freecomponent.exe

The executable freecomponent.exe has been detected as malware by 10 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from www.technoriversoft.com.
MD5:
97575f02377b2d3388c9ff18cbe1413f

SHA-1:
070896c92e28621e4f425efc58c2b96f93633d07

SHA-256:
ea3732c72055b19cf1095b4b47655542b8d3d70ee59b0d69107e74e9639d42a9

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/19/2024 11:46:12 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160216-3

AVG
Win32/Sality
2015.0.4530

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.213.7751.0

Sophos
Virus 'Mal/Sality-D'
5.23

File size:
3.6 MB (3,728,448 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\freecomponent.exe

File PE Metadata
Compilation timestamp:
8/21/2008 4:22:30 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:ULU2mL0qOx7N8pieRHw1RaZsvzEQ8TcLwNPv2IDrN9KAhGVdKFgM:UVmL0qOJN8UeZw1RNgjc8NX2crNbIQFL

Entry address:
0x28AA2

Entry point:
85, ED, 68, 0B, 41, 89, 00, 88, E7, 81, E0, 6F, 49, 32, 27, 8B, DA, 3B, D5, 0F, B6, F8, 8D, 05, A5, 88, CF, 74, B2, 54, 0F, BE, C8, E8, 12, 00, 00, 00, F6, D3, 87, C6, 81, E9, F5, BF, 00, 00, 2B, DD, 81, E9, E0, 3D, 00, 00, 5A, FF, CE, 8A, EC, 0F, C9, 81, FD, 5B, E3, 00, 00, 77, 09, 0F, CF, 88, E9, B7, 7F, 80, D0, 45, 85, D6, 68, 4D, 0C, 00, 00, 35, 8C, 99, 3F, F9, 5E, 80, D5, E7, 81, EE, 4D, 0C, 00, 00, 87, C1, 18, F9, 81, FD, 5A, 07, 00, 00, 76, 07, B9, A4, 1D, 97, D3, 09, D9, 8A, CB, 8D, 05, FC, D5, FF...
 
[+]

Code size:
168.5 KB (172,544 bytes)

The file freecomponent.exe has been seen being distributed by the following URL.

Remove freecomponent.exe - Powered by Reason Core Security