skype_idg_downloader_37337_pc.exe

The application skype_idg_downloader_37337_pc.exe has been detected as a potentially unwanted program by 35 anti-malware scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from www.idg.pl.
Version:
2.2.3.1

MD5:
42126c2c88fda29ee9c5a654160c66f8

SHA-1:
f98581d37f6b3069138ba738ed601c9045fed52e

SHA-256:
98861c024c458597c3d598a51ea86585eaa849e49ca395151f478f4035b979f7

Scanner detections:
35 / 68

Status:
Potentially unwanted

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/16/2024 8:24:02 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
6544504

Agnitum Outpost
Win32.Sality.BL
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2015.03.19

Avira AntiVirus
W32/Sality.AT
7.11.218.102

avast!
Win32:SaliCode
150319-1

AVG
Win32/Sality
2014.0.4257

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.15318

Bitdefender
Win32.Sality.3
1.0.20.385

Bkav FE
W32.Sality.PE
1.3.0.6379

Comodo Security
Virus.Win32.Sality.gen
21457

Dr.Web
Win32.Sector.22
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
9.0.0.4799

ESET NOD32
Win32/Sality.NBA
9.11342

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.13.68

G Data
Win32.Sality
15.3.25

IKARUS anti.virus
AdWare.Gen2
t3scan.1.8.6.0

K7 AntiVirus
Virus
13.201.15304

Kaspersky
Virus.Win32.Sality
15.0.0.543

McAfee
Program.Artemis!BA6AF0B0FC0B
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.193.2708.0

MicroWorld eScan
Win32.Sality.3
16.0.0.231

NANO AntiVirus
Virus.Win32.Sality.beygb
0.30.8.659

Norman
Win32.Sality.3
03.12.2014 13:20:04

nProtect
Virus/W32.Sality.D
15.03.18.01

Panda Antivirus
W32/Sality.AA
15.03.18.11

Quick Heal
W32.Sality.U
3.15.14.00

Rising Antivirus
PE:Win32.KUKU.kt!1591113
23.00.65.15316

Total Defense
Win32/Sality.AA
37.0.11503

Trend Micro House Call
PE_SALITY.RL
7.2.77

Trend Micro
PE_SALITY.RL
10.465.18

Vba32 AntiVirus
Virus.Win32.Sality.bakc
3.12.26.3

VIPRE Antivirus
Threat.4721115
38552

ViRobot
Win32.Sality.Gen.A[h]
2014.3.20.0

Zillya! Antivirus
Virus.Sality.Win32.20
2.0.0.2105

File size:
916.5 KB (938,536 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Polish

Common path:
C:\documents and settings\zawadzinska\moje dokumenty\downloads\skype_idg_downloader_37337_pc.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:oSNloZIqnEDBY3bhj/CQzQ2nRrYDACa30zgHyVk:dYnwY3dj/CQztRGY3tS2

Entry address:
0x1744C0

Entry point:
BF, 83, A9, 00, 57, FF, C5, 1D, 3F, 12, FE, 14, B6, 09, 87, E9, 0F, BE, FE, 12, D2, 8A, EF, 2B, C6, 21, DA, 8A, FE, EB, 02, 28, C4, F6, C3, 8B, 0F, BE, E9, 42, 68, CF, 69, 46, 00, 0F, BE, D8, E8, 46, 00, 00, 00, 0F, B7, F6, 81, E2, A4, 72, 23, 14, 85, C0, 69, D3, 44, AE, 64, C9, 8D, 35, 4C, 7C, D4, 6D, 8A, E6, 8D, 0E, C6, C3, A6, 8D, 2D, 88, 02, B4, 76, 0F, BE, DF, 77, 05, 89, FA, 0F, AF, C1, 33, F9, 85, C8, 75, 12, 8D, 1D, 79, 32, 89, EB, 8D, 35, 3F, 2E, AC, D6, 69, F1, 7D, 51, F0, 67, C6, C4, 11, 0F, AF...
 
[+]

Code size:
468 KB (479,232 bytes)

The file skype_idg_downloader_37337_pc.exe has been seen being distributed by the following URL.

Remove skype_idg_downloader_37337_pc.exe - Powered by Reason Core Security