!install.exe

The executable !install.exe, “Install SpIDer Guard © HA3APET” has been detected as malware by 23 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source.
Description:
Install SpIDer Guard © HA3APET

Version:
5. 0. 0. 0

MD5:
6b547bbef3fb632be0ed984ccb406ae1

SHA-1:
92bfa2d33d66ca5cfd9a1097d2272a19d3e6c2b7

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
4/25/2024 2:48:08 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.4829309
775

Avira AntiVirus
TR/Gendal.4829309
7.11.173.24

Bitdefender
Trojan.Generic.4829309
1.0.20.1780

Clam AntiVirus
Trojan.Delf-9628
0.98/21411

Emsisoft Anti-Malware
Trojan.Generic.4829309
8.14.12.22.06

Fortinet FortiGate
W32/SPNR.04CM11!tr
12/22/2014

F-Prot
W32/Dropper.AHIP
v6.4.7.1.166

F-Secure
Trojan.Generic.4829309
11.2014-22-12_2

G Data
Trojan.Generic.4829309
14.12.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.183.13417

McAfee
Generic.dx!6B547BBEF3FB
5600.6909

MicroWorld eScan
Trojan.Generic.4829309
15.0.0.1068

Norman
Delfiles.BP
11.20141222

nProtect
Trojan.Generic.4829309
14.09.18.01

Panda Antivirus
Trj/CI.A
14.12.22.06

Qihoo 360 Security
Win32/Trojan.441
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.12AAC63C!313181756
23.00.65.141220

Sophos
Mal/Generic-L
4.98

Total Defense
Win32/FakeAV.CTK
37.0.11187

Trend Micro House Call
TROJ_SPNR.04CM11
7.2.356

Trend Micro
TROJ_SPNR.04CM11
10.465.22

VIPRE Antivirus
Trojan.Win32.Generic
33232

File size:
55 KB (56,320 bytes)

Product version:
5. 0. 0. 0

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\programs\dr.web.15\!install.exe

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
768:39J8NowRheD8/3rJiUqyet8w9abyzS5E50kyoVonvnRiZljBwiwo5sW3yhz7v76P:39wvQUreUbyzsB+2myhzT7hOzRv5

Entry address:
0xA0C0

Entry point:
55, 8B, EC, B9, 06, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 58, A0, 40, 00, E8, 0C, A9, FF, FF, 33, C0, 55, 68, F9, A4, 40, 00, 64, FF, 30, 64, 89, 20, A1, C0, B2, 40, 00, 33, D2, 89, 10, 8D, 45, EC, E8, 7D, F8, FF, FF, 8B, 55, EC, B8, 5C, C9, 40, 00, E8, 58, 99, FF, FF, 8D, 55, E8, A1, 5C, C9, 40, 00, E8, 83, F7, FF, FF, 8B, 55, E8, B8, 5C, C9, 40, 00, E8, 3E, 99, FF, FF, B8, 60, C9, 40, 00, BA, 00, 08, 00, 00, E8, 9F, 9D, FF, FF, 68, 00, 08, 00, 00, A1, 60, C9, 40, 00, E8, A8, 9C, FF, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
38 KB (38,912 bytes)

Remove !install.exe - Powered by Reason Core Security