maq.exe

UTool

The executable maq.exe has been detected as malware by 29 anti-virus scanners.
Publisher:
UTool

Product:
UTool

Version:
3.006 LegalCopyright

MD5:
07335f257e3e8eaf188a8dac3e5df159

SHA-1:
225c5d7564824d0fbba043f748afe5e20ad1528b

SHA-256:
48727e76e9383751b6ec4a5135be10e1e778c2a15c473a27a8840f146ad570c7

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
4/29/2024 8:26:02 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Agent.26112.KA
5.0.

Avira AntiVirus
DR/Delphi.Gen
7.9.1.14

Emsisoft A-Squared
Trojan.Win32.Buzus!IK
4.5.0.24

avast!
Win32:Trojan-gen {Other}
2014.9-170314

AVG
Agent2
2018.0.2439

Bitdefender
Trojan.Slenfbot.F
1.0.20.365

Clam AntiVirus
Trojan.Agent-117059
0.98/171

Comodo Security
UnclassifiedMalware
2310

Dr.Web
BackDoor.Bifrost.11
9.0.1.073

ESET NOD32
Win32/Injector.KZ (variant)
11.4422

Fortinet FortiGate
W32/Agent.BVOC!tr
3/14/2017

F-Prot
W32/Trojan2.HUMD
v6.4.5.1.85

F-Secure
Trojan.Win32.Agent.bvoc
11.2017-14-03_3

G Data
Trojan.Slenfbot
17.3.19

IKARUS anti.virus
Trojan.Win32.Buzus
t3scan.1.1.72.0

K7 AntiVirus
Trojan.Win32.Agent.bvoc
13.7.10.843

Kaspersky
Trojan.Win32.Agent
14.0.0.-1308

McAfee
Spam-Mailbot.l
5600.6095

Microsoft Security Essentials
VirTool:Win32/DelfInject.gen!AF
1.163.1557.0

Norman
W32/Agent.MEUF
11.20170314

nProtect
Trojan/W32.Agent.26112.BP
2009.1.8.0

Panda Antivirus
Trj/Downloader.MDW
17.03.14.03

Prevx
Email High Risk Cloaked Malware
3.0

Quick Heal
Trojan.Agent.bvoc
3.17.10.00

Rising Antivirus
Trojan.Win32.Nodef.fot
23.00.65.17312

Sophos
W32/Mailbt-Gen
4.45

Trend Micro
TROJ_MAILBOT.AP
10.465.14

Vba32 AntiVirus
Trojan.Win32.Agent.btld
3.12.10.10

ViRobot
Trojan.Win32.Agent.26112.AFF
2009.9.12.1932

File size:
25.5 KB (26,112 bytes)

Product version:
3.00D

Copyright:
1990-2009

Trademarks:
UTool

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
7/27/2002 3:47:21 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x2F20

Entry point:
55, 8B, EC, 83, C4, F0, B8, A8, 2E, 00, 01, E8, 7C, EA, FF, FF, 33, C0, 55, 68, B7, 2F, 00, 01, 64, FF, 30, 64, 89, 20, 6A, 00, 6A, 00, 6A, 00, 6A, 00, E8, D1, ED, FF, FF, 6A, 00, E8, D2, ED, FF, FF, 6A, 00, 6A, 00, 6A, 00, E8, CF, ED, FF, FF, 90, 6A, 00, 6A, 00, 6A, 00, 68, FF, FF, FF, 0F, E8, 2E, EB, FF, FF, 85, C0, 75, 37, 90, E8, 48, FE, FF, FF, 84, C0, 75, 2D, 90, B8, 7B, 00, 00, 00, E8, 69, FE, FF, FF, 90, E8, E7, EE, FF, FF, 90, E8, A9, FB, FF, FF, 90, 6A, 00, 68, 08, 2C, 00, 01, 6A, 0A, 6A, 00, A1...
 
[+]

Entropy:
7.1457

Developed / compiled with:
Microsoft Visual C++

Code size:
8 KB (8,192 bytes)

Remove maq.exe - Powered by Reason Core Security