flash_professional_8.exe

The executable flash_professional_8.exe has been detected as malware by 34 anti-virus scanners. This virus which infects .exe files stops various security software and prevents some core Windows utilities from running. It also tries to download other files from a remote server, including other malware.
MD5:
eedcf8b549760a4d511fbb869b7f5900

SHA-1:
38d82f6941bf20e5020d0ce5cc88ebdc83475971

SHA-256:
80c69ae7ea7acb54287e3f5780e8730641efbd7c78af4dd7a9ac245f1906d7fe

Scanner detections:
34 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 5:09:02 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
1023

Agnitum Outpost
Win32.Sality.BL
7.1.1

AhnLab V3 Security
Win32/Kashu.E
14.04.18

Avira AntiVirus
W32/Sality.AT
7.11.144.52

avast!
Win32:SaliCode
2014.9-140418

AVG
Win32/Sality
2015.0.3501

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.14418

Bitdefender
Win32.Sality.3
1.0.20.540

Bkav FE
W32.Sality.PE
1.3.0.4959

Comodo Security
Virus.Win32.Sality.Gen
18125

Dr.Web
Win32.Sector.22
9.0.1.0108

Emsisoft Anti-Malware
Win32.Sality
8.14.04.18.10

ESET NOD32
Win32/Sality.NBA
8.9694

F-Prot
W32/Sality.gen2
v6.4.7.1.166

F-Secure
Win32.Sality.3
11.2014-18-04_6

G Data
Win32.Sality
14.4.24

IKARUS anti.virus
Virus.Win32.Sality
t3scan.1.6.1.0

K7 AntiVirus
Virus
13.176.11806

Kaspersky
Virus.Win32.Sality
14.0.0.3998

McAfee
W32/Sality.gen.z
5600.7157

Microsoft Security Essentials
Virus:Win32/Sality.AT
1.10502

MicroWorld eScan
Win32.Sality.3
15.0.0.324

NANO AntiVirus
Virus.Win32.Sality.beygb
0.28.0.59288

Norman
Sality.ZHB
11.20140418

nProtect
Win32.Sality.3
14.04.18.01

Panda Antivirus
W32/Sality.AA
14.04.18.10

Quick Heal
W32.Sality.U
4.14.12.00

Sophos
Mal/Sality-D
4.98

Total Defense
Win32/Sality.AA
37.0.10884

Trend Micro House Call
PE_SALITY.RL
7.2.108

Trend Micro
PE_SALITY.RL
10.465.18

Vba32 AntiVirus
Virus.Win32.Sality.bakc
3.12.26.0

VIPRE Antivirus
Virus.Win32.Sality.at
28352

ViRobot
Win32.Sality.N
2011.4.7.4223

File size:
348 KB (356,352 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\idm\dwnldata\singh\flash_professional_8_11\flash_professional_8.exe

File PE Metadata
Compilation timestamp:
9/5/2001 10:02:57 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:WKMw54w9V4xzikZ1Zuz7mzVGnM6vKBj5OM8LcKwA5i/kfoQ+hSl0+:jJ5/4JikZhS5sjkM8nn5T7+hsz

Entry address:
0x8947

Entry point:
EB, 0C, 0F, BF, F1, 69, FD, 48, C1, 4F, A5, 0F, AF, FE, 89, D2, F6, C6, 43, 71, 0A, 46, F7, C0, 77, F8, 85, 35, 0F, AF, CE, 53, 48, 04, AF, 1B, CB, 23, C5, 40, E8, 00, 00, 00, 00, 33, D2, 31, FB, 84, F2, 33, C6, 14, 25, 0F, B6, EF, 0F, BE, DA, 81, C2, 33, 05, 00, 00, 0F, AF, E8, 8D, 3D, 4C, 17, 49, 69, 81, EA, 32, 05, 00, 00, 38, CD, 0F, B7, C0, 8B, F8, 69, C7, F5, AE, EA, 84, 70, 01, 4B, 81, FA, 15, 01, 00, 00, 0F, 8C, C1, FF, FF, FF, 5B, B2, D7, B6, 09, 3A, E0, 8B, D0, 48, 80, E1, 2D, 8A, C9, 81, EF, E9...
 
[+]

Entropy:
4.8747

Code size:
72 KB (73,728 bytes)

Remove flash_professional_8.exe - Powered by Reason Core Security