eset lifetime updater_mrt_32.exe

The executable eset lifetime updater_mrt_32.exe has been detected as malware by 38 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
MD5:
40a59489acb32f6812d7d7f1ce0bfa31

SHA-1:
c0c2a262ed3d0a34fec531388b5202a39a4559fc

SHA-256:
a231322d995f03fe697d6614f7e1d5a700fac3fb9bef5be1b268d050c50dd7d4

Scanner detections:
38 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/24/2024 2:19:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.OG
6213306

Agnitum Outpost
Win32.Sality.AP.Gen
7.1.1

AhnLab V3 Security
Win32/Kashu.B
2014.12.22

Avira AntiVirus
W32/Sality.AA
7.11.197.26

avast!
Win32:Kukacka
141214-1

AVG
Win32/Tanatos.M
2014.0.4235

Baidu Antivirus
Virus.Win32.Sality.$gen
4.0.3.141222

Bitdefender
Win32.Sality.OG
1.0.20.1780

Bkav FE
W32.Sality.PE
1.3.0.6267

Comodo Security
Virus.Win32.Sality.Gen
20438

Dr.Web
Win32.Sector.16
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality.OG
9.0.0.4668

ESET NOD32
Win32/Sality.NAU virus
7.0.302.0

Fortinet FortiGate
W32/Sality.AA
12/22/2014

F-Prot
W32/Sality.AK
4.6.5.141

F-Secure
Win32.Sality.OG
5.13.68

G Data
Win32.Sality.OG
14.12.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.5.0

K7 AntiVirus
Virus
13.188.14395

Kaspersky
Virus.Win32.Sality
15.0.0.543

McAfee
Trojan.Artemis!8052067C73A1
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.191.565.0

MicroWorld eScan
Win32.Sality.OG
15.0.0.1068

NANO AntiVirus
Virus.Win32.Sality.gcen
0.28.6.64267

Norman
Win32.Sality.OG
04.12.2014 14:30:06

nProtect
Win32.Sality.OG
14.12.19.01

Panda Antivirus
W32/Sality.AN
14.12.22.03

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Quick Heal
W32.Sality.R
12.14.14.00

Rising Antivirus
PE:Win32.KUKU.kj!1522176
23.00.65.141220

Sophos
Virus 'Mal/Sality-B'
5.09

Total Defense
Win32/Sality.AA
37.0.11343

Trend Micro House Call
PE_SALITY.BU
7.2.356

Trend Micro
PE_SALITY.BU
10.465.22

Vba32 AntiVirus
Virus.Win32.Sality.baka
3.12.26.3

VIPRE Antivirus
Threat.416209
35418

ViRobot
Win32.Sality.LA[h]
2014.3.20.0

Zillya! Antivirus
Virus.Sality.Win32.15
2.0.0.2012

File size:
2.2 MB (2,310,612 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\eset lifetime updater_mrt_32.exe

File PE Metadata
Compilation timestamp:
6/9/2012 5:49:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:xsB9ji06890fY68wbEskwLrHPLrlBgaSyVqNSM:xsBX68WY6DbRkIrHPLPglyVqv

Entry address:
0xAC87

Entry point:
60, 6A, 3D, E8, E1, 08, 00, 00, 33, C1, C1, D6, 05, 0F, CF, F3, 86, D5, 78, 3C, 68, 6B, B9, C9, D3, F2, FF, C6, 58, F3, 08, C2, 81, E8, 22, 5D, AC, BF, 0F, C1, CB, 0F, A4, F7, C4, 69, FE, 25, 54, C7, 6E, 69, C8, 17, 7E, 49, E8, 0F, AF, DA, 81, C0, 97, FE, C9, 68, FF, C1, 81, F0, A0, E3, 1A, 75, F7, C0, 65, 94, 07, AE, 81, C4, 01, 00, 00, 00, C1, E1, 24, 0F, A4, F7, 05, BE, D5, 44, F7, DE, 41, 81, C4, 03, 00, 00, 00, 0F, BC, FE, 84, F1, 8B, D9, 81, E1, CC, 5F, A6, D1, EB, 01, AF, E8, 15, 00, 00, 00, 19, F7...
 
[+]

Entropy:
7.8492  (probably packed)

Code size:
73 KB (74,752 bytes)

Remove eset lifetime updater_mrt_32.exe - Powered by Reason Core Security