gehh.exe

The executable gehh.exe has been detected as malware by 2 anti-virus scanners.
MD5:
57bcdd39759862522365d53a1fa4ba49

SHA-1:
3ed8999d7da2b42e362a41a17670579ab9004c2b

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
5/1/2024 7:50:24 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160917-0

ESET NOD32
Win32/Sality virus
6.3.12010.0

File size:
96.7 KB (99,044 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
2/10/2002 10:15:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1040

Entry point:
E8, 00, 00, 00, 00, 59, 0F, 6E, C9, 0F, 7E, CB, 81, C3, F9, 01, 00, 00, FF, E3, 6A, 00, FF, 15, 00, 10, 40, 00, C3, 90, 90, 90, 9C, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BA, 10, 00, 00, 00, 10, 00, 00, A4, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, 10, 00, 00, 08, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AC, 10, 00, 00, 00, 00, 00, 00, C8, 10, 00, 00, 00, 00, 00, 00, 7D, 00, 45, 78, 69, 74, 50, 72, 6F, 63, 65, 73, 73, 00, 4B, 45, 52, 4E, 45, 4C...
 
[+]

Code size:
512 Bytes (512 bytes)

Windows Firewall Allowed Program
Name:
C:\gehh.exe


Remove gehh.exe - Powered by Reason Core Security