windows.exe

The executable windows.exe has been detected as malware by 27 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘2b84a7ed33f26a9ef98ff459e1950594’.
MD5:
6f30f6a10e5e86cb0c2151ded5f9a4f9

SHA-1:
a8685c673f4841fe8b6150e3ac7862076bbd14d7

SHA-256:
5fbc5ec4c5df80c8aa4a032e1ed3eb35d0de535bf3d9c3ab2c7a8a334c93320e

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
5/14/2024 4:25:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.144969
5791462

AhnLab V3 Security
Trojan/Win32.Generic
2015.09.02

Avira AntiVirus
TR/Crypt.XPACK.Gen
8.3.2.2

Arcabit
Trojan.Graftor.D23649
1.0.0.425

avast!
Win32:Malware-gen
150828-0

AVG
Luhe.Fiha.A
2016.0.2999

Baidu Antivirus
Virus.Win32.Virut
4.0.3.1591

Bitdefender
Gen:Variant.Graftor.144969
1.0.20.1220

Dr.Web
Trojan.Winlock.9484
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Graftor.144969
10.0.0.5366

ESET NOD32
Win32/Virut.NBP virus
7.0.302.0

Fortinet FortiGate
W32/Virut.CE
9/1/2015

F-Prot
W32/Zusy.Q.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Graftor.144969
5.14.151

G Data
Gen:Variant.Graftor.144969
15.9.25

K7 AntiVirus
Trojan
13.2017075

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1492

Malwarebytes
Trojan.MSIL
v2015.09.01.03

McAfee
Trojan.BackDoor-FCJC!6F30F6A10E5E
18.0.204.0

MicroWorld eScan
Gen:Variant.Graftor.144969
16.0.0.732

Norman
Gen:Variant.Graftor.144969
04.08.2015 10:30:46

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Quick Heal
Trojan.Agen.r4
9.15.14.00

Rising Antivirus
PE:Backdoor.Win32.Bindi.a!1614329[F1]
23.00.65.15830

SUPERAntiSpyware
Trojan.Agent/Gen-Gal[Ex]
9656

VIPRE Antivirus
Threat.4657539
42326

Zillya! Antivirus
Backdoor.PePatch.Win32.76279
2.0.0.2384

File size:
355.8 KB (364,288 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\windows.exe

File PE Metadata
Compilation timestamp:
10/11/2000 1:23:26 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:t5C2F8NXC796TB9vj48hB4CEc/+Vi9ub6An113pZkOGmBaR5Y+w3RhXOeJCrrrYd:tjeVQkTrvj4+i7c/+/bB9SOGVR5YDee9

Entry address:
0xFFEF

Entry point:
E8, 12, 5B, 00, 00, E9, A4, FE, FF, FF, 6A, 0C, 68, 38, 11, 42, 00, E8, 67, 0D, 00, 00, 6A, 0E, E8, 68, 02, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, F4, 37, 42, 00, BA, F0, 37, 42, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, D9, E7, FF, FF, 59, FF, 76, 04, E8, D0, E7, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 56, 0D, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, 33, 01, 00, 00, 59, C3, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
7.6323

Code size:
102 KB (104,448 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
2b84a7ed33f26a9ef98ff459e1950594

Command:
"C:\users\{user}\appdata\roaming\windows.exe"..


Remove windows.exe - Powered by Reason Core Security