MSIMN.EXE

Операционная система Microsoft Windows

Корпорация Майкрософт

The executable MSIMN.EXE has been detected as malware by 8 anti-virus scanners.
Publisher:
Корпорация Майкрософт

Product:
Операционная система Microsoft® Windows®

Description:
Outlook Express

Version:
6.00.2900.5512 (xpsp.080413-2105)

MD5:
9ab9099fd141d2454c8e49e65f67284a

SHA-1:
e387cc2c3b73f7e277850c9657f7aa9cb6bcb270

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/26/2024 9:13:29 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Zusy.19894
7.11.97.22

avast!
Win32:WrongInf-C [Susp]
2014.9-141222

Bitdefender
Gen:Variant.Zusy.19894
1.0.20.1780

Emsisoft Anti-Malware
Gen:Variant.Zusy.19894
8.14.12.22.06

F-Secure
Gen:Variant.Zusy.19894
11.2014-22-12_2

G Data
Gen:Variant.Zusy.19894
14.12.22

MicroWorld eScan
Gen:Variant.Zusy.19894
15.0.0.1068

VIPRE Antivirus
Trojan.Win32.Generic
20588

File size:
70 KB (71,680 bytes)

Product version:
6.00.2900.5512

Copyright:
© Корпорация Майкрософт, 2004. Все права защищены.

Original file name:
MSIMN.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\outlook express\msimn.exe

File PE Metadata
Compilation timestamp:
4/13/2008 9:31:01 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
1536:qZLnV6vE0/Gzz+c+ZdT1rMMMMM2MMMMMov:cLV6DGP+c+ZdlMMMMM2MMMMMov

Entry address:
0x26D1

Entry point:
E8, 0A, 00, 00, 00, E9, 5D, FF, FF, FF, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, 0C, 40, 00, 01, 85, C0, 74, 07, 3D, 40, BB, 00, 00, 75, 4D, 56, 8D, 45, F8, 50, FF, 15, 64, 10, 00, 01, 8B, 75, FC, 33, 75, F8, FF, 15, 60, 10, 00, 01, 33, F0, FF, 15, 5C, 10, 00, 01, 33, F0, FF, 15, 58, 10, 00, 01, 33, F0, 8D, 45, F0, 50, FF, 15, 54, 10, 00, 01, 8B, 45, F4, 33, 45, F0, 33, C6, 25, FF, FF, 00, 00, 5E, 75, 05, B8, 40, BB, 00, 00, A3, 0C, 40, 00, 01, F7, D0, A3, 08, 40, 00, 01, C9, C3, CC, CC, CC...
 
[+]

Code size:
8.5 KB (8,704 bytes)

Shell Open Command
Open type:
mailto

Command:
"C:\Program Files\outlook express\msimn.exe" \mailurC:%1


Remove MSIMN.EXE - Powered by Reason Core Security