GrooveMonitor.exe

GrooveMonitor Utility

Microsoft Corporation

The executable GrooveMonitor.exe has been detected as malware by 14 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘GrooveMonitor’. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
Publisher:
Microsoft Corporation

Product:
GrooveMonitor Utility

Version:
12.0.6413.1000

MD5:
250da5c6937d3adb6fe8276010b7dccf

SHA-1:
4bd7007ca90e6359122d33162ff4cdd7fac4a567

SHA-256:
bd540b8141d60c00070aa8084ed161844406068e4c0336afa537c9737ff54ffc

Scanner detections:
14 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
5/7/2024 12:52:44 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160203-1

AVG
Win32/Sality
2015.0.4489

Boost by Reason
Optional.Startup
188838

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5352.0

Norman
Win32.Sality.3
03.12.2014 13:20:04

Sophos
Virus 'Mal/Sality-D'
5.23

VIPRE Antivirus
Threat.4721115
46838

File size:
102.3 KB (104,800 bytes)

Product version:
4.2.2.2803

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
GrooveMonitor.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\microsoft office\office12\groovemonitor.exe

File PE Metadata
Compilation timestamp:
10/25/2008 1:42:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:Y9Orb+YKgkC63n6qSuP7VUqrowcShSZTwp98C1i:d+Y/JuP7V1DRSZkDNi

Entry address:
0x2A96

Entry point:
05, DB, 78, 38, 6D, 80, DA, D3, 87, C1, 0F, AF, D0, 86, FE, BF, 4F, 0A, 28, FB, 88, F7, FF, C7, 0F, AF, F1, 81, C7, FE, 2C, 99, C5, F3, 3D, 7B, 1B, 00, 00, 69, D0, F6, 17, CB, F4, FE, CF, 47, 81, E0, E0, 39, F8, B5, BB, 67, 42, 42, 7F, FF, C8, 69, D0, C7, 5C, 5A, BF, 42, 8A, E9, F7, C2, A2, A6, F8, 49, E8, 25, 00, 00, 00, 8D, 3D, F8, 10, 88, 16, 0F, AF, DA, 0F, B6, DF, 69, E8, A0, 19, 1C, 70, 33, CD, 35, EC, 62, 00, 00, 85, FD, 74, 08, 0F, B7, EB, C6, C6, 63, FE, CD, 5F, C7, C3, 04, A1, 38, 12, FE, C8, 18...
 
[+]

Entropy:
7.7120  (probably packed)

Code size:
10.5 KB (10,752 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GrooveMonitor

Command:
"C:\Program Files\microsoft office\office12\groovemonitor.exe"


Remove GrooveMonitor.exe - Powered by Reason Core Security