restartf5.exe

Project1

The executable restartf5.exe has been detected as malware by 5 anti-virus scanners.
Publisher:
Microsoft*  (Invalid match)

Product:
Project1

Version:
1.00

MD5:
824e193d824972619dd224eca78625c9

SHA-1:
7920c107f293e28497866d9b313a5246ae805853

SHA-256:
bc9bee6350f473ab2d286ae7ab5ca623f1bac82f50f8ae815f94adffa643bf78

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
4/24/2024 1:40:39 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Spy.28672.1903
7.11.146.2

Bkav FE
W32.Clod099.Trojan
1.3.0.4959

Comodo Security
UnclassifiedMalware
18186

IKARUS anti.virus
Trojan-Spy.28672
t3scan.1.6.1.0

K7 AntiVirus
EmailWorm
13.176.11913

File size:
28 KB (28,672 bytes)

Product version:
1.00

Original file name:
restartf5.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\f5\restartf5.exe

File PE Metadata
Compilation timestamp:
5/5/2013 5:25:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
96:eS/mcW6FCZUZ1FCxBTRwV3yRXWDO0plDl+uw4F2IT9uW5BEF:FKxtAqXWfqK2xW/E

Entry address:
0x120C

Entry point:
68, 8C, 22, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 69, 06, ED, 77, 78, 50, 8E, 4A, 9B, 27, 8B, 1D, 2D, F6, 90, 17, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 69, 04, 69, 00, 00, 00, 50, 72, 6F, 6A, 65, 63, 74, 31, 00, 08, 41, 00, F0, 07, 41, 00, 00, 00, 00, 00, FF, CC, 31, 00, 02, B9, 7F, 99, E0, 98, 86, EB, 42, 83, D6, 4B, 7A, D7, 0D, B4, 59, FE, 08, C3, 02, D2, 8F, 5C, 45, AC, 35, DB, 8F, 9E, B1, EC, 22, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
2.0779

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
12 KB (12,288 bytes)

Remove restartf5.exe - Powered by Reason Core Security