google chrome.exe

The executable google chrome.exe has been detected as malware by 27 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘8e08bb988aa2c587b0fb666031b02d67’. This backdoor trojan may be used to conduct distributed denial of service attacks, or used to install additional trojans or other forms of malicious software as well as can steal your sensitive information.
MD5:
eaa0e5bef686ad4ba4250e31993e3ca1

SHA-1:
6a59879d4954e431f54acbddaa955d519416a155

SHA-256:
ad01969ef1ab6c1b3da41b0d6904500bf396c040e6ec43bc70603a02073bd6e7

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/27/2024 4:34:57 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.75900
-40

AegisLab AV Signature
Troj.W32.Generic!c
2.1.4+

Avira AntiVirus
TR/Dropper.Gen7
8.3.3.4

Arcabit
Trojan.Zusy.D1287C
1.0.0.696

avast!
Win32:Malware-gen
2014.9-170316

AVG
Bladabindi2
2018.0.2438

Baidu Antivirus
MSIL.Backdoor.Bladabindi
4.0.3.17316

Bitdefender
Gen:Variant.Zusy.75900
1.0.20.375

Comodo Security
UnclassifiedMalware
25150

Dr.Web
Trojan.DownLoader16.21303
9.0.1.075

Emsisoft Anti-Malware
Gen:Variant.Zusy.75900
8.17.03.16.12

ESET NOD32
MSIL/Bladabindi.BM (variant)
11.13582

Fortinet FortiGate
W32/Generic.BM!tr
3/16/2017

F-Secure
Gen:Variant.Zusy.75900
11.2017-16-03_5

G Data
Gen:Variant.Zusy.75900
17.3.25

IKARUS anti.virus
Trojan.MSIL.Bladabindi
t3scan.2.0.9.0

K7 AntiVirus
Trojan
13.227.19779

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1315

McAfee
Artemis!EAA0E5BEF686
5600.6094

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.AL
1.1.12805.0

MicroWorld eScan
Gen:Variant.Zusy.75900
18.0.0.225

NANO AntiVirus
Trojan.Win32.DownLoader16.dxaeah
1.0.30.8482

Qihoo 360 Security
Win32/Trojan.Dropper.fae
1.0.0.1120

Quick Heal
Backdoor.BLA.g3
3.17.14.00

Rising Antivirus
Backdoor.MSIL.Bladabindi!1.9E49
23.00.65.17314

Sophos
Troj/Bbindi-W
4.98

VIPRE Antivirus
Trojan.Win32.Generic
49814

File size:
1.9 MB (2,032,128 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\google chrome.exe

File PE Metadata
Compilation timestamp:
9/10/2015 4:36:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x1F186E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.9 MB (2,030,080 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
8e08bb988aa2c587b0fb666031b02d67

Command:
"C:\users\{user}\appdata\local\temp\google chrome.exe"..


Remove google chrome.exe - Powered by Reason Core Security