pci_filerecovery.exe

The executable pci_filerecovery.exe has been detected as malware by 8 anti-virus scanners. The program is a setup application that uses the Nullsoft Scriptable Install System installer, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from download.pcinspector.de.
MD5:
38ebf4f2e64e1b73a7866f0c3f4f8054

SHA-1:
0d9f7e70ad221d78700c640ae1491a506d6a760a

SHA-256:
8984be0a927379d3734da4559b544fa6300b3a9da4051a840a1243f17ff66819

Scanner detections:
8 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 4:14:46 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

AVG
Win32/Sality
2015.0.4604

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
16.07.06

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.469.0

Norman
Win32.Sality.3
19.05.2016 01:04:49

File size:
3.4 MB (3,539,857 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\pci_filerecovery.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:Ga9PjzmUphJoMI0BYP67am52UIveFdRcMMRDaRarxG8M1hoiD:RPuUbJoMDYoam5AeFDHuGPHXD

Entry address:
0x30FA

Entry point:
60, 8B, ED, 86, DB, 3B, D0, 72, 04, B6, 2C, 8B, C0, EB, 06, 0F, AF, E9, 80, E8, CE, 81, FB, 0D, 83, B7, DD, C7, C0, E1, 5D, 48, AB, 86, DC, 88, DE, 81, EF, 77, 17, 00, 00, 48, 85, C3, 81, EF, 75, 27, 00, 00, F2, 76, 06, 0F, BF, E8, 0F, B7, CB, FF, CF, F7, C0, 2F, 77, F0, 38, 29, F7, 32, F8, E8, 00, 00, 00, 00, 59, 8A, DE, 81, FF, 74, E7, 00, 00, 72, 02, 84, C3, EB, 05, 80, E4, 99, 38, EF, 81, C1, B3, 3E, 06, 00, 84, FA, 81, C1, 75, 0E, 00, 00, 76, 04, F3, 0F, AF, C2, FF, C8, 76, 09, 69, FB, B5, B7, 5C, 97...
 
[+]

Code size:
23.5 KB (24,064 bytes)

The file pci_filerecovery.exe has been seen being distributed by the following URL.

Remove pci_filerecovery.exe - Powered by Reason Core Security