forever.exe

FUCK YOU

The application forever.exe has been detected as a potentially unwanted program by 30 anti-malware scanners.
Product:
FUCK YOU

Version:
1.00

MD5:
0c132f227cd871e766f3485820391fa0

SHA-1:
10920564bf2d9b2b82517806bd96803c328a4edc

SHA-256:
7190a3df12e8d572888809fa55bbb37efaf31922dc20cfe46b29c13ba5be13b6

Scanner detections:
30 / 68

Status:
Potentially unwanted

Analysis date:
5/1/2024 10:43:19 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/Xema.worm.82432.AS
2011.08.14

Avira AntiVirus
TR/Crypt.PEPM.Gen
7.11.13.37

avast!
Win32:Adware-gen [Adw]
2014.9-170315

AVG
Worm/VB
2018.0.2438

Bitdefender
Worm.Generic.256767
1.0.20.370

Clam AntiVirus
PUA.Packed.PECompact-1
0.98/18011

Comodo Security
Worm.Win32.Autorun.eb0
9742

Dr.Web
Win32.HLLW.Autoruner.7157
9.0.1.074

Emsisoft Anti-Malware
Virus.Worm.VB!IK
8.17.03.15.07

ESET NOD32
Win32/AutoRun.VB.CN (variant)
11.6377

F-Prot
W32/Worm.AMTJ
v6.4.6.2.117

F-Secure
Worm.Generic.256767
11.2017-15-03_4

G Data
Worm.Generic.256767
17.3.22

IKARUS anti.virus
Virus.Worm.VB
t3scan.1.1.107.0

K7 AntiVirus
EmailWorm
13.105010

Kaspersky
Worm.Win32.VB
14.0.0.-1314

McAfee
W32/Autorun.worm.eb
5600.6094

Microsoft Security Essentials
Worm:Win32/VB.HA
1.163.1557.0

Norman
W32/VBWorm.TFN
11.20170315

nProtect
Worm/W32.Agent.82432.AH
11.08.14.01

Panda Antivirus
Adware/AccesMembre
17.03.15.07

Quick Heal
Worm.VB.amh
3.17.11.00

Rising Antivirus
Worm.Win32.Autorun.fap
23.00.65.17313

Sophos
Mal/Behav-109
4.67

SUPERAntiSpyware
Trojan.Agent/Gen-Falprod
8533

Trend Micro House Call
WORM_AUTORUN.SM3
7.2.74

Trend Micro
WORM_AUTORUN.SM3
10.465.15

Vba32 AntiVirus
Trojan.VBO.0292
3.12.16.4

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
10160

ViRobot
Worm.Win32.VB.82432.CW
2011.8.13.4621

File size:
80.5 KB (82,432 bytes)

Product version:
1.00

Original file name:
love.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\s-1-5-31-1286970278978-5713669491-166975984-320\rotinom\forever.exe

File PE Metadata
Compilation timestamp:
4/3/2009 6:54:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x122C

Entry point:
B8, 84, A4, 43, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, C9, 6A, ED, 02, 56, 17, 1F, 53, 85, B4, 0A, AE, 31, 46, 8B, 50, 27, 65, E2, 76, 5A, 3D, 63, 30, 8C, 6E, D5, 5D, B0, 42, 0A, 19, 0C, 28, 46, 48, 99, B4, 50, D1, E8, 4D, 88, 2B, 4A, 69, 18, C7, 1B, D1, 48, D0, DA, 2C, AE, A2, 3D, A0, 1F, 01, DC, DF, 24, 56, 4E, DA, 99, 1E, 9B, 8C, 9F, CB, 15, B4, DB, B3, 29, 76, 8C, F6, BE, 73, 4F, 41, FF, B5, AA, 35, F3, 82, A8, 49, E7...
 
[+]

Entropy:
6.6498

Packer / compiler:
PECompact v2

Code size:
136 KB (139,264 bytes)

Remove forever.exe - Powered by Reason Core Security