stub.exe

The executable stub.exe has been detected as malware by 14 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
MD5:
ca373c862abff7c7eefced78cef98fa7

SHA-1:
4244f5657642af34f0a60e8dcfe22aa97637a893

SHA-256:
00ba4e36105147192c92eb64e6d059aaf7fdc81f5603e11090f8f0f423be9d9b

Scanner detections:
14 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/24/2024 9:17:35 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
5813571

Avira AntiVirus
W32/Sality.AG
7.11.30.172

avast!
Win32:Kukacka
160201-0

AVG
Win32/Sality
2015.0.4477

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5087.0

Norman
Win32.Sality.3
03.12.2014 13:20:04

Sophos
Virus 'Mal/Sality-D'
5.23

VIPRE Antivirus
Threat.4721115
46826

File size:
117.3 KB (120,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\pokerstars.eu\stub.exe

File PE Metadata
Compilation timestamp:
8/1/2008 2:23:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:WTGNMKboUNkdW0jKSWusyh6gihuhKm6V7pOhIGL2y8NImB94+WcuFNv:aG7boUNgWwzPYiq0hI82TNImBOPpv

Entry address:
0x16CF

Entry point:
60, 0F, BE, D3, F3, 8D, 15, 1A, 62, 25, 2C, 42, 21, D6, 86, E2, 45, FF, CA, 8B, CF, 3D, 1F, D5, F2, 44, 81, F7, 8C, A8, 00, 00, EB, 04, 31, DB, 11, D3, F6, C0, A0, F2, 0B, C8, 53, F2, 81, CE, FD, 91, 98, 4E, F3, 87, C7, 0F, AF, D5, FF, C7, 0F, AF, F8, E8, 11, 00, 00, 00, 76, 03, 0F, AF, E9, EB, 02, 84, F5, 77, 04, 87, F2, 85, F7, 3B, F9, 5B, 10, FA, 84, FF, 0B, D0, F2, 8A, F0, 81, E8, 0A, 8F, BE, B0, EB, 0E, B9, 00, E0, 2A, 68, 0F, AF, CB, 81, C7, 47, 30, 51, B0, 81, FD, B0, 38, 00, 00, 75, 08, 69, F1, B9...
 
[+]

Entropy:
7.1702

Code size:
16 KB (16,384 bytes)

Remove stub.exe - Powered by Reason Core Security