winampa.exe

The executable winampa.exe has been detected as malware by 12 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WinampAgent’.
MD5:
dfdaa2066354065b1799a53599be1bb5

SHA-1:
000c1f8b1c1b4c0d32f718bfc5ff157ad8029881

SHA-256:
89a96282f8f913454a699f3ebdc76475883d57bd77cc9e18be9f1c2e35bbe0ec

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
4/26/2024 7:21:05 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Vitro
160214-1

AVG
Win32/Virut
2015.0.4522

Dr.Web
Win32.Virut.56
9.0.1.05190

ESET NOD32
Win32/Virut.NBP virus
7.0.302.0

F-Prot
W32/Virut.E.gen
4.6.5.141

F-Secure
Win32.Virtob.Gen.12
5.15.21

Kaspersky
Virus.Win32.Virut
15.0.0.562

McAfee
Virus.W32/Virut.n.gen
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.6277.0

Norman
Win32.Virtob.Gen.12
13.02.2016 01:47:07

Sophos
Virus 'W32/Scribble-B'
5.23

VIPRE Antivirus
Threat.4739697
47068

File size:
63.5 KB (65,024 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\winamp\winampa.exe

File PE Metadata
Compilation timestamp:
12/23/2005 9:06:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
768:kMI2pRxs4RP5aFUFFsNeFVGPSBqnDDFUrPHJK4xz8JJRxEuiHD2SzTxEWDX7Ey:YCs4rNlGjDDFYPtF8J+rD2qxzYy

Entry address:
0x1FDB

Entry point:
55, 8B, EC, 83, EC, 1C, 56, 57, 6A, 06, 59, 33, F6, 33, C0, 89, 75, E4, 8D, 7D, E8, F3, AB, 56, BF, 20, 40, 40, 00, 57, FF, 15, A4, 30, 40, 00, 85, C0, 0F, 85, B6, 00, 00, 00, 68, 00, 34, 40, 00, FF, 15, BC, 30, 40, 00, 56, A3, 64, 62, 40, 00, C7, 05, 74, 6A, 40, 00, 6E, 13, 40, 00, E9, 85, C8, 00, 00, 00, A3, 80, 6A, 40, 00, A3, E4, 6D, 40, 00, 89, 3D, 94, 6A, 40, 00, E8, 01, FD, FF, FF, 68, 70, 6A, 40, 00, FF, 15, B8, 30, 40, 00, 66, 85, C0, 75, 0E, 6A, 10, 68, 30, 40, 40, 00, 68, E0, 33, 40, 00, EB, 34...
 
[+]

Entropy:
6.2892

Developed / compiled with:
Microsoft Visual C++

Code size:
6 KB (6,144 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WinampAgent

Command:
"C:\Program Files\winamp\winampa.exe"


Remove winampa.exe - Powered by Reason Core Security