tsmuxer.exe

The executable tsmuxer.exe has been detected as malware by 10 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
MD5:
c32d69303ac5b0b607c37a3ed49911ae

SHA-1:
33841aa7eb9bde08614e60eea225a69c1135b4fb

SHA-256:
2fb8f0dac084cf37a079099a39fe7ceacb6bde543f5682a1870ec954fdd45133

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 2:33:15 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160209-2

AVG
Win32/Sality
2015.0.4489

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.6222.0

Norman
Win32.Sality.3
08.02.2016 04:24:12

Sophos
Virus 'Mal/Sality-D'
5.23

VIPRE Antivirus
Threat.4721115
46800

File size:
293 KB (300,032 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\leawo\video converter\tsmuxer.exe

File PE Metadata
Compilation timestamp:
5/11/2009 8:10:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
6144:Y6iQOpl9qHlCPZk2mi9kz5q56798qIVW3dgCZYH5uCoS9sC45EmRO:Y6m9qxzc56mq9gCjCoS9sC6PE

Entry address:
0xC7230

Entry point:
0F, BF, FE, 78, 06, 86, FC, 19, CD, 19, FB, 2A, FB, 4B, 2C, 17, 69, DE, D1, 18, 38, 9B, 28, C3, 85, DD, FF, CF, 80, E7, E8, C6, C7, 9A, 8B, F2, 0F, BE, C9, B8, 4C, BE, 00, 00, 81, DE, 38, 2F, BC, CA, C6, C1, 3A, 8D, 35, 54, 01, 91, 82, 35, 60, B0, 00, 00, 30, CF, BB, AC, 0B, CC, FB, BD, 73, A4, 84, 2A, 2D, CE, 0B, 00, 00, 69, ED, F2, 16, DB, E2, 84, CF, 8D, 10, 0F, B7, CB, 85, C7, 81, C2, 60, 07, 00, 00, 8A, FC, 0F, BF, F2, 0F, AF, F0, 85, CB, C7, C3, C1, EC, B6, 1E, 86, E9, B9, 86, 9F, 36, 49, 81, EA, 03...
 
[+]

Entropy:
7.9692  (probably packed)

Code size:
220 KB (225,280 bytes)

Remove tsmuxer.exe - Powered by Reason Core Security