getrt52b.exe

The executable getrt52b.exe has been detected as malware by 33 anti-virus scanners. This virus which infects .exe files stops various security software and prevents some core Windows utilities from running. It also tries to download other files from a remote server, including other malware.
MD5:
f79b422e60aa98692cbb469959ab48aa

SHA-1:
34850365179fcf6f3eb5a2ac85ae3ece2cdf98f8

SHA-256:
460560e569a3cb46991d7717feef2c31b8169fb7a5757080220f35f71423eed8

Scanner detections:
33 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/18/2024 10:31:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
1023

Agnitum Outpost
Win32.Sality.BL
7.1.1

AhnLab V3 Security
Win32/Kashu.E
14.04.18

Avira AntiVirus
W32/Sality.AT
7.11.144.52

avast!
Win32:SaliCode
2014.9-140418

AVG
Win32/Sality
2015.0.3501

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.14418

Bitdefender
Win32.Sality.3
1.0.20.540

Comodo Security
Virus.Win32.Sality.Gen
18125

Dr.Web
Win32.Sector.22
9.0.1.0108

Emsisoft Anti-Malware
Win32.Sality
8.14.04.18.10

ESET NOD32
Win32/Sality.NBA
8.9694

F-Prot
W32/Sality.gen2
v6.4.7.1.166

F-Secure
Win32.Sality.3
11.2014-18-04_6

G Data
Win32.Sality
14.4.24

IKARUS anti.virus
Virus.Win32.Sality
t3scan.1.6.1.0

K7 AntiVirus
Virus
13.176.11806

Kaspersky
Virus.Win32.Sality
14.0.0.3998

McAfee
W32/Sality.gen.z
5600.7157

Microsoft Security Essentials
Virus:Win32/Sality.AT
1.10502

MicroWorld eScan
Win32.Sality.3
15.0.0.324

NANO AntiVirus
Virus.Win32.Sality.beygb
0.28.0.59288

Norman
Malware.EOUY
11.20140418

nProtect
Win32.Sality.3
14.04.18.01

Panda Antivirus
W32/Sality.AA
14.04.18.10

Quick Heal
W32.Sality.U
4.14.12.00

Sophos
Mal/Sality-D
4.98

Total Defense
Win32/Sality.AA
37.0.10884

Trend Micro House Call
PE_SALITY.RL
7.2.108

Trend Micro
PE_SALITY.RL
10.465.18

Vba32 AntiVirus
Virus.Win32.Sality.bakc
3.12.26.0

VIPRE Antivirus
Virus.Win32.Sality.at
28352

ViRobot
Win32.Sality.N
2011.4.7.4223

File size:
3.2 MB (3,319,059 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\getrt52b.exe

File PE Metadata
Compilation timestamp:
4/25/2000 7:37:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:PXGSLt775ShHamd3/4fqNVQbbLt6tqIm8W6Kz+lcp:DJ4hHTd3/FVst6sIxWJz+l2

Entry address:
0x21AF

Entry point:
C7, C7, B1, 08, E6, 9A, 51, 0F, AF, CE, 02, CB, F6, C3, 23, 0F, AF, FE, 51, 68, 0E, 9C, DF, 00, F7, C1, BB, 77, 43, FE, F2, FF, C1, C6, C5, A8, 87, C9, F7, C6, DB, 7B, E2, 5A, E8, 27, 00, 00, 00, 8D, 2D, 2E, 90, 6B, F8, FF, CD, 8D, 15, D5, A1, A1, D4, 32, D7, 69, D2, 1A, 1A, 45, F2, 81, F3, CB, 6A, 00, 00, 0D, F3, E2, DA, 29, 8D, 0D, 50, 62, 8F, A4, EB, 07, 8B, D3, 87, C9, C6, C6, DA, 8A, F2, 0F, BE, E8, 88, DF, 81, EF, DD, A3, 00, 00, FF, C2, 81, C7, 1C, 0F, 00, 00, 58, 45, B7, D7, 0F, AF, D5, 0F, AF, FB...
 
[+]

Entropy:
7.9984  (probably packed)

Code size:
8.5 KB (8,704 bytes)

Remove getrt52b.exe - Powered by Reason Core Security