mtkdroidtools.exe

The executable mtkdroidtools.exe has been detected as malware by 39 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
7ef5eac7549d5f214e6ed9236905db18

SHA-1:
126f0a8293856db1bf52775f8c7c1272d1e474da

SHA-256:
fa4bf248497c8ef9dda96f1287b43dd0b55bdba44e4cc03002a7e94cdee1ee72

Scanner detections:
39 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/24/2024 1:22:50 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Ramnit.N
5734772

Agnitum Outpost
Win32.Nimnul.Gen.2
7.1.1

AhnLab V3 Security
Win32/Ramnit.G
2015.10.09

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

Arcabit
Win32.Ramnit.N
1.0.0.582

avast!
Win32:RmnDrp
150913-1

AVG
Win32/Zbot.F
2015.0.4409

Baidu Antivirus
Virus.Win32.Nimnul.$a
4.0.3.15109

Bitdefender
Win32.Ramnit.N
1.0.20.1410

Bkav FE
W32.InjectAdwaredDwnA1.PE
1.3.0.7237

Clam AntiVirus
W32.Ramnit-1
0.98/20957

Comodo Security
Virus.Win32.Ramnit.K
23382

Dr.Web
Win32.Rmnet.12
9.0.1.05190

Emsisoft Anti-Malware
Win32.Ramnit.N
10.0.0.5366

ESET NOD32
Win32/Ramnit.H virus
7.0.302.0

Fortinet FortiGate
W32/Ramnit.C
10/9/2015

F-Prot
W32/Ramnit.E
4.6.5.141

F-Secure
Win32.Ramnit.N
5.14.151

G Data
Win32.Ramnit
15.10.25

IKARUS anti.virus
Virus.Win32.Ramnit
t3scan.1.9.5.0

K7 AntiVirus
Virus
13.210.17479

Kaspersky
Virus.Win32.Nimnul
15.0.0.543

McAfee
Trojan.Artemis!9830634B3BA8
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.207.2059.0

MicroWorld eScan
Win32.Ramnit.N
16.0.0.846

NANO AntiVirus
Virus.Win32.Nimnul.bqjjnb
0.30.26.3947

Norman
Win32.Ramnit.N
03.12.2014 13:20:04

nProtect
Virus/W32.SpyEye
15.10.08.01

Panda Antivirus
W32/Cosmu.E
15.10.09.10

Quick Heal
W32.Ramnit.BA
10.15.14.00

Rising Antivirus
PE:Trojan.Injector!1.9DEE[F1]
23.00.65.151007

Sophos
Virus 'W32/Ramnit-A'
5.15

Total Defense
Win32/Ramnit.C
37.1.62.1

Trend Micro House Call
PE_RAMNIT.DEN
7.2.282

Trend Micro
PE_RAMNIT.DEN
10.465.09

Vba32 AntiVirus
Virus.Win32.Nimnul.b
3.12.26.4

VIPRE Antivirus
Threat.4732184
42326

ViRobot
Win32.Nimnul.A[h]
2014.3.20.0

Zillya! Antivirus
Virus.Nimnul.Win32.1
2.0.0.2435

File size:
778.9 KB (797,634 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\compressed\mtkdroidtools v2.5.3\mtkdroidtools.exe

File PE Metadata
Compilation timestamp:
1/19/2014 5:10:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
6144:vB7SMKLEu6obGokwsKFm8RgLu0duqusboZE5xcHhTu0f4riUOXEywd0SEltoe54j:vJFKLwoSoUKFm8Rn0df1o+UCiUC5NfnK

Entry address:
0x7C000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 8B, C5, 81, ED, A8, A6, 01, 20, 2B, 85, 0F, AE, 01, 20, 89, 85, 0B, AE, 01, 20, B0, 00, 86, 85, 40, B0, 01, 20, 3C, 01, 0F, 85, BC, 01, 00, 00, 83, BD, 3B, AF, 01, 20, 00, 74, 33, 83, BD, 3F, AF, 01, 20, 00, 74, 2A, 8B, 85, 0B, AE, 01, 20, 2B, 85, 3B, AF, 01, 20, 8B, 00, 89, 85, 78, AF, 01, 20, 8B, 85, 0B, AE, 01, 20, 2B, 85, 3F, AF, 01, 20, 8B, 00, 89, 85, 7C, AF, 01, 20, EB, 61, 83, BD, 43, AF, 01, 20, 00, 74, 58, 8B, 85, 0B, AE, 01, 20, 2B, 85, 43, AF, 01, 20, FF, 30, 8D, 85...
 
[+]

Entropy:
6.9508

Packer / compiler:
ASPack v1.08.04

Code size:
365 KB (373,760 bytes)

Remove mtkdroidtools.exe - Powered by Reason Core Security