prepreinstaller_win.exe

The executable prepreinstaller_win.exe has been detected as malware by 11 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from d2wg8tiotv43q3.cloudfront.net.
MD5:
742b695927614514d67119a0baedef9e

SHA-1:
d4543d9b09896cd83d0955e20ef77f67c93a4cd7

SHA-256:
d4223169c818ea29e4e7d31db72eb96f61abb6d9e1e921be2ae6994e33e3677a

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 5:30:25 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160119-0

AVG
Win32/Sality
2015.0.4477

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Trojan.RDN/Generic Downloader.x
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.3536.0

Norman
Win32.Sality.3
11.01.2016 17:30:26

Sophos
Virus 'Mal/Sality-D'
5.23

VIPRE Antivirus
Threat.4758034
46732

File size:
300 KB (307,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\prepreinstaller_win.exe

File PE Metadata
Compilation timestamp:
1/19/2016 4:55:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:zU+Ei5k6R6gRKt9O7uKNhT3n+DF+2sP/4QVrDlnbqkh1Y:Q7gRKt9YzG+2sP/4QhDlbqkh1Y

Entry address:
0x1305C

Entry point:
21, C8, 0F, CF, 53, 68, A0, FB, 3B, 00, E8, 00, 00, 00, 00, BF, 63, A9, 62, 05, 2B, D6, C6, C4, 49, 5F, 86, C6, EB, 02, F7, D3, 8D, 2D, B6, 03, 00, 00, FF, C9, 81, F5, AE, 0A, 00, 00, 05, 76, 40, 58, 28, FE, CF, 68, 24, 06, 00, 00, 19, EA, 59, 69, DF, A5, DD, 5B, CB, 81, E9, 75, 04, 00, 00, C7, C2, 88, 41, 65, 57, 88, CC, 81, E9, F5, F8, FF, FF, FF, C8, 81, E9, 0C, 07, 00, 00, 0F, CB, BD, 0E, 64, 9D, 98, 81, F9, 6D, 00, 00, 00, 73, DB, 0F, 6E, E7, 4B, 81, F2, AC, 88, 00, 00, 0F, 7E, E0, 85, CA, 3B, DE, 70...
 
[+]

Entropy:
6.6911

Code size:
107 KB (109,568 bytes)

The file prepreinstaller_win.exe has been seen being distributed by the following URL.

Remove prepreinstaller_win.exe - Powered by Reason Core Security