microinstallernative.exe

The executable microinstallernative.exe has been detected as malware by 38 anti-virus scanners. The file is most likely infected with the Neshta virus, a Russian virus that gathers system information and send it to a remote command and cotrol server.
MD5:
27830d7a357bc3e174e8a09822c43cbf

SHA-1:
2ca559978fff29937ed4a088dcc066f0ba1cb113

SHA-256:
815f5c7ff10237ee870661b1cbefb6e5677f03876a1f5c5ad7583aff4520bc35

Scanner detections:
38 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 4:25:43 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Neshta.A
551

Agnitum Outpost
Win32.Neshta.A
7.1.1

AhnLab V3 Security
Win32/Neshta
2015.03.28

Avira AntiVirus
W32/Neshta.A
3.6.1.96

avast!
Win32:Apanas [Trj]
2014.9-150802

AVG
Worm/Delf
2016.0.3029

Baidu Antivirus
Virus.Win32.Neshta.$a
4.0.3.1582

Bitdefender
Win32.Neshta.A
1.0.20.1070

Bkav FE
W32.NeshtaB.PE
1.3.0.6379

Clam AntiVirus
W32.Neshuta.A
0.98/21511

Comodo Security
Win32.Neshta.A
21560

Dr.Web
Win32.HLLP.Neshta
9.0.1.0214

Emsisoft Anti-Malware
Win32.Neshta
8.15.08.02.12

ESET NOD32
Win32/Neshta
9.11388

Fortinet FortiGate
W32/Neshta.A
8/2/2015

F-Prot
W32/HLLP.41472
v6.4.7.1.166

F-Secure
Win32.Neshta.A
11.2015-02-08_1

G Data
Win32.Neshta
15.8.25

IKARUS anti.virus
Virus.Win32.Neshta
t3scan.1.8.9.0

K7 AntiVirus
Virus
13.202.15407

Kaspersky
Virus.Win32.Neshta
14.0.0.1642

McAfee
W32/HLLP.41472.e
5600.6685

Microsoft Security Essentials
1.1.11502.0

MicroWorld eScan
Win32.Neshta.A
16.0.0.642

NANO AntiVirus
Virus.Win32.Neshta.cdby
0.30.8.659

Norman
Neshta.C
11.20150802

Qihoo 360 Security
Malware.Radar02.Gen
1.0.0.1015

Quick Heal
W32.Neshta.C8
8.15.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
15.8.2.12

Rising Antivirus
PE:Win32.Netsha.a!411233
23.00.65.15731

Sophos
W32/Bloat-A
4.98

Total Defense
Win32/Neshta.A
37.0.11517

Trend Micro House Call
PE_NESHTA.A
7.2.214

Trend Micro
PE_NESHTA.A
10.465.02

Vba32 AntiVirus
Virus.Win32.Neshta.a
3.12.26.3

VIPRE Antivirus
Virus.Win32.Neshta.a
38834

ViRobot
Win32.Neshta.B[h]
2014.3.20.0

Zillya! Antivirus
Virus.Neshta.Win32.1
2.0.0.2118

File size:
202.2 KB (207,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\microinstallernative.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:sr85CCG1Ggz1/6m1KH3+8+QHXCZRvANZp:k9CGX1BhsXivAN3

Entry address:
0x80E4

Entry point:
55, 8B, EC, 83, C4, E0, 33, C0, 89, 45, E0, 89, 45, E8, 89, 45, E4, 89, 45, EC, B8, 54, 80, 40, 00, E8, 12, BE, FF, FF, 33, C0, 55, 68, 20, 82, 40, 00, 64, FF, 30, 64, 89, 20, B8, A8, 91, 40, 00, B9, 0B, 00, 00, 00, BA, 0B, 00, 00, 00, E8, 5C, EF, FF, FF, B8, B4, 91, 40, 00, B9, 09, 00, 00, 00, BA, 09, 00, 00, 00, E8, 48, EF, FF, FF, B8, C0, 91, 40, 00, B9, 03, 00, 00, 00, BA, 03, 00, 00, 00, E8, 34, EF, FF, FF, B8, DC, 91, 40, 00, B9, 03, 00, 00, 00, BA, 03, 00, 00, 00, E8, 20, EF, FF, FF, A1, 10, 92, 40...
 
[+]

Entropy:
5.9503

Developed / compiled with:
Microsoft Visual C++

Code size:
29 KB (29,696 bytes)

Remove microinstallernative.exe - Powered by Reason Core Security