mshww.exe

The executable mshww.exe has been detected as malware by 32 anti-virus scanners. This trojon will perform a number of actions that will compromise a PC including changing protected system registry values, hiding in protected operating system locations and downloading and installing additional malware.
MD5:
4ff266907f4a149c5e1e95ec3252a811

SHA-1:
59d4befe5d09a3320afb263038dc21c2be4a8d88

SHA-256:
3ad48fac9882cd2a42bea00c3bddaca6d939d1989dd22ae6ae9f24eada6d937f

Scanner detections:
32 / 68

Status:
Malware

Analysis date:
4/19/2024 2:03:43 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1762858
701

AegisLab AV Signature
Troj.Dropper.W32.Dorifel
2.1.4+

Agnitum Outpost
Backdoor.Androm
7.1.1

AhnLab V3 Security
Trojan/Win32.Gen
2014.11.06

Avira AntiVirus
BDS/Androm.eorc
7.11.183.118

avast!
Win32:Malware-gen
2014.9-150306

AVG
Inject2
2016.0.3179

Baidu Antivirus
Backdoor.Win32.Androm
4.0.3.1536

Bitdefender
Trojan.GenericKD.1762858
1.0.20.325

Comodo Security
UnclassifiedMalware
20002

Dr.Web
Trojan.Hottrend
9.0.1.065

Emsisoft Anti-Malware
Trojan.GenericKD.1762858
8.15.03.06.06

ESET NOD32
Win32/Injector.BIDO (variant)
9.10678

Fortinet FortiGate
W32/Androm.EORC!tr.bdr
3/6/2015

F-Secure
Trojan.GenericKD.1762858
11.2015-06-03_6

G Data
Trojan.GenericKD.1762858
15.3.24

IKARUS anti.virus
Backdoor.Win32.Androm
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.185.13888

Kaspersky
Backdoor.Win32.Androm
14.0.0.2389

McAfee
RDN/Generic BackDoor!zn
5600.6835

Microsoft Security Essentials
Trojan:Win32/Malagent!gmb
1.11104

MicroWorld eScan
Trojan.GenericKD.1762858
16.0.0.195

NANO AntiVirus
Trojan.Win32.Androm.dcywzs
0.28.6.62995

Norman
Troj_Generic.VBDDU
11.20150306

nProtect
Trojan.GenericKD.1762858
14.11.05.01

Qihoo 360 Security
HEUR/Malware.QVM05.Gen
1.0.0.1015

Quick Heal
Backdoor.Androm.r8
3.15.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.38H414
7.2.65

Trend Micro
TROJ_SPNR.38H414
10.465.06

VIPRE Antivirus
Trojan.Win32.Generic
34552

Zillya! Antivirus
Backdoor.Androm.Win32.10039
2.0.0.1976

File size:
123 KB (125,952 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\documents and settings\all users\mshww.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:t0aCrp2Hoss5snZ6aBRbif0nGTPAcnMjBmzcD8:mro5L04MXPASc

Entry address:
0x15028

Entry point:
55, 8B, EC, 83, C4, E8, 53, 56, 57, B8, 90, 4F, 41, 00, E8, 69, 02, FF, FF, 33, C0, 55, 68, F4, 5E, 41, 00, 64, FF, 30, 64, 89, 20, BE, 6E, A3, 01, 00, BB, 6E, A3, 01, 00, C7, 05, 78, 78, 41, 00, 6E, A3, 01, 00, BF, 6E, A3, 01, 00, B8, 7C, 78, 41, 00, E8, 44, E9, FE, FF, 66, C7, 05, 80, 78, 41, 00, 47, 01, 33, C0, 89, 05, 84, 78, 41, 00, C7, 05, 88, 78, 41, 00, 00, 00, F0, 3F, 33, C0, 89, 05, 8C, 78, 41, 00, C7, 05, 90, 78, 41, 00, 00, 00, F0, 3F, 33, C0, 89, 05, 94, 78, 41, 00, C7, 05, 98, 78, 41, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

Policies Explorer Run
Name:
747881841


Remove mshww.exe - Powered by Reason Core Security