nggqmb.exe

MD5:
7d6b1fd0c666aa3f586c9726abc77740

SHA-1:
0d2277d2ebae8e3aeeda4c78f28dface2e5c02be

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 5:58:31 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Sality virus
6.3.12010.0

File size:
100.7 KB (103,140 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Application data\s-1-5-31-1286970278978-5713669491-166975984-320\rotinom\nggqmb.exe

File PE Metadata
Compilation timestamp:
2/10/2002 8:15:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1040

Entry point:
60, E8, 00, 00, 00, 00, 5A, 81, C2, 14, 02, 00, 00, 52, EB, 0B, 88, C1, 0F, BF, CF, C7, C6, 30, 6D, A0, A6, C3, C3, 90, 90, 90, 9C, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BA, 10, 00, 00, 00, 10, 00, 00, A4, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, 10, 00, 00, 08, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AC, 10, 00, 00, 00, 00, 00, 00, C8, 10, 00, 00, 00, 00, 00, 00, 7D, 00, 45, 78, 69, 74, 50, 72, 6F, 63, 65, 73, 73, 00, 4B, 45, 52, 4E, 45, 4C...
 
[+]

Entropy:
7.9511

Packer / compiler:
ASPack v1.08.04

Code size:
512 Bytes (512 bytes)

Scan nggqmb.exe - Powered by Reason Core Security