plugin.exe

The executable plugin.exe has been detected as malware by 7 anti-virus scanners.
Version:
1.0.5874.24596

MD5:
8e1bbe7cd6affb0c8ddd871ff1e9449c

SHA-1:
eb19de185d2a1175aab8b925e2117911c461f392

SHA-256:
481bf8405edb67ef4cb94f2d62aa73cef82826a3ba49f532fc42bc6a5ed35432

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/26/2024 6:13:51 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160118-1

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5053.0

Norman
Win32.Sality.3
11.01.2016 17:30:26

VIPRE Antivirus
Threat.4721115
46838

File size:
601.7 KB (616,160 bytes)

Product version:
1.0.5874.24596

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Application data\4f596ec3-77fb-4fc3-82cb-691c42c71d77\plugins\7\plugin.exe

File PE Metadata
Compilation timestamp:
1/31/2016 1:40:04 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:OwnN3RSYg4uF0HoJL0IY/NrpszKmOif5Y6dOZCFw0kpBFJKH:VNBSYgt0HoJL0IY/NrMKliTAZT0kpzQH

Entry address:
0x35D5D

Entry point:
60, 0F, B7, FD, 68, B4, DF, A7, 00, 68, 7D, 9E, 12, 00, 71, 01, F2, 81, FF, 19, 7F, 19, 8D, 8B, C0, 69, D8, 04, 6A, 4E, 82, 80, EC, 00, 71, 08, BA, AF, 6B, 70, 7F, 49, 84, D2, 02, EC, 88, CB, E8, 22, 00, 00, 00, 4A, 80, EA, E8, 71, 11, 69, EB, E7, AE, 02, 43, BF, AF, 4D, 6E, 98, 8D, 35, CD, 1D, B3, 9D, C7, C1, EF, 0A, 3D, 9B, 3D, EC, 4F, 00, 00, EB, 0A, 69, C1, 37, B2, 03, AD, 89, DE, B1, 05, FE, C7, FF, CD, 8A, C9, 69, F5, A6, 60, 99, 7E, 38, CF, 0F, AF, C1, B4, CD, 8D, 35, 33, 3A, AD, F1, 3D, 9F, DE, 0C...
 
[+]

Entropy:
6.9103

Code size:
416 KB (425,984 bytes)

Remove plugin.exe - Powered by Reason Core Security