nmtdoe.exe

The executable nmtdoe.exe has been detected as malware by 34 anti-virus scanners.
MD5:
5d64522db7de2be2290dcbc91120ceb2

SHA-1:
40e15132b58e3a1a3cc4b92290994e89bf73a7cc

SHA-256:
655e28863078a79a9b740ab7b8ffc6d0773320ed913f975c4fcbedb8c9468a16

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
4/26/2024 9:08:33 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Generic.ServStart.75D120FE
524

AhnLab V3 Security
Trojan/Win32.Agent
2015.04.22

Avira AntiVirus
WORM/Rbot.Gen
3.6.1.96

avast!
Win32:Nitol-B [Trj]
2014.9-150830

AVG
Rozena
2016.0.3002

Baidu Antivirus
Trojan.Win32.ServStart
4.0.3.15830

Bitdefender
Generic.ServStart.75D120FE
1.0.20.1210

Clam AntiVirus
Win.Trojan.Agent-831085
0.98/21511

Dr.Web
Trojan.DownLoader11.51152
9.0.1.0242

Emsisoft Anti-Malware
Generic.ServStart.75D120FE
8.15.08.30.02

ESET NOD32
Win32/ServStart.EN (variant)
9.11515

Fortinet FortiGate
W32/Agent.QUB!tr
8/30/2015

F-Prot
W32/QQhelper.C.gen
v6.4.7.1.166

F-Secure
Generic.ServStart.75D120FE
11.2015-30-08_1

G Data
Generic.ServStart.75D120FE
15.8.25

IKARUS anti.virus
Trojan.Win32.ServStart
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.203.15671

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1505

Malwarebytes
Trojan.Agent.FVA
v2015.08.30.02

McAfee
Trojan-FGAW!5D64522DB7DE
5600.6658

Microsoft Security Essentials
TrojanDownloader:Win32/Yemrok.A
1.1.11602.0

MicroWorld eScan
Generic.ServStart.75D120FE
16.0.0.726

NANO AntiVirus
Trojan.Win32.Rbot.dkhudw
0.30.20.1219

Norman
Nitol.A
11.20150830

nProtect
Generic.ServStart.75D120FE
15.04.22.01

Panda Antivirus
Trj/CI.A
15.08.30.02

Quick Heal
Trojan.ServStart.A
8.15.14.00

Rising Antivirus
PE:Trojan.Nitol!1.9E17
23.00.65.15828

Sophos
Mal/Behav-116
4.98

Trend Micro House Call
TROJ_GEN.R047C0DDD15
7.2.242

Trend Micro
TROJ_GEN.R047C0DDD15
10.465.30

Vba32 AntiVirus
BScope.Trojan.Win32.Inject.2
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Nitol.b
39576

ViRobot
Trojan.Win32.DDOS-Agent.25600.A[h]
2014.3.20.0

File size:
25 KB (25,600 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\syswow64\nmtdoe.exe

File PE Metadata
Compilation timestamp:
12/9/2014 4:38:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
384:BOFvr0+8BjH6KF2DxEDh4fyBDpOvDWcpqdOQIg0BJNqnWi7UB8sC1oOOuK+wy+S:BM05F2WeKBoQOXis8sCQy+S

Entry address:
0x4FDF

Entry point:
55, 8B, EC, 6A, FF, 68, C8, 65, 40, 00, 68, B0, 4F, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, D4, 60, 40, 00, 59, 83, 0D, 18, 8C, 40, 00, FF, 83, 0D, 1C, 8C, 40, 00, FF, FF, 15, 3C, 61, 40, 00, 8B, 0D, 14, 8C, 40, 00, 89, 08, FF, 15, C4, 60, 40, 00, 8B, 0D, 10, 8C, 40, 00, 89, 08, A1, 14, 61, 40, 00, 8B, 00, A3, 20, 8C, 40, 00, E8, 45, 01, 00, 00, 39, 1D, C8, 8B, 40, 00, 75, 0C, 68, 90, 51, 40, 00, FF, 15, 38, 61...
 
[+]

Entropy:
5.8637

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
16.5 KB (16,896 bytes)

Remove nmtdoe.exe - Powered by Reason Core Security