recom.exe

The application recom.exe has been detected as a potentially unwanted program by 28 anti-malware scanners.
MD5:
6b0a555c59e47e270932723308c118b0

SHA-1:
003cfdc04581a373e95765d8091777ed57507105

SHA-256:
82251a8d247bfd79c46c3f2a46e14347eb546aa8e242093d95cb4477c82b278e

Scanner detections:
28 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 7:31:02 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12070677
801

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.IntClient
2014.11.24

Avira AntiVirus
TR/Drop.Agent.459264.1
7.11.188.94

avast!
Win32:Dropper-gen [Drp]
2014.9-141126

AVG
Pakes2_c
2015.0.3279

Baidu Antivirus
Trojan.Win32.Downloader
4.0.3.141126

Bitdefender
Trojan.Generic.12070677
1.0.20.1650

Emsisoft Anti-Malware
Trojan.Generic.12070677
8.14.11.26.09

ESET NOD32
Generik.CCURSXI (variant)
8.10770

Fortinet FortiGate
W32/Agent.AANRB!tr.dldr
11/26/2014

F-Prot
W32/Busky.B.gen
v6.4.7.1.166

F-Secure
Trojan.Generic.12070677
11.2014-26-11_4

G Data
Trojan.Generic.12070677
14.11.24

IKARUS anti.virus
Trojan-Downloader.Win32.Agent
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.185.14113

Kaspersky
Trojan-Downloader.Win32.Agent
14.0.0.2888

McAfee
RDN/Downloader.a!ts
5600.6935

MicroWorld eScan
Trojan.Generic.12070677
15.0.0.990

Norman
Agent.BKPQP
11.20141126

nProtect
Trojan.Generic.12070677
14.11.21.01

Panda Antivirus
Trj/Chgt.J
14.11.26.09

Quick Heal
TrojanDownloader.Agent.r3
11.14.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.1791BE32!395427378
23.00.65.141124

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNV.01KA14
7.2.330

Trend Micro
TROJ_SPNV.01KA14
10.465.26

VIPRE Antivirus
Trojan.Win32.Generic
35082

File size:
448.5 KB (459,264 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\temp\recom.exe

File PE Metadata
Compilation timestamp:
5/1/2014 6:05:47 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:skoTPfYgjEJjiqZxPWTaxtp155NKCELzClH5QMdsAZmfG1nfHos/GN:cnajNqOR15rSLzC0Md5cfaf9/

Entry address:
0x220340

Entry point:
60, BE, 00, C0, 5B, 00, 8D, BE, 00, 50, E4, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8553

Packer / compiler:
UPX 2.90LZMA

Code size:
404 KB (413,696 bytes)

Remove recom.exe - Powered by Reason Core Security