js.exe

The executable js.exe has been detected as malware by 32 anti-virus scanners.
MD5:
995b29e1cadf6272a5ccf3f9ef50c5ab

SHA-1:
d517f64969bb0e145a99fd13b1285cf40c4c0375

SHA-256:
80bcac1ea3c1a0d36bfd2ffb1b6da2c0a3fcd7212a4378547290e9e79c3e3f21

Scanner detections:
32 / 68

Status:
Malware

Analysis date:
4/29/2024 3:03:15 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/Mabezat
2011.09.24

Avira AntiVirus
Worm/Mabezat.b
7.11.15.29

avast!
Win32:Mabezat-AM [Trj]
2014.9-170314

AVG
Worm/Mabezat.A
2018.0.2440

Bitdefender
Win32.Worm.Mabezat.J
1.0.20.365

Clam AntiVirus
W32.Mabezat-2
0.98/18011

Comodo Security
Worm.Win32.Mabezat.b
10233

Dr.Web
Win32.HLLW.Tazebama
9.0.1.073

Emsisoft Anti-Malware
Worm.Win32.Mabezat!IK
8.17.03.14.12

ESET NOD32
Win32/Mabezat
11.6491

Fortinet FortiGate
W32/Mabezat.B!worm
3/14/2017

F-Prot
W32/Mabezat.A
v6.4.6.2.117

F-Secure
Win32.Worm.Mabezat.J
11.2017-14-03_3

G Data
Win32.Worm.Mabezat
17.3.22

IKARUS anti.virus
Worm.Win32.Mabezat
t3scan.1.1.107.0

K7 AntiVirus
Virus
13.113.5184

Kaspersky
Worm.Win32.Mabezat
14.0.0.-1305

McAfee
W32/Mabezat
5600.6096

Microsoft Security Essentials
Virus:Win32/Mabezat.B
1.163.1557.0

Norman
Mabezat.B
11.20170314

nProtect
Win32.Worm.Mabezat.S
11.09.24.01

Panda Antivirus
W32/Mabezat.C.worm
17.03.14.12

Prevx
High Risk Cloaked Malware
3.0

Quick Heal
W32.Mabezat.Dr
3.17.11.00

Rising Antivirus
Worm.Win32.Autorun.gcy
23.00.65.17312

Sophos
W32/Mabezat-B
4.69

SUPERAntiSpyware
Trojan.Agent/Gen-VirutZ
8537

Trend Micro House Call
PE_MABEZAT.B-O
7.2.73

Trend Micro
PE_MABEZAT.B-O
10.465.14

Vba32 AntiVirus
Worm.Win32.Mabezat.b
3.12.16.4

VIPRE Antivirus
Worm.Win32.Mabezat.b
10574

ViRobot
Worm.Win32.Mabezat.154751
2011.9.24.4687

File size:
151.4 KB (155,001 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-computer\js\js.exe

File PE Metadata
Compilation timestamp:
10/29/2007 9:17:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1000

Entry point:
53, 83, EC, 44, B8, 23, 10, 40, 00, B9, 00, 00, 00, 00, 8A, 18, 80, C3, 42, 88, 18, 83, C0, 01, 83, C1, 01, 81, F9, 37, D1, 00, 00, 75, EB, 76, BE, BE, FF, BE, 77, BE, BE, BE, BE, 48, D6, 3E, 81, 9C, 46, D6, 41, 7F, BF, 41, 7E, BF, 3F, B7, BD, E5, BE, BE, 33, A9, 76, BE, CE, FE, BE, 79, 81, 81, 81, 81, 47, D6, 76, 93, 98, FE, BE, 41, 7E, BE, 41, 82, 02, BD, 8E, 81, 19, 81, A6, C3, BE, BE, BE, A7, C8, BE, BE, BE, 77, 96, E5, FF, BE, A7, 29, 73, BE, BE, 26, 3C, CE, FE, BE, A6, ED, 87, BE, BE, 17, 81, 77, 96...
 
[+]

Entropy:
7.0361

Code size:
52.5 KB (53,760 bytes)

Remove js.exe - Powered by Reason Core Security