tmpb99.exe

The executable tmpb99.exe has been detected as malware by 24 anti-virus scanners.
MD5:
7a0ae40a87d008c4729f72bf0c0e1e24

SHA-1:
4d50e215c28aada98e9c19194ca0052930a792ab

SHA-256:
dac1d842c06a91db63759f570c2857ee86e5f24d1ee2ca5cba44a4bbce2dbc3e

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/19/2024 6:43:59 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2688151
488

Avira AntiVirus
TR/Crypt.Xpack.27341
8.3.2.2

Arcabit
Trojan.Generic.D290497
1.0.0.425

avast!
Win32:Malware-gen
2014.9-151004

AVG
Crypt4
2016.0.2966

Baidu Antivirus
Backdoor.Win32.Androm
4.0.3.15104

Bitdefender
Trojan.GenericKD.2688151
1.0.20.1385

Dr.Web
BackDoor.Andromeda.614
9.0.1.0277

Emsisoft Anti-Malware
Trojan.GenericKD.2688151
8.15.10.04.10

ESET NOD32
Win32/Kryptik.DUZK (variant)
9.12192

Fortinet FortiGate
W32/Kryptik.DUZK!tr
10/4/2015

F-Secure
Trojan.GenericKD.2688151
11.2015-04-10_1

G Data
Trojan.GenericKD.2688151
15.10.25

K7 AntiVirus
Trojan
13.2017095

Kaspersky
Backdoor.Win32.Androm
14.0.0.1325

McAfee
RDN/Generic BackDoor
5600.6622

Microsoft Security Essentials
Worm:Win32/Gamarue.AU
1.1.12002.0

MicroWorld eScan
Trojan.GenericKD.2688151
16.0.0.831

nProtect
Trojan.GenericKD.2688151
15.09.02.01

Panda Antivirus
Trj/Genetic.gen
15.10.04.10

Qihoo 360 Security
Win32/Backdoor.e00
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R028C0DHV15
10.465.04

VIPRE Antivirus
Trojan.Win32.Kryptik.cpvt
43400

File size:
77 KB (78,848 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\microsoft\performance\monitor\temp\tmpb99.exe

File PE Metadata
Compilation timestamp:
8/29/2015 2:11:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:JtI7GXGY+XpkCUHrkY7PjKpfH/bd6pY0Q9zBcy:JtIKXGY+jUBPjKpffJOpI9

Entry address:
0x51B5

Entry point:
E8, 05, 25, 00, 00, E9, 89, FE, FF, FF, 2D, A4, 03, 00, 00, 74, 22, 83, E8, 04, 74, 17, 83, E8, 0D, 74, 0C, 48, 74, 03, 33, C0, C3, B8, 04, 04, 00, 00, C3, B8, 12, 04, 00, 00, C3, B8, 04, 08, 00, 00, C3, B8, 11, 04, 00, 00, C3, 8B, FF, 56, 57, 8B, F0, 68, 01, 01, 00, 00, 33, FF, 8D, 46, 1C, 57, 50, E8, 5B, 25, 00, 00, 33, C0, 0F, B7, C8, 8B, C1, 89, 7E, 04, 89, 7E, 08, 89, 7E, 0C, C1, E1, 10, 0B, C1, 8D, 7E, 10, AB, AB, AB, B9, 28, 11, 41, 00, 83, C4, 0C, 8D, 46, 1C, 2B, CE, BF, 01, 01, 00, 00, 8A, 14, 01...
 
[+]

Code size:
35.5 KB (36,352 bytes)

Policies Explorer Run
Name:
217093040


Remove tmpb99.exe - Powered by Reason Core Security