pcliente.exe

The executable pcliente.exe has been detected as malware by 14 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Cliente’.
MD5:
901d5c2b7bb14a52701020d06580d1b3

SHA-1:
05f1a8b1b397b9fe408d6b1e66693adf21f195b2

SHA-256:
2b2da9b761e2005dfdfb14c8c36dc1ac66996478da6c79e338eed15141531014

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
4/24/2024 3:30:00 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160213-1

AVG
Win32/Tanatos.B
2015.0.4522

Dr.Web
infected with Trojan.Siggen4.14502
9.0.1.05190

Emsisoft Anti-Malware
Win32.Kashu
10.0.0.5366

ESET NOD32
Win32/Sality.NBC virus
7.0.302.0

F-Prot
W32/Trojan2.YVZ (exact, not disinfectable)
4.6.5.141

F-Secure
Win32.Kashu.A
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.ad
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.6277.0

Norman
Win32.Kashu.A
03.02.2016 07:38:05

Sophos
Virus 'W32/Sality-AM'
5.23

VIPRE Antivirus
Threat.4098350
47188

File size:
754.5 KB (772,608 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:O9AG3WLpQdEN4qHtIdTWpACuuHkppTJzBbWuYYYybcLse5:C3eEt2tIdTWpauE5suYYYybcLT5

Entry address:
0x63F84

Entry point:
60, E8, 00, 00, 00, 00, 2B, D3, D2, EE, 0F, AD, FD, 8D, 1D, E1, 20, 63, 9A, 56, 81, D6, C5, 74, 67, 8E, C1, E1, 04, 0F, A4, F7, 65, 5D, EB, 01, 35, 0F, B7, FD, 69, EF, 43, FA, D5, 44, 33, D1, F3, 0F, BE, EA, F7, C5, 31, 30, 33, 2A, 33, CB, 15, 15, 84, 37, 1E, 85, DA, FF, C6, 03, DA, 85, C3, 0F, AD, FD, 0F, BC, DA, 33, C6, 38, F0, D1, D6, 18, D4, 58, 81, C0, C0, 33, B8, 00, 0F, C1, DA, 81, E1, 07, AE, B9, 98, 0F, AF, DA, 81, E8, 4A, 27, B3, 00, 85, D5, FF, C1, C7, C1, 47, EE, F9, D8, 50, 81, C0, 58, 20, 73...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
396 KB (405,504 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Cliente

Command:
C:\pcliente.exe


Remove pcliente.exe - Powered by Reason Core Security