E8, 19, 5F, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 50, 82, 40, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 54, 82, 40, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, AE, 22, 00, 00, 85, C0, 75, 06, B8, B8, 83, 40, 00, C3, 83, C0, 08, C3, E8, 9B, 22, 00, 00, 85, C0, 75, 06, B8, BC, 83, 40, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Remove dprotect_setup.exe - Powered by Reason Core Security