msrtn32.exe

The executable msrtn32.exe, “Wmi provider host” has been detected as malware by 24 anti-virus scanners.
Description:
Wmi provider host

Version:
6.2.0.2

MD5:
4b074765e8a82bbfb344d12d62bef3ed

SHA-1:
3fd4930d01aecb0818efd71f6b0636041a9242e4

SHA-256:
1485b1d1530e82d7fb769adb8ea47de5e2db6cfde90fd80e57bd484985d42d00

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/23/2024 7:37:38 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11701761
701

avast!
Win32:Malware-gen
2014.9-150305

AVG
Clicker
2016.0.3179

Baidu Antivirus
Trojan.Win32.Clamtext
4.0.3.1535

Bitdefender
Trojan.Generic.11701761
1.0.20.320

Comodo Security
UnclassifiedMalware
21156

Emsisoft Anti-Malware
Trojan.Generic.11701761
8.15.03.05.09

ESET NOD32
Win32/TrojanClicker.Clamtext
9.11210

F-Secure
Trojan.Generic.11701761
11.2015-05-03_5

G Data
Trojan.Generic.11701761
15.3.25

IKARUS anti.virus
Trojan.Win32.TrojanClicker
t3scan.1.8.6.0

K7 AntiVirus
Spyware
13.197.15040

Malwarebytes
Trojan.FakeMS
v2015.03.05.09

McAfee
Artemis!4B074765E8A8
5600.6835

Microsoft Security Essentials
TrojanClicker:Win32/Clamtext.A
1.1.11400.0

MicroWorld eScan
Trojan.Generic.11701761
16.0.0.192

Norman
Troj_Generic.WFTOG
11.20150305

nProtect
Trojan.Generic.11701761
15.02.17.01

Panda Antivirus
Trj/CI.A
15.03.05.09

Quick Heal
TrojanClicker.Clamtext.g6
3.15.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R0C1C0DJH14
7.2.64

Trend Micro
TROJ_GEN.R0C1C0DJH14
10.465.05

VIPRE Antivirus
Trojan.Win32.Clicker
37752

File size:
2.3 MB (2,405,376 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\msrtn32\msrtn32.exe

File PE Metadata
Compilation timestamp:
7/7/2014 1:08:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:FnI7rU3a0TlAPtbiUtFyDJQHtjdY4neclCOjSjaZb6aySlF7R6oNiynKkwu:Fnh7OjSj616oNCkwu

Entry address:
0x11F520

Entry point:
E8, 55, 04, 00, 00, E9, 1C, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 60, D2, 61, 00, 89, 0D, 5C, D2, 61, 00, 89, 15, 58, D2, 61, 00, 89, 1D, 54, D2, 61, 00, 89, 35, 50, D2, 61, 00, 89, 3D, 4C, D2, 61, 00, 66, 8C, 15, 78, D2, 61, 00, 66, 8C, 0D, 6C, D2, 61, 00, 66, 8C, 1D, 48, D2, 61, 00, 66, 8C, 05, 44, D2, 61, 00, 66, 8C, 25, 40, D2, 61, 00, 66, 8C, 2D, 3C, D2, 61, 00, 9C, 8F, 05, 70, D2, 61, 00, 8B, 45, 00, A3, 64, D2, 61, 00, 8B, 45, 04, A3, 68, D2, 61, 00, 8D, 45, 08, A3, 74, D2, 61...
 
[+]

Entropy:
5.7592

Code size:
1.4 MB (1,461,248 bytes)

Remove msrtn32.exe - Powered by Reason Core Security