w68v12.exe

The executable w68v12.exe has been detected as malware by 46 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘wi68’. This trojan will attemp to establish a connection to a remote server through various TCP ports and will use Winlogon to survive reboots.
MD5:
f599a4cd861fa3f21b11a54a126e071e

SHA-1:
4dc72c4b754dd24b36465d2d175e120172f401da

Scanner detections:
46 / 68

Status:
Malware

Analysis date:
4/16/2024 11:37:36 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.KDZ.1286
864

Agnitum Outpost
Trojan.Injector
7.1.1

AhnLab V3 Security
Worm/Win32.Stekct
2014.06.13

Avira AntiVirus
TR/Agent.73728.31
7.11.154.162

avast!
Win32:Malware-gen
2014.9-140923

AVG
Generic30
2015.0.3342

Baidu Antivirus
Trojan.Win32.SmartPepi
4.0.3.14923

Bitdefender
Trojan.Generic.KDZ.1286
1.0.20.1330

Bkav FE
W32.TomcatF.Trojan
1.3.0.4959

Clam AntiVirus
Win.Trojan.Buzus-3318
0.98/21155

Comodo Security
TrojWare.Win32.Agent.AABQ
18533

Dr.Web
Trojan.Packed.23610
9.0.1.0266

Emsisoft Anti-Malware
Trojan.Generic.KDZ.1286
8.14.09.23.01

ESET NOD32
Win32/Lethic.AA
8.9938

Fortinet FortiGate
W32/Jorik_Nrgbot.AA!tr
9/23/2014

F-Prot
W32/Trojan2.NUWN
v6.4.7.1.166

F-Secure
Trojan.Generic.KDZ.1286
11.2014-23-09_3

G Data
Trojan.Generic.KDZ.1286
14.9.24

IKARUS anti.virus
Trojan.Win32.Lethic
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.1712387

Kaspersky
Worm.Win32.Ngrbot
14.0.0.3207

Malwarebytes
Trojan.Agent
v2014.09.23.01

McAfee
W32/Hamweq.worm
5600.6998

Microsoft Security Essentials
1.10600

MicroWorld eScan
Trojan.Generic.KDZ.1286
15.0.0.798

NANO AntiVirus
Trojan.Win32.Jorik.bfdyup
0.28.0.60253

Norman
Injector.GESY
11.20140923

nProtect
Trojan/W32.Buzus.72192.AB
14.06.12.01

Panda Antivirus
Trj/OCJ.A
14.09.23.01

Qihoo 360 Security
Win32/Trojan.100
1.0.0.1015

Quick Heal
Trojan.Hoptto.A
9.14.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.13CDE811!332261393
23.00.65.14921

Sophos
Mal/EncPk-AIC
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Dropper
10342

Total Defense
Win32/Lethic.MH
37.0.10995

Trend Micro House Call
TROJ_LETHIC.CH
7.2.266

Trend Micro
TROJ_LETHIC.CH
10.465.23

Vba32 AntiVirus
BScope.Trojan-Dropper.2B05
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
30252

ViRobot
Trojan.Win32.A.Buzus.143872.A
2011.4.7.4223

Zillya! Antivirus
Trojan.Buzus.Win32.109660
2.0.0.1822

File size:
70.5 KB (72,192 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
12/9/2012 9:14:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:7n759h3bJa8u3iGeycQDBU6ehB6E9i/wEDzAnt6uSh8uprO3nwMC9zE0UbBbXGml:7n759JJ085QyxiytS/Ry04icp1

Entry address:
0x4A96

Entry point:
E8, E4, 14, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 38, FC, 40, 00, 89, 0D, 34, FC, 40, 00, 89, 15, 30, FC, 40, 00, 89, 1D, 2C, FC, 40, 00, 89, 35, 28, FC, 40, 00, 89, 3D, 24, FC, 40, 00, 66, 8C, 15, 50, FC, 40, 00, 66, 8C, 0D, 44, FC, 40, 00, 66, 8C, 1D, 20, FC, 40, 00, 66, 8C, 05, 1C, FC, 40, 00, 66, 8C, 25, 18, FC, 40, 00, 66, 8C, 2D, 14, FC, 40, 00, 9C, 8F, 05, 48, FC, 40, 00, 8B, 45, 00, A3, 3C, FC, 40, 00, 8B, 45, 04, A3, 40, FC, 40, 00, 8D, 45, 08, A3, 4C, FC, 40...
 
[+]

Code size:
31.5 KB (32,256 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
wi68

Command:
C:\recycler\{random}\w68v12.exe


Remove w68v12.exe - Powered by Reason Core Security