doinaa.exe

SzWXMLpOA

The executable doinaa.exe has been detected as malware by 6 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘doinaa’.
Product:
SzWXMLpOA

Version:
1.00

MD5:
0701313529ea8176370cbf22b1113fe9

SHA-1:
027ce229546911c35a65976f88baf9fcb45456a5

SHA-256:
4681e8c04649f54223a3749e1bb034fe8a753247d28f075dc0161e16679c73ef

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
5/6/2024 12:53:57 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.Otran-5
0.98/23207

Dr.Web
Trojan.VbCrypt.77
9.0.1.05190

ESET NOD32
Win32/AutoRun.VB.ANJ worm
6.3.12010.0

F-Prot
W32/Vobfus.Z.gen
4.6.5.141

Kaspersky
Worm.Win32.WBNA
15.0.2.529

Microsoft Security Essentials
Worm:Win32/Vobfus.gen!S
1.237.1231.0

File size:
336 KB (344,064 bytes)

Product version:
1.00

Original file name:
HhRopMplFJ.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\sony\doinaa.exe

File PE Metadata
Compilation timestamp:
10/8/2011 5:02:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x3B14

Entry point:
68, AC, 3B, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 82, 66, C2, 77, D1, 2B, 05, 4A, 8F, 05, 48, B0, D0, D9, 2D, B2, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 65, 67, 69, 6E, 20, 56, 64, 46, 5A, 64, 76, 70, 00, 20, 00, 00, 00, 00, 06, 00, 00, 00, 0C, 57, 40, 00, 07, 00, 00, 00, 08, 4F, 40, 00, 01, 00, 00, 00, 6C, 4A, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, C0, 4A, 40, 00, 08, E0, 44, 00, 01, 00, 00, 00, A8, 3B, 40, 00...
 
[+]

Entropy:
5.9058

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
308 KB (315,392 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
doinaa

Command:
C:\users\sony\doinaa.exe \a


Remove doinaa.exe - Powered by Reason Core Security