loader.exe

The application loader.exe has been detected as a potentially unwanted program by 33 anti-malware scanners. This is a setup program which is used to install the application. This file is typically installed with the program Havij 1.15 Free by ITSecTeam. The file has been seen being downloaded from dc276.gulfup.com.
MD5:
e050665de79858fe45b6616ed36a0160

SHA-1:
53362f4bebb7682d21c9ef1a3ae224ccae8c9df6

SHA-256:
d99cf5e296e724089cf7e936d5561d45088ccd58b026b02835ea3727fbbb8c60

Scanner detections:
33 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 5:57:48 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.23777
1106

Agnitum Outpost
Trojan.DR.Agent
7.1.1

AhnLab V3 Security
Win-Trojan/Xema.variant
2013.12.29

Avira AntiVirus
APPL/Agent.23217
7.11.122.154

avast!
Win32:Malware-gen
2014.9-140124

AVG
Skodna.GameHack
2015.0.3584

Baidu Antivirus
HackTool.Win32.Crack
4.0.3.14124

Bitdefender
Gen:Variant.Strictor.23777
1.0.20.120

Bkav FE
W32.Clodab8.Trojan
1.3.0.4923

Comodo Security
UnclassifiedMalware
17667

Emsisoft Anti-Malware
Gen:Variant.Strictor.23777
8.14.01.24.08

ESET NOD32
Win32/HackTool.Crack.BF
8.9190

Fortinet FortiGate
W32/VB.BL
1/24/2014

F-Prot
W32/VBTrojan.17D1
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.23777
11.2014-24-01_6

G Data
Gen:Variant.Strictor.23777
14.1.24

IKARUS anti.virus
Trojan-Dropper
t3scan.2.2.29

K7 AntiVirus
Trojan
13.174.10656

McAfee
Crack-RestrictRem
5600.7240

MicroWorld eScan
Gen:Variant.Strictor.23777
15.0.0.72

NANO AntiVirus
Trojan.Win32.VBBL.hedym
0.28.0.57029

Norman
Suspicious_Gen2.PFAZK
11.20140124

nProtect
Trojan/W32.Agent_Packed.23217
13.12.27.01

Panda Antivirus
Trj/CI.A
14.01.24.08

Reason Heuristics
Unnamed.Threat.41
14.2.23.11

Rising Antivirus
PE:Trojan.Win32.Generic.12341646!305403462
23.00.65.14122

Sophos
Mal/VB-BL
4.96

SUPERAntiSpyware
Trojan.Agent/Gen-Strictor
10825

Trend Micro House Call
CRCK_LOADER
7.2.24

Trend Micro
CRCK_LOADER
10.465.24

Vba32 AntiVirus
TScope.Trojan.VB
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
24852

ViRobot
Trojan.Win32.S.Agent.23230
2011.4.7.4223

File size:
22.7 KB (23,230 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\itsecteam\havij pro 1.7\loader.exe

File PE Metadata
Compilation timestamp:
3/28/2013 5:34:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.50

CTPH (ssdeep):
384:/TjN/RiNeOvgYnQe6fV/h2nBNw0OdykStbKEQpLko4lSMdPV1K2Cb/8Ca1uAOq6F:/XNwJxC6tbKwO2CbEZ4AC

Entry address:
0x17A20

Entry point:
60, BE, 00, 30, 41, 00, 8D, BE, 00, E0, FE, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA]

Code size:
20 KB (20,480 bytes)

The file loader.exe has been discovered within the following program.

Havij 1.15 Free  by ITSecTeam
ITSecTeam.com
About 6% of users remove it
 
Powered by Should I Remove It?

The file loader.exe has been seen being distributed by the following URL.

Remove loader.exe - Powered by Reason Core Security