launcher.exe

vb_sade

The executable launcher.exe has been detected as malware by 34 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
Product:
vb_sade

Version:
1.00

MD5:
c3134c6545272c568c3ffc3c8dc48db5

SHA-1:
3c6e829ad5541c62bcf6d37f7bb3d4a5a84ff493

SHA-256:
a133b221cc6ea7031b96b2964e7189f6f33b20848c07bffd59bb10d1649cf7ea

Scanner detections:
34 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 2:04:51 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
6486625

Agnitum Outpost
Win32.Sality.FA.Gen
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2015.01.31

Avira AntiVirus
W32/Sality.AT
7.11.30.172

avast!
Win32:Sality
150101-1

AVG
Win32/Sality
2014.0.4257

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.15130

Bitdefender
Win32.Sality.3
1.0.20.150

Bkav FE
W32.Sality.PE
1.3.0.6379

Dr.Web
Win32.Sector.22
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
9.0.0.4799

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.13.68

G Data
Win32.Sality
15.1.25

IKARUS anti.virus
Virus.Win32.Sality
t3scan.1.8.6.0

K7 AntiVirus
Virus
13.193.14817

Kaspersky
Virus.Win32.Sality
15.0.0.543

McAfee
Trojan.Artemis!8BFB86066953
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.191.3639.0

MicroWorld eScan
Win32.Sality.3
16.0.0.90

NANO AntiVirus
Virus.Win32.Sality.bzkem
0.30.0.65070

Norman
Win32.Sality.3
03.12.2014 13:20:04

nProtect
Win32.Sality.3
15.01.30.01

Panda Antivirus
W32/Sality.AA
15.01.30.01

Quick Heal
W32.Sality.U
1.15.14.00

Sophos
Virus 'Mal/Sality-D'
5.09

Total Defense
Win32/Sality.AA
37.0.11411

Trend Micro House Call
PE_SALITY.ER
7.2.30

Trend Micro
PE_SALITY.ER
10.465.30

Vba32 AntiVirus
Virus.Win32.Sality.bakb
3.12.26.3

VIPRE Antivirus
Threat.4758034
36694

ViRobot
Win32.Sality.N[h]
2014.3.20.0

Zillya! Antivirus
Virus.Sality.Win32.20
2.0.0.2049

File size:
104 KB (106,496 bytes)

Product version:
1.00

Original file name:
a_chrome.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\opera\launcher.exe

File PE Metadata
Compilation timestamp:
12/30/2014 1:37:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:/IDCRK67E9Qj4qzmt+HgJlzHXzB1Pzlhqr25y9b+cRJhkfrvCDW7sLG:NRK6g924yqnV1P74IcRJmfb2LG

Entry address:
0x1214

Entry point:
8B, F2, 0F, AF, C0, 8A, CC, 0F, AF, DA, 02, DE, F7, C2, B0, C0, 51, 4A, 03, DD, 8B, F0, F6, C2, 43, 56, 8A, ED, 5F, 57, 43, 5D, 3D, DA, 4B, 00, 00, 73, 02, 0C, F7, 74, 07, 14, 65, C6, C1, 6E, 89, E9, 33, D5, EB, 06, 8D, 1D, 52, 64, A2, 7F, F7, D0, 68, 78, 91, D1, 00, EB, 0D, FF, C1, F6, C3, 8C, F7, C2, D1, 96, 95, 11, 89, C7, 09, D1, C6, C4, 9C, 72, 06, 81, D6, ED, E6, 1F, 5B, 8D, 1D, 15, 30, FE, FF, 81, EB, 5A, 64, 00, 00, 12, CE, 0F, C9, C6, C5, CC, B8, 3D, 0A, 07, 00, 0F, AF, CE, 35, 56, 86, 00, 00, F6...
 
[+]

Code size:
8 KB (8,192 bytes)

Remove launcher.exe - Powered by Reason Core Security