office_2010_activator_1.1.exe

Office 2010 Activator

The application office_2010_activator_1.1.exe has been detected as a potentially unwanted program by 28 anti-malware scanners.
Product:
Office 2010 Activator

Version:
01.10.00.00

MD5:
0515cd8cc5ad2a87801ed6489fd591ae

SHA-1:
399bad525bf67e6c41589f6af56ef894470d2164

SHA-256:
b2fc8074df16663c7eeb03b628ce7f7593f3aa65f5860f49837df0ddab6a5810

Scanner detections:
28 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 11:53:43 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8187727
521

Agnitum Outpost
Trojan.DR.Agent
7.1.1

AhnLab V3 Security
Dropper/Win32.Agent
2014.09.18

Avira AntiVirus
TR/Drop.Agent.cdva.1
7.11.173.16

avast!
Win32:Malware-gen
2014.9-150901

AVG
Crack
2016.0.2999

Baidu Antivirus
Hacktool.Win32.HackKMS
4.0.3.1591

Bitdefender
Trojan.Generic.8187727
1.0.20.1220

Bkav FE
W32.Clodcf7.Trojan
1.3.0.4959

Clam AntiVirus
Trojan.Dropper-26561
0.98/21411

Comodo Security
UnclassifiedMalware
19546

Emsisoft Anti-Malware
Trojan.Generic.8187727
8.15.09.01.03

ESET NOD32
Win32/HackKMS
9.10434

Fortinet FortiGate
W32/Agent.CDVA!tr
9/1/2015

F-Prot
W32/MalwareS.BIWN
v6.4.7.1.166

G Data
Trojan.Generic.8187727
15.9.24

IKARUS anti.virus
Trojan-Dropper.Agent
t3scan.1.7.8.0

K7 AntiVirus
Riskware
13.183.13407

McAfee
Artemis!0515CD8CC5AD
5600.6655

NANO AntiVirus
Trojan.Win32.MalwareS.ctkgcc
0.28.2.62151

Norman
Suspicious_Gen2.PHTZB
11.20150901

nProtect
Trojan-Dropper/W32.Agent.1147392
14.09.17.01

Qihoo 360 Security
Win32/Trojan.673
1.0.0.1015

Quick Heal
Trojan.ZAgent.g9
9.15.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.1273BB26!309574438
23.00.65.15830

Trend Micro House Call
TROJ_SPNR.03IB11
7.2.244

Trend Micro
TROJ_SPNR.03IB11
10.465.01

VIPRE Antivirus
Trojan-Dropper.Win32.Agent
33212

File size:
1.1 MB (1,147,392 bytes)

Product version:
01.10.00.00

Copyright:
quangnhut123

Trademarks:
quangnhut123

Original file name:
Office_2010_Activator_by_quangnhut123.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
10/30/2009 5:26:13 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.25

CTPH (ssdeep):
12288:x0HpjrL4SLf95zB3nfrJhzohF4Xt2NdvO21fXle:aBrESzhXoz4X6229Ve

Entry address:
0x152C8

Entry point:
55, 8B, EC, B9, 09, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, A1, 0C, 6C, 41, 00, C6, 00, 01, B8, 00, 4E, 41, 00, E8, 2C, 0C, FF, FF, 33, C0, 55, 68, 3C, 58, 41, 00, 64, FF, 30, 64, 89, 20, A1, 98, 6A, 41, 00, 33, D2, 89, 10, 8D, 45, E8, E8, 1D, E2, FF, FF, 8B, 55, E8, B8, C4, CA, 41, 00, E8, 24, F0, FE, FF, 8D, 55, E4, A1, C4, CA, 41, 00, E8, 17, E1, FF, FF, 8B, 55, E4, B8, C4, CA, 41, 00, E8, 0A, F0, FE, FF, 8D, 45, E0, E8, 2E, FA, FF, FF, 8B, 55, E0, B8, D0, CA, 41, 00, E8, F5, EF, FE, FF, A1...
 
[+]

Entropy:
6.6604

Developed / compiled with:
Microsoft Visual C++

Code size:
82.5 KB (84,480 bytes)

Remove office_2010_activator_1.1.exe - Powered by Reason Core Security