r8.exe

The application r8.exe has been detected as a potentially unwanted program by 30 anti-malware scanners.
MD5:
bb5c67e1e1ecd1f38e08f1e6c52d3db2

SHA-1:
07bfe69b13d3a580fbf96ba354faa5349cda534a

SHA-256:
9aa6dc3721c2e0e8a86f7103f3c5fece3f5355ced93326c3241552976df6dcf9

Scanner detections:
30 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 11:00:00 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Strictor.61989
856

AhnLab V3 Security
Trojan/Win32.Preloader
2014.09.19

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

avast!
Win32:Adware-gen [Adw]
2014.9-141002

AVG
Generic5
2015.0.3334

Baidu Antivirus
Adware.Win32.MultiPlug
4.0.3.14102

Bitdefender
Gen:Variant.Adware.Strictor.61989
1.0.20.1375

Comodo Security
ApplicUnwnt
19547

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.61989
8.14.10.02.09

ESET NOD32
Win32/AdWare.MultiPlug.BN (variant)
8.10438

Fortinet FortiGate
Riskware/MultiPlug
10/2/2014

F-Secure
Gen:Variant.Adware.Strictor.61989
11.2014-02-10_5

G Data
Gen:Variant.Adware.Strictor.61989
14.10.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.7.8.0

K7 AntiVirus
Adware
13.183.13417

Malwarebytes
PUP.Optional.MultiPlug
v2014.10.02.09

McAfee
RDN/Generic PUP.x!cmw
5600.6990

MicroWorld eScan
Gen:Variant.Adware.Strictor.61989
15.0.0.825

NANO AntiVirus
Trojan.Win32.EPACK.deocbi
0.28.2.62151

Norman
Suspicious_Gen5.AURZR
11.20141002

Panda Antivirus
Trj/Genetic.gen
14.10.02.09

Qihoo 360 Security
Win32/Trojan.b92
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.10.2.9

Rising Antivirus
PE:Trojan.Win32.Generic.1741A73F!390178623
23.00.65.14930

Sophos
Generic PUA LB
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10324

Trend Micro House Call
TROJ_GEN.R02KC0PIE14
7.2.275

Trend Micro
TROJ_GEN.R02KC0PIE14
10.465.02

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
33230

File size:
639.5 KB (654,848 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\application data\dealssfiindeerprro\r8.exe

File PE Metadata
Compilation timestamp:
9/8/2014 2:04:53 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:hcT7FuXkgpqJHoXmo9ytond5ACWmIHKrLlfjM/738l4hYJJ:hi7+kLJIX99ytQ3AHULlfjM/73ne

Entry address:
0x3466

Entry point:
6A, 5C, 68, 38, C6, 45, 00, E8, C8, 02, 00, 00, 89, 5D, DC, 89, 55, D8, 81, 7D, DC, DE, C0, AD, BA, 75, 09, FF, 75, D8, E8, 08, 04, 00, 00, 59, 33, FF, 89, 7D, 94, 6A, 40, 57, 8D, 45, 98, 50, E8, F2, DB, FF, FF, 83, C4, 0C, 89, 7D, FC, 8D, 45, 94, 50, FF, 15, 60, F1, 44, 00, FF, 15, 64, F1, 44, 00, 8B, F0, 89, 75, E0, 85, F6, 75, 08, BE, 54, F7, 44, 00, 89, 75, E0, B0, 20, 88, 45, E7, 8A, 0E, 84, C9, 74, 0A, 3A, C8, 7F, 06, 46, 89, 75, E0, EB, F0, 8A, 0E, 3A, C8, 7E, 14, 80, F9, 22, 75, 09, 0F, BE, C0, 83...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
308.5 KB (315,904 bytes)

Remove r8.exe - Powered by Reason Core Security