Windows 7 Loader.exe

Windows 7 Loader

The executable Windows 7 Loader.exe has been detected as malware by 12 anti-virus scanners. The file has been seen being downloaded from docviewer.yandex.com.
Product:
Windows 7 Loader

Version:
2.2.1.0

MD5:
c46a624c0ce5a84eb4878c1bc6ccc4ce

SHA-1:
da514cd916ab659ea201f8902006d84e9bea46d3

SHA-256:
ef033c1d3661233721d21d3347a8783f80d7e8a2abd530ce43dc0e77072f0304

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
4/26/2024 2:32:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.445336
549

Avira AntiVirus
TR/Dropper.Gen
8.3.1.6

Arcabit
Trojan.Kazy.D6CB98
1.0.0.425

Bitdefender
Gen:Variant.Kazy.445336
1.0.20.1085

Emsisoft Anti-Malware
Gen:Variant.Kazy.445336
8.15.08.05.08

G Data
Gen:Variant.Kazy.445336
15.8.25

IKARUS anti.virus
Virus.Win32.Sality
t3scan.1.9.5.0

MicroWorld eScan
Gen:Variant.Kazy.445336
16.0.0.651

Panda Antivirus
Trj/CI.A
15.08.05.08

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.18EA48C1!418007233
23.00.65.15803

Sophos
Windows 7 Loader (PUA)
4.98

File size:
4.3 MB (4,517,888 bytes)

Product version:
2.2.1.0

Copyright:
Copyright © 2015

Original file name:
Windows 7 Loader.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\windows_7_loader\windows 7 loader.exe

File PE Metadata
Compilation timestamp:
8/3/2015 2:22:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:HEYz38cgg/ngk4mYfA7fgvn812nvkB0y23pNO:HEYz5gg/v4mevn8i1yUG

Entry address:
0x44BC4E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6982

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
4.3 MB (4,496,896 bytes)

The file Windows 7 Loader.exe has been seen being distributed by the following URL.

Remove Windows 7 Loader.exe - Powered by Reason Core Security