installer.exe

The executable installer.exe has been detected as malware by 15 anti-virus scanners. The program is a setup application that uses the Nullsoft Scriptable Install System installer, however the file is not signed with an authenticode signature from a trusted source.
MD5:
40dc1c96ad20d2628d48d6dd0731bb12

SHA-1:
3a4f14ca0d4f623db2b14abc71156fb2c5847e2e

SHA-256:
f7b84a0ba22613b6937bfd7db536942e9068bceeafee348d29a08d84b239ddcb

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
4/27/2024 12:52:10 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Virtob.Gen.12
5813571

avast!
Win32:Vitro
160118-1

AVG
Win32/Virut
2015.0.4477

Clam AntiVirus
Win.Trojan.Agent-971646
0.98/21330

Dr.Web
Win32.Virut.56
9.0.1.05190

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
10.0.0.5366

ESET NOD32
Win32/Virut.NBP virus
7.0.302.0

F-Prot
W32/Virut.AL!Generic
4.6.5.141

F-Secure
Win32.Virtob.Gen.12
5.15.21

Kaspersky
Virus.Win32.Virut
15.0.0.562

McAfee
Virus.W32/Madangel.b
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5087.0

Norman
Win32.Virtob.Gen.12
11.01.2016 17:30:26

Sophos
Virus 'W32/Scribble-B'
5.22

VIPRE Antivirus
Threat.4737366
46244

File size:
664.5 KB (680,448 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\installer.exe

File PE Metadata
Compilation timestamp:
12/10/2002 1:08:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:mISCHiwlAp5nFs8jtHAWz+8EZE9BJGyizOX598EBX/F5DeHni8Cvs21:m9CHi9rho8msJGywOpK6vF5R1

Entry address:
0xDB2C3

Entry point:
83, 3C, 24, FE, 77, FE, 8D, 64, 24, CC, 60, 83, EC, DC, E8, D5, FF, FF, FF, 4B, 66, 4B, E9, 8B, 00, 00, 00, 01, AD, 10, 00, 00, 00, FF, 15, D4, FE, FF, FF, 29, AD, 10, 00, 00, 00, C3, 6A, 08, FF, 54, 24, 58, FF, 85, CC, FE, FF, FF, FF, 54, 24, 58, 54, FF, 54, 24, 5C, FF, 54, 24, 5C, FF, 54, 24, 58, FF, D7, 3B, F0, 74, DD, 8D, 17, 8B, D5, 50, 0F, 31, 5E, C3, 4C, 74, 6B, 43, 33, 00, 0F, BE, F3, 8D, 34, 30, E8, C3, FF, FF, FF, 8D, 4C, 24, 40, 6A, 05, 56, 87, 51, F0, 89, 41, F4, 8F, 41, EC, 8F, 85, CC, FE, FF...
 
[+]

Code size:
23.5 KB (24,064 bytes)

Remove installer.exe - Powered by Reason Core Security