eset lifetime updater_mrt_64.exe

The executable eset lifetime updater_mrt_64.exe has been detected as malware by 37 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
MD5:
f1029ba9b7099fe4d8edec05f355111c

SHA-1:
f2944233a1e19d6bde5512d9c29de7ea3176573b

SHA-256:
8df227f8eccfebde55dbf6f307e49853179f90a987ecaed4fa74eb5efa60067d

Scanner detections:
37 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 10:15:05 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.OG
6213306

Agnitum Outpost
Win32.Sality.AP.Gen
7.1.1

AhnLab V3 Security
Win32/Kashu.B
2014.12.22

Avira AntiVirus
W32/Sality.AA
7.11.30.172

avast!
Win32:Kukacka
141214-1

AVG
Win32/Tanatos.M
2014.0.4235

Bitdefender
Win32.Sality.OG
1.0.20.1780

Bkav FE
W32.Sality.PE
1.3.0.6267

Comodo Security
Virus.Win32.Sality.Gen
20438

Dr.Web
Win32.Sector.16
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality.OG
9.0.0.4668

ESET NOD32
Win32/Sality.NAU virus
7.0.302.0

Fortinet FortiGate
W32/Sality.AA
12/22/2014

F-Prot
W32/Sality.AK
4.6.5.141

F-Secure
Win32.Sality.OG
5.13.68

G Data
Win32.Sality.OG
14.12.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.5.0

K7 AntiVirus
Virus
13.188.14395

Kaspersky
Virus.Win32.Sality
15.0.0.543

McAfee
Trojan.Artemis!8052067C73A1
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.191.565.0

MicroWorld eScan
Win32.Sality.OG
15.0.0.1068

NANO AntiVirus
Virus.Win32.Sality.gcen
0.28.6.64267

Norman
Win32.Sality.OG
04.12.2014 14:30:06

nProtect
Win32.Sality.OG
14.12.19.01

Panda Antivirus
W32/Sality.AN
14.12.22.03

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Quick Heal
W32.Sality.R
12.14.14.00

Rising Antivirus
PE:Win32.KUKU.kj!1522176
23.00.65.141220

Sophos
Virus 'Mal/Sality-B'
5.09

Total Defense
Win32/Sality.AA
37.0.11343

Trend Micro House Call
PE_SALITY.BU
7.2.356

Trend Micro
PE_SALITY.BU
10.465.22

Vba32 AntiVirus
Virus.Win32.Sality.baka
3.12.26.3

VIPRE Antivirus
Threat.416209
35418

ViRobot
Win32.Sality.LA[h]
2014.3.20.0

Zillya! Antivirus
Virus.Sality.Win32.15
2.0.0.2012

File size:
2.2 MB (2,310,612 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\[productname]\eset lifetime updater_mrt_64.exe

File PE Metadata
Compilation timestamp:
6/9/2012 5:49:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:/nFDQsB9ji06890fY68wbEskwLrHPLrlBgaSyVqNSM:/n9QsBX68WY6DbRkIrHPLPglyVqv

Entry address:
0xAC87

Entry point:
60, 51, 68, 8C, BC, 41, 0C, E8, E1, 07, 00, 00, 5A, 5A, 68, 50, 7F, 7F, 08, 6A, 61, B9, 00, 00, 00, 00, 51, FF, 15, 78, 40, 41, 00, 33, DE, 0F, BE, F4, 0F, AF, EF, 0F, AD, EA, C7, C1, 3C, 0F, 96, 01, C0, F8, A6, 76, 0B, 03, DB, C0, F8, B6, 69, C8, EC, FF, C6, 71, 81, C4, D8, 04, FB, 00, 3C, 4F, 84, C3, 0F, AF, EF, C6, C2, 49, 81, EC, D0, 04, FB, 00, 0F, BA, E0, 67, 2B, F6, 56, FF, 15, 08, 41, 41, 00, E8, D2, 05, 00, 00, 81, EE, 82, 4F, 00, 00, F3, 8A, E2, 33, D9, B9, 6C, 7F, 46, F1, 69, C3, CF, 56, C1, 80...
 
[+]

Entropy:
7.8492  (probably packed)

Code size:
73 KB (74,752 bytes)

Remove eset lifetime updater_mrt_64.exe - Powered by Reason Core Security