sfx.exe

My Autoplay SFX Creator

Arafasoft

The executable sfx.exe, “My Autoplay SFX Creator to create self-extracting archives” has been detected as malware by 4 anti-virus scanners.
Publisher:
Arafasoft

Product:
My Autoplay SFX Creator

Description:
My Autoplay SFX Creator to create self-extracting archives

Version:
1.00

MD5:
b32349c1b7019abcfa6fd681428ab4d0

SHA-1:
3fffcc003914a4d50b936ea55a0f06094f9e8bb6

SHA-256:
1520c4d3c7307d9469f9e9de57dd5fe80ae6ecb8fa098d302bb9fb186a52ff36

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
12/20/2025 11:42:06 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/VB.Downloader.Gen8
7.11.71.168

Comodo Security
UnclassifiedMalware
15883

Emsisoft Anti-Malware
Trojan.Win32.RiskWare.VBCrypt.AMN
8.14.04.01.12

ESET NOD32
Win32/RiskWare.VBCrypt (variant)
8.8213

File size:
424 KB (434,176 bytes)

Product version:
1.00

Copyright:
Arafasoft©2008

Trademarks:
Arafasoft©2008

Original file name:
My Autoplay SFX Creator.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\arafasoft\my autoplay 10 pro\sfx.exe

File PE Metadata
Compilation timestamp:
3/14/2013 5:16:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:qQ+XZTQ31IGjPuzUeWls04v+I8HEon4Y5+yM2:qZa31XfeWls04v+I8HEon4Y5+yM2

Entry address:
0x1254

Entry point:
68, B8, 50, 42, 00, E8, EE, FF, FF, FF, 00, 00, 88, 00, 00, 00, 30, 00, 00, 00, 80, 00, 00, 00, 40, 00, 00, 00, AD, 2D, 92, DB, 3C, 04, 29, 4E, B3, 31, 0A, 04, F7, BA, FA, AF, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 90, 1B, F0, 05, 4D, 79, 41, 75, 74, 6F, 70, 6C, 61, 79, 53, 46, 58, 00, 41, 00, 4D, 79, 20, 41, 75, 74, 6F, 70, 6C, 61, 79, 20, 53, 46, 58, 20, 43, 72, 65, 61, 74, 6F, 72, 20, 74, 6F, 20, 63, 72, 65, 61, 74, 65, 20, 73, 65, 6C, 66, 2D, 65, 78, 74, 72, 61, 63, 74, 69, 6E, 67, 20, 61, 72...
 
[+]

Entropy:
5.0135

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
412 KB (421,888 bytes)

Remove sfx.exe - Powered by Reason Core Security