removewat v2.2.5.exe

RemoveWAT

Hazar & Co.

The application removewat v2.2.5.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. The file has been seen being downloaded from dc616.4shared.com.
Publisher:
Hazar & Co.

Product:
RemoveWAT

Version:
2.2.5.0

MD5:
61f9b51e2ed6dc33b92cfb7df6beb6ed

SHA-1:
a0d8a7ff93ac6bfaacebc4ee2b8d9655d8b7b927

SHA-256:
ed54497d4515369c5a805b4ed5bfae608b688724d72f580c48c61482dd78ab76

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 6:01:37 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
HackTool.Wpakill
7.1.1

avast!
Win32:PUP-gen [PUP]
2014.9-141226

Baidu Antivirus
Hacktool.Win32.Wpakill
4.0.3.141226

IKARUS anti.virus
HackTool.Win32.Wpakill
t3scan.1.8.3.0

K7 AntiVirus
Riskware
13.186.14210

Malwarebytes
HackTool.Wpakill
v2014.12.26.10

Microsoft Security Essentials
HackTool:Win32/Wpakill.B
1.11202

Norman
Suspicious_Gen2.KFAML
11.20141226

Reason Heuristics
PUP.Win.Reputation
15.6.19.11

Sophos
RemoveWAT
4.98

SUPERAntiSpyware
Hacktool.WPAKill
10154

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
35358

File size:
6.4 MB (6,663,680 bytes)

Product version:
2.2.5.0

Copyright:
Copyright Hazar & Co. © 2010

Original file name:
RemoveWAT.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\removewat v2.2.5.exe

File PE Metadata
Compilation timestamp:
2/26/2010 9:57:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:033yKMaL/eXV1i/kDxkmcL/eXV1i/kaRWYL/eXV1i/kmeM1qj4iwiANvSo2/CAyT:6yKnZrrLGA3PhsKPkG09WP

Entry address:
0x64349E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.1466

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
6.3 MB (6,559,232 bytes)

The file removewat v2.2.5.exe has been seen being distributed by the following URL.

Remove removewat v2.2.5.exe - Powered by Reason Core Security