msiexec2.exe

The executable msiexec2.exe has been detected as malware by 33 anti-virus scanners.
MD5:
bcb69c1bab27f53a0223e255d9b60d87

SHA-1:
53a0d0b7cd0edcc32b9430e74211d289306cb7f4

SHA-256:
7c6c89b7a7c31bcb492a581dfb6c52d09dffca9107b8fd25991c708a0069625f

Scanner detections:
33 / 68

Status:
Malware

Analysis date:
4/23/2024 5:17:01 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Win-Trojan/Agent.33841.B
2013.10.15

Avira AntiVirus
TR/Agent.cpel
7.11.107.160

avast!
Win32:Lyzapo [Drp]
2014.9-141022

AVG
Agent2
2015.0.3314

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.141022

Bitdefender
Trojan.Agent.ANHJ
1.0.20.1475

Clam AntiVirus
Trojan.Agent-119750
0.98/18155

Comodo Security
TrojWare.Win32.Trojan.Agent.Gen
17109

Dr.Web
DDoS.Config.8
9.0.1.0295

Emsisoft Anti-Malware
Trojan.Agent.ANHJ
8.14.10.22.03

ESET NOD32
Win32/Lyzapo
8.8917

Fortinet FortiGate
W32/Agent.CPEL!tr
10/22/2014

F-Prot
W32/Trojan2.MCOD
v6.4.7.1.166

F-Secure
Trojan.Agent.ANHJ
11.2014-22-10_4

G Data
Trojan.Agent.ANHJ
14.10.22

IKARUS anti.virus
Trojan.Win32.Agent
t3scan.2.0.127

K7 AntiVirus
Trojan
13.173.9866

Kaspersky
Trojan.Win32.Agent
14.0.0.3064

McAfee
W32/Mydoom.cf
5600.6970

Microsoft Security Essentials
TrojanDropper:Win32/Lyzapo.A
1.163.1557.0

MicroWorld eScan
Trojan.Agent.ANHJ
15.0.0.885

NANO AntiVirus
Trojan.Win32.Agent.yofs
0.26.0.55366

Norman
MyDoom.EB
11.20141022

nProtect
Trojan/W32.Agent.33841.C
13.10.15.01

Panda Antivirus
W32/MyDoom.HN.worm
14.10.22.03

Sophos
Troj/Dropr-BH
4.93

Total Defense
Win32/Mydoom.BT
37.0.10498

Trend Micro House Call
WORM_MYDOOM.EA
7.2.295

Trend Micro
WORM_MYDOOM.EA
10.465.22

Vba32 AntiVirus
Trojan.Agent
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Agent.cpe
22398

ViRobot
Trojan.Win32.DDoS-Agent.33841
2011.4.7.4223

File size:
33 KB (33,841 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
7/7/2009 1:22:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
192:skSkTE9KoD8+TxWhgdMOS0fIcoJzugQMrQXfaw99kmZBdZDr/vCv0XU9vvnYR3nG:lrTmmYzSykmlR/vJ1oyy5RTXDthKllW

Entry address:
0x1430

Entry point:
55, 8B, EC, 6A, FF, 68, C8, 40, 40, 00, 68, 64, 1F, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 48, 40, 40, 00, 33, D2, 8A, D4, 89, 15, F0, 55, 40, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, EC, 55, 40, 00, C1, E1, 08, 03, CA, 89, 0D, E8, 55, 40, 00, C1, E8, 10, A3, E4, 55, 40, 00, 33, F6, 56, E8, A1, 09, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, E1, 07, 00, 00, FF, 15, 44, 40, 40, 00, A3, D8, 5A, 40, 00, E8...
 
[+]

Entropy:
3.9509

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
12 KB (12,288 bytes)

Remove msiexec2.exe - Powered by Reason Core Security