msiexec.exe

PEview

Wayne J. Radburn

The executable msiexec.exe, “PE/COFF File Viewer” has been detected as malware by 31 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Wayne J. Radburn

Product:
PEview

Description:
PE/COFF File Viewer

Version:
0.9.8.2

MD5:
c0432df41fd427ba522ea92111e177c7

SHA-1:
94b5ce44059effbb504d420ac3dd3c6d6aeb8684

SHA-256:
b3624a8f24681ebed915e14ee0983fa497940cd6894c56be23746131ce4a89c9

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/24/2024 7:49:05 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.154544
826

Agnitum Outpost
Trojan.Kryptik
7.1.1

AhnLab V3 Security
Trojan/Win32.ZBot
2014.10.11

avast!
Win32:Dropper-gen [Drp]
2014.9-141101

AVG
Crypt3
2015.0.3304

Bitdefender
Gen:Variant.Graftor.154544
1.0.20.1525

Clam AntiVirus
Win.Trojan.Zbot-36709
0.98/21411

Dr.Web
Trojan.PWS.Panda.2401
9.0.1.0305

Emsisoft Anti-Malware
Gen:Variant.Graftor.154544
8.14.11.01.01

ESET NOD32
Win32/Kryptik.CLAL (variant)
8.10544

Fortinet FortiGate
W32/Zbot.CLAL!tr
11/1/2014

F-Secure
Gen:Variant.Graftor.154544
11.2014-01-11_7

G Data
Gen:Variant.Graftor.154544
14.11.24

IKARUS anti.virus
Trojan-Spy.Zbot
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.183.13642

Kaspersky
Trojan-Spy.Win32.Zbot
14.0.0.3015

Malwarebytes
Trojan.Ransom.ED
v2014.11.01.01

McAfee
RDN/Generic PWS.y!bbb
5600.6960

Microsoft Security Essentials
PWS:Win32/Zbot
1.11005

MicroWorld eScan
Gen:Variant.Graftor.154544
15.0.0.915

NANO AntiVirus
Trojan.Win32.Zbot.devias
0.28.2.62483

Panda Antivirus
Trj/CI.A
14.11.01.01

Qihoo 360 Security
Win32/Trojan.Spy.2d9
1.0.0.1015

Sophos
Troj/Wonton-GU
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Wonton
10265

Total Defense
Win32/Zbot.bTDYaaB
37.0.11219

Trend Micro House Call
TROJ_GEN.R028C0DID14
7.2.305

Trend Micro
TROJ_GEN.R028C0DID14
10.465.01

Vba32 AntiVirus
TrojanSpy.Zbot
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
33804

Zillya! Antivirus
Trojan.ZBot.Win32.26
2.0.0.1949

File size:
299 KB (306,176 bytes)

Product version:
0.9.8.2

Copyright:
Copyright© 1997-2011 Wayne J. Radburn

Original file name:
PEview.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\application data\windows genuine advantage\{40a67d2d-efea-400c-a93b-5a7bc5fbd7cf}\msiexec.exe

File PE Metadata
Compilation timestamp:
9/6/2014 12:57:26 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:hFt1QrrcctH38U9CKTECKBqVJkFdbZopzleCiP49x:H7QrrccHT9CKsBzHtod1iP4v

Entry address:
0x3BF2

Entry point:
E8, 35, 84, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 30, 34, 44, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 3C, 31, 44, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 28, A4, 44, 00, 89, 0D, 24, A4, 44, 00, 89, 15, 20, A4, 44, 00, 89, 1D, 1C, A4, 44, 00, 89, 35, 18, A4, 44, 00, 89, 3D...
 
[+]

Entropy:
7.1891

Code size:
264 KB (270,336 bytes)

Remove msiexec.exe - Powered by Reason Core Security