winampa.exe

The executable winampa.exe has been detected as malware by 13 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WinampAgent’. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
MD5:
25c3bdaf96d1556b5e7250014c851ddf

SHA-1:
1ae78238ec707034effd45e8890387eb2b8f70b9

SHA-256:
5d188792fbeeb38d88cd174d3240b7b7e8e7c97c88dea9743b12e26f4a713c71

Scanner detections:
13 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
5/7/2024 4:53:13 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160203-1

AVG
Win32/Sality
2015.0.4489

Boost by Reason
Optional.Startup
188838

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.E.gen
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Norman
Win32.Sality.3
03.12.2014 13:20:04

Sophos
Virus 'Mal/Sality-D'
5.23

VIPRE Antivirus
Threat.4721115
46938

File size:
101 KB (103,424 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\winamp\winampa.exe

File PE Metadata
Compilation timestamp:
12/13/2003 2:50:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:W4eNhsrlG5P5Q12E5xbHYA/XZCkDxT91SEfUQdXFg2TzTixUzxZ:WhurlG5K2Enb7/cbEd9TzTix6

Entry address:
0x1AF5

Entry point:
60, 8A, F5, C7, C5, D7, 76, 88, AE, BE, 17, 99, DF, CF, 1B, EA, 8D, 05, 2E, 08, FC, D4, C7, C3, 6D, 38, A1, AC, FF, CF, 8D, 2D, 01, F3, 8D, 51, 86, C1, 89, DA, 6B, ED, 00, 3D, 77, 89, E9, 57, FF, C1, 84, D6, 0F, AF, D5, 86, C9, 81, C5, F3, FF, FF, FF, 84, D2, 80, F0, 0F, 81, C5, 0E, 00, 00, 00, 74, 02, 87, C6, 0F, AF, D9, 40, 19, F0, 81, FD, 5F, 08, 00, 00, 0F, 82, CB, FF, FF, FF, EB, 02, 3A, C5, 53, 52, FE, CE, C6, C6, A8, 86, F3, E8, 00, 00, 00, 00, EB, 02, FE, C7, 3B, F1, 70, 04, B0, E2, 20, E0, 1B, C3...
 
[+]

Entropy:
7.1840

Code size:
4 KB (4,096 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WinampAgent

Command:
C:\Program Files\winamp\winampa.exe


Remove winampa.exe - Powered by Reason Core Security