nokian73tools.exe

The executable nokian73tools.exe has been detected as malware by 28 anti-virus scanners.
MD5:
417e5dff5038bacb39a6068caa5e69c0

SHA-1:
7905dbe686c7b126071c8f86f64446bf19d8ae4b

SHA-256:
6800d5dfef21a4fe6833f2f1cb5b2fb88550cc84e4e6f772596df3af36047672

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/30/2024 9:09:56 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/Mabezat
5.0.

Avira AntiVirus
Worm/Mabezat.b
7.9.1.146

Emsisoft A-Squared
Worm.Win32.Mabezat!IK
4.5.0.50

avast!
Win32:Mabezat-AM
2014.9-170309

AVG
Worm/Mabezat.A
2018.0.2445

Bitdefender
Worm.Generic.59144
1.0.20.340

Clam AntiVirus
W32.Mabezat-2
0.98/171

Comodo Security
Worm.Win32.Mabezat.b
3656

Dr.Web
Win32.HLLW.Tazebama
9.0.1.068

ESET NOD32
Win32/Mabezat
11.4791

Fortinet FortiGate
W32/Mabezat.B
3/9/2017

F-Prot
W32/Mabezat.A
v6.4.5.1.85

F-Secure
Worm.Generic.59144
11.2017-09-03_5

G Data
Worm.Generic.59144
17.3.19

IKARUS anti.virus
Worm.Win32.Mabezat
t3scan.1.1.80.0

K7 AntiVirus
Virus.Win32.Mabezat.b-3
13.7.10.951

Kaspersky
Worm.Win32.Mabezat
14.0.0.-1280

McAfee
W32/Mabezat
5600.6101

Microsoft Security Essentials
Virus:Win32/Mabezat.B
1.163.1557.0

Norman
Mabezat.B
11.20170309

Panda Antivirus
W32/Mabezat.C.worm
17.03.09.01

Prevx
High Risk System Back Door
3.0

Quick Heal
W32.Mabezat.Dr
3.17.10.00

Rising Antivirus
Win32.Mabezat.b
23.00.65.17307

Sophos
W32/Mabezat-B
4.50

Trend Micro
PE_MABEZAT.B-O
10.465.09

Vba32 AntiVirus
Worm.Win32.Mabezat.b
3.12.12.1

ViRobot
Worm.Win32.Mabezat.154751
2010.1.21.2148

File size:
157.5 KB (161,315 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\s-1-5-31-1286970278978-5713669491-166975984-320\rotinom\recycler\{random}\nokian73tools.exe

File PE Metadata
Compilation timestamp:
10/29/2007 8:17:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1000

Entry point:
53, 83, EC, 44, B8, 23, 10, 40, 00, B9, 00, 00, 00, 00, 8A, 18, 80, C3, 26, 88, 18, 83, C0, 01, 83, C1, 01, 81, F9, 37, D1, 00, 00, 75, EB, 92, DA, DA, 1B, DA, 93, DA, DA, DA, DA, 64, F2, 5A, 9D, FF, 62, F2, 5D, 9B, DB, 5D, 9A, DB, 5B, D3, D9, 01, DA, DA, 4F, C5, 92, DA, EA, 1A, DA, 95, 9D, 9D, 9D, 9D, 63, F2, 92, AF, B4, 1A, DA, 5D, 9A, DA, 5D, 9E, 1E, D9, AA, 9D, 35, 9D, C2, DF, DA, DA, DA, C3, E4, DA, DA, DA, 93, B2, 01, 1B, DA, C3, 45, 8F, DA, DA, 42, 58, EA, 1A, DA, C2, 09, A3, DA, DA, 33, 9D, 93, B2...
 
[+]

Entropy:
7.0151

Code size:
52.5 KB (53,760 bytes)

Remove nokian73tools.exe - Powered by Reason Core Security