nsivmobi.exe

The executable nsivmobi.exe has been detected as malware by 31 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ajdnitlf’. According to AVG, this software downloads additional adware offers during setup.
Description:
Explorer

Version:
1.0

MD5:
759780bacc0e568d4b0c780a2a7b0c27

SHA-1:
8070130785ccf287ad6a91ee35ee0e4a0c21513c

SHA-256:
bd73624942eeb9712f4113f29836a0bfb33b565648a59e728e91a4179de5e3ae

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/23/2024 10:12:21 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1803984
889

Agnitum Outpost
Trojan.DL.Zortob
7.1.1

AhnLab V3 Security
Trojan/Win32.Agent
2014.08.26

Avira AntiVirus
TR/Crypt.ZPACK.67381
7.11.169.78

avast!
Win32:Malware-gen
2014.9-140829

AVG
Downloader.Generic13
2015.0.3367

Baidu Antivirus
Trojan.Win32.Yakes
4.0.3.14829

Bitdefender
Trojan.GenericKD.1803984
1.0.20.1205

Dr.Web
BackDoor.Kuluoz.66
9.0.1.0241

Emsisoft Anti-Malware
Trojan.GenericKD.1803984
8.14.08.29.02

ESET NOD32
Win32/TrojanDownloader.Zortob
8.10316

Fortinet FortiGate
W32/Yakes.F!tr
8/29/2014

F-Secure
Trojan.GenericKD.1803984
11.2014-29-08_6

G Data
Trojan.GenericKD.1803984
14.8.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.7.5.0

K7 AntiVirus
Trojan-Downloader
13.183.13160

Kaspersky
Trojan.Win32.Yakes
14.0.0.3332

Malwarebytes
Trojan.Yakes
v2014.08.29.02

McAfee
RDN/Downloader.a!so
5600.7023

Microsoft Security Essentials
TrojanDownloader:Win32/Kuluoz.D
1.10904

MicroWorld eScan
Trojan.GenericKD.1803984
15.0.0.723

NANO AntiVirus
Trojan.Win32.Kuluoz.ddtgre
0.28.2.61861

nProtect
Trojan.GenericKD.1803984
14.08.25.01

Panda Antivirus
Trj/Genetic.gen
14.08.29.02

Qihoo 360 Security
Win32/Trojan.577
1.0.0.1015

Quick Heal
Trojan.Agen.r5
8.14.14.00

Sophos
Troj/Agent-AIIK
4.98

Trend Micro House Call
TROJ_SPNR.11HH14
7.2.241

Trend Micro
TROJ_SPNR.11HH14
10.465.29

VIPRE Antivirus
Trojan.Win32.Generic
32554

Zillya! Antivirus
Trojan.Yakes.Win32.22919
2.0.0.1901

File size:
156 KB (159,744 bytes)

Product version:
1.0

Copyright:
No rights reserved.

Original file name:
MINIPAD.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\nsivmobi.exe

File PE Metadata
Compilation timestamp:
8/12/2014 1:28:21 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.71

CTPH (ssdeep):
3072:0jEqYYe8q+doOTxRjQch6JfszFJu1rlx1AKCv4u1AKCv4Bj:WEt+dxxme6JfuFKneKCvPeKCvQ

Entry address:
0x2278

Entry point:
55, 89, E5, 83, EC, 24, C7, 45, E0, 00, 00, 00, 00, C7, 45, E4, 00, 00, 00, 00, 6A, 00, FF, 15, 34, 1F, 40, 00, 6A, 00, FF, 15, 50, 1F, 40, 00, 8B, 45, FC, 81, 3D, 38, 1A, 40, 00, 67, C0, 11, 00, 0F, 84, 5D, 01, 00, 00, 81, 3D, 38, 1A, 40, 00, A9, AB, 51, 00, 74, 51, C7, 45, FC, 03, 00, 00, 00, B8, 00, 00, 00, 00, 6A, 00, FF, 75, E8, FF, 15, F4, 1E, 40, 00, FF, 15, 0C, 1F, 40, 00, 83, F8, 57, 0F, 85, 94, 01, 00, 00, C7, 05, 38, 1A, 40, 00, A9, AB, 51, 00, 68, 3C, 1A, 40, 00, 64, FF, 35, 00, 00, 00, 00, 64...
 
[+]

Entropy:
7.0478

Code size:
144.5 KB (147,968 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ajdnitlf

Command:
"C:\users\{user}\appdata\local\nsivmobi.exe"


Remove nsivmobi.exe - Powered by Reason Core Security