google chrome.exe

Setup

Google Inc.

The executable google chrome.exe has been detected as malware by 12 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from s10203.chomikuj.pl.
Publisher:
Google Inc.

Product:
Setup

Version:
1.2.183.29

MD5:
3767e69480f030f9b556c45677e55c25

SHA-1:
5030411f543c3eba5bec83e0f3cb2e0dfc219ffd

SHA-256:
413830503a95a91dccb2ca225b60854f931f428e3050ae63343ac3610d7ddf76

Scanner detections:
12 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
5/15/2024 11:27:09 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160207-1

AVG
Win32/Sality
2015.0.4477

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5580.0

Norman
Win32.Sality.3
03.12.2014 13:20:04

Sophos
Virus 'Mal/Sality-D'
5.23

VIPRE Antivirus
Threat.4721115
46904

File size:
726.4 KB (743,792 bytes)

Product version:
1.2.183.29

Copyright:
Copyright 2007-2010 Google Inc.

Original file name:
Setup

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\google chrome.exe

File PE Metadata
Compilation timestamp:
6/2/2010 1:19:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:OUITUHVc+4ankoM64oAdQW4iUTitzg5nZCSd++epTxw0Ni:7IIezGkH6ydQDi0iRsnddN0i

Entry address:
0x1000

Entry point:
60, 74, 05, 89, C9, 85, F8, F2, 84, FF, 88, D2, F6, C1, 9A, 85, DB, 42, 8B, D0, FF, C5, 81, FA, D6, 04, 00, 00, 73, 05, 88, D4, F6, C1, A1, 81, F7, 6A, CE, 00, 00, 29, F5, 84, F1, F2, 20, FE, 2D, BB, D2, 3F, DB, 12, D9, F7, C0, 0C, 59, C5, 11, 11, CF, 69, DA, EF, 2A, 8F, 2D, EB, 06, 84, E4, B5, 58, FF, C6, E8, 21, 00, 00, 00, 81, FA, 58, F3, 00, 00, 71, 08, 81, DB, 26, 4B, C7, 77, F2, F2, F7, C5, CA, B3, 82, 05, 8A, CF, 8B, DE, 0F, AF, D2, 2C, 71, 3B, F8, 81, FB, 59, 25, 00, 00, 72, 04, 39, F8, 85, C1, 80...
 
[+]

Code size:
13.5 KB (13,824 bytes)

The file google chrome.exe has been seen being distributed by the following URL.

Remove google chrome.exe - Powered by Reason Core Security