regsvr.exe

The executable regsvr.exe has been detected as malware by 26 anti-virus scanners.
MD5:
624753faff539d46d61be4e37112161e

SHA-1:
09e6f197bda23d4a4d9a7bb996ef9c405f6de36c

SHA-256:
4b39a3c8717635880d48843fbf30499103053eec2f148bcb761adc894522880d

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/26/2024 3:15:54 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.CSon
2012.04.18

Avira AntiVirus
TR/Autoit.CI.14
7.11.27.230

avast!
AutoIt:AutoRun-B@BC [Wrm]
2014.9-140725

AVG
Autoit
2015.0.3403

Bitdefender
Trojan.Generic.7006156
1.0.20.1030

Clam AntiVirus
Trojan.Siggen-7
0.98/18155

Comodo Security
TrojWare.Win32.Trojan.Autoit.ci0
12096

Dr.Web
Trojan.Click1.37970
9.0.1.0206

Emsisoft Anti-Malware
Virus.AutoIt!IK
8.14.07.25.08

ESET NOD32
Win32/Patched.AF
8.7062

Fortinet FortiGate
W32/PEPatcher.DFT!tr
7/25/2014

F-Prot
W32/Trojan2.FPHM
v6.4.6.5.141

F-Secure
Trojan.Generic.7006156
11.2014-25-07_6

G Data
Trojan.Generic.7006156
14.7.22

IKARUS anti.virus
Virus.AutoIt
t3scan.1.1.118.0

K7 AntiVirus
Trojan
13.138.6681

Kaspersky
Trojan.Win32.Patched
14.0.0.3508

Norman
Sohanad.gen6
11.20140725

nProtect
Trojan.Generic.7006156
12.04.17.01

Panda Antivirus
W32/Sality.AF
14.07.25.08

Quick Heal
Trojan.Patched.BZ
7.14.12.00

Rising Antivirus
Worm.Win32.GPC.a
23.00.65.14723

Sophos
W32/LibHack-A
4.73 TP

Trend Micro House Call
Mal_OtorunN
7.2.206

Trend Micro
Mal_OtorunN
10.465.25

VIPRE Antivirus
Worm.Win32.Nuqel.z
11808

File size:
2.6 MB (2,748,416 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\regsvr.exe

File PE Metadata
Compilation timestamp:
11/25/2007 11:21:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:L3i8X7pt4Oti0BWmKWIBtOcI9SSbA+cubhsBM7xXYs:L3TdtLW5WIj1YSSdFdsBSX

Entry address:
0x313E1

Entry point:
60, 68, F3, 13, 43, 00, FF, 15, 64, 5F, 4A, 00, 61, E9, 0E, 3C, 07, 00, 64, 75, 72, 6E, 65, 77, 33, 32, 2E, 64, 61, 74, 00, 20, 43, B3, BA, 19, 11, AB, 00, 28, 47, E3, B8, F7, 16, AD, 7B, DB, AF, 41, 4E, D0, 84, 04, 20, 22, 43, 64, 9B, 3A, 04, 9B, 35, 9B, 3A, 88, 28, 6C, DD, D9, 26, A6, F5, BB, D2, 12, 34, 54, AD, 6A, B5, 6D, 78, 7A, AF, 2D, 78, D6, DA, 56, B5, AD, B5, E3, 6D, 6B, 5A, AD, 6B, A5, 7D, AF, 4A, F1, B6, BC, 79, 6B, EB, 6F, 1B, 6B, 5A, F1, E3, 55, B5, 2D, AD, 6B, 5A, D4, DF, 06, C7, 77, 41, 64...
 
[+]

Remove regsvr.exe - Powered by Reason Core Security