update.exe

The executable update.exe has been detected as malware by 40 anti-virus scanners.
MD5:
6bc81c8990b21c8488fa2b3c6d7923b5

SHA-1:
a22d483108b236440c423db38e0a85560c2bd6dd

SHA-256:
49039b09dd1847a52e1eebf9438c59f52343a8af5e8647b8705be8bb4eda3aa8

Scanner detections:
40 / 68

Status:
Malware

Analysis date:
5/29/2024 1:33:30 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Agent.AQNV
1003

Agnitum Outpost
Trojan.Agent2
7.1.1

AhnLab V3 Security
Win-Trojan/Agent.100616.B
14.05.08

Avira AntiVirus
TR/Patched.Ren.Gen
7.11.148.56

avast!
Win32:Agent-ALZJ [Trj]
2014.9-140508

AVG
Worm/Generic_r
2015.0.3481

Bitdefender
Trojan.Agent.AQNV
1.0.20.640

Bkav FE
W32.FakeFolderKA
1.3.0.4959

Clam AntiVirus
Trojan.Agent-142577
0.98/211

Comodo Security
Worm.Win32.Agent.NEC1
18237

Dr.Web
Trojan.MulDrop4.55815
9.0.1.0128

Emsisoft Anti-Malware
Trojan.Agent.AQNV
8.14.05.08.05

ESET NOD32
Win32/Agent.NEC
8.9771

Fortinet FortiGate
W32/Rotinom.SME!tr
5/8/2014

F-Prot
W32/Trojan2.MGVM
v6.4.7.1.166

F-Secure
Trojan.Agent.AQNV
11.2014-08-05_5

G Data
Trojan.Agent.AQNV
14.5.24

IKARUS anti.virus
Trojan.Win32.Agent2
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.177.12013

Kaspersky
Trojan-Dropper.Win32.Autoit
14.0.0.3899

Malwarebytes
Worm.Viking
v2014.05.08.05

McAfee
W32/Rotinom
5600.7137

Microsoft Security Essentials
Worm:Win32/Folstart.A
1.10502

MicroWorld eScan
Trojan.Agent.AQNV
15.0.0.384

NANO AntiVirus
Trojan.Win32.Agent2.bvovk
0.28.0.59608

Norman
Malware
11.20140508

nProtect
Worm/W32.Agent.243976
14.05.07.01

Panda Antivirus
W32/FakeFolder.Q.worm
14.05.08.05

Qihoo 360 Security
Worm.Win32.FakeFolder.BF
1.0.0.1015

Quick Heal
Worm.Folstart.A2
5.14.14.00

Rising Antivirus
PE:Malware.FakeFolder@CV!1.6AA9
23.00.65.14506

Sophos
Mal/Autorun-T
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Virut
10619

Total Defense
Win32/Folstart.A
37.0.10923

Trend Micro House Call
WORM_ROTINOM.SME
7.2.128

Trend Micro
WORM_ROTINOM.SME
10.465.08

Vba32 AntiVirus
Trojan.Autorun.0472
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Rotinom.b
28984

ViRobot
Trojan.Win32.Agent.178440
2011.4.7.4223

Zillya! Antivirus
Trojan.Agent2.Win32.9090
2.0.0.1781

File size:
238.3 KB (243,976 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\start\update.exe

File PE Metadata
Compilation timestamp:
6/3/2009 4:09:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:YrBR9ieUOc+/RAhDcaPLXbbsAyQIrZBQlgSJ0TWS:GBR8Y6hDaAyQIrZBbSJK

Entry address:
0x4189

Entry point:
E8, 58, 35, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, F8, 0F, 41, 00, 89, 0D, F4, 0F, 41, 00, 89, 15, F0, 0F, 41, 00, 89, 1D, EC, 0F, 41, 00, 89, 35, E8, 0F, 41, 00, 89, 3D, E4, 0F, 41, 00, 66, 8C, 15, 10, 10, 41, 00, 66, 8C, 0D, 04, 10, 41, 00, 66, 8C, 1D, E0, 0F, 41, 00, 66, 8C, 05, DC, 0F, 41, 00, 66, 8C, 25, D8, 0F, 41, 00, 66, 8C, 2D, D4, 0F, 41, 00, 9C, 8F, 05, 08, 10, 41, 00, 8B, 45, 00, A3, FC, 0F, 41, 00, 8B, 45, 04, A3, 00, 10, 41, 00, 8D, 45, 08, A3, 0C, 10, 41...
 
[+]

Entropy:
2.9119

Code size:
46.5 KB (47,616 bytes)

User Start Menu Item
Name:
update.exe


Remove update.exe - Powered by Reason Core Security