ois.exe

The executable ois.exe has been detected as malware by 26 anti-virus scanners.
MD5:
44892b387fe2e92f0fb2ef882bba3809

SHA-1:
5d8e9bbf9009c45a53ca8c5aa9a7fe8a38830d3b

SHA-256:
9b854dfa2c9ffd67791fa2051ddc33a404a93e642c1f5d5cc20741651d44c9a3

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/23/2024 7:19:13 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.3120764
943

Agnitum Outpost
Trojan.Small
7.1.1

AhnLab V3 Security
Win-Trojan/ASD.variant
2013.05.31

Avira AntiVirus
TR/Small.53248.B
7.11.81.234

Baidu Antivirus
Trojan.Win32.Dynamer
4.0.3.1477

Bitdefender
Trojan.Generic.3120764
1.0.20.540

Bkav FE
W32.Clodca1.Trojan
1.3.0.4923

Comodo Security
UnclassifiedMalware
16349

Emsisoft Anti-Malware
Trojan.Generic.3120764
8.14.04.18.09

Fortinet FortiGate
W32/Dx.NKC!tr
7/7/2014

F-Prot
W32/Trojan2.MTDH
v6.4.7.1.166

F-Secure
Trojan.Generic.3120764
11.2014-18-04_6

G Data
Trojan.Generic.3120764
14.4.24

IKARUS anti.virus
Trojan.Small
t3scan.2.0.0.0

K7 AntiVirus
Trojan
13.175.10881

McAfee
Artemis!95A9C14472C6
5600.7157

Microsoft Security Essentials
Trojan:Win32/Dynamer!dtc
1.165.247.01

MicroWorld eScan
Trojan.Generic.3120764
15.0.0.324

Norman
Troj_Generic.LQFE
11.20140418

nProtect
Trojan/W32.Agent.53248.ABW
14.01.17.02

Panda Antivirus
Trj/CI.A
14.07.07.04

Sophos
Ardamax
4.96

Total Defense
Win32/Tnega.BAC
37.0.10498

Trend Micro House Call
TROJ_SMALLTRO.YI
7.2.108

Trend Micro
TROJ_SMALLTRO.YI
10.465.18

VIPRE Antivirus
Trojan.Win32.Generic
25568

File size:
52 KB (53,248 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\thinstall\microsoft office enterprise 2007\300000004500002h\ois.exe

File PE Metadata
Compilation timestamp:
10/28/2006 12:59:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
768:2c595F8eaE9w2/IpNCZga/W155ocNooVr+nY///////////////////////////u:JV809apNwjaXnyoVrWlII4wQiT

Entry address:
0x1F26

Entry point:
9C, 60, 68, 53, 74, 41, 6C, 68, 54, 68, 49, 6E, E8, 00, 00, 00, 00, 58, BB, 37, 1F, 00, 00, 2B, C3, 50, 68, 00, 00, 00, 30, 68, 00, 28, 00, 00, 68, 04, 01, 00, 00, E8, BA, FE, FF, FF, E9, 90, FF, FF, FF, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 83, C4, F4, FC, 53, 57, 56, 8B, 75, 08, 8B, 7D, 0C, C7, 45, FC, 08, 00, 00, 00, 33, DB, BA, 00, 00, 00, 80, 43, 33, C0, E8, 19, 01, 00, 00, 73, 0E, 8B, 4D, F8, E8, 27, 01, 00, 00, 02, 45, F7, AA, EB, E9, E8, 04, 01, 00, 00, 0F, 82, 96, 00, 00, 00, E8, F9, 00, 00, 00...
 
[+]

Entropy:
6.3148

Code size:
6.5 KB (6,656 bytes)

Remove ois.exe - Powered by Reason Core Security