pl-pl.exe

The executable pl-pl.exe has been detected as malware by 30 anti-virus scanners.
MD5:
66605f2a08acb0f94f722213e6729c88

SHA-1:
2e9486ebb53d9453381a2595530ea4b52255250f

SHA-256:
94f1579444bcdf6ecd0c08d001930ae9a3765e1297431e2cada3e9e4d3173b5e

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/29/2024 6:55:16 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/Mabezat
2010.07.24

Avira AntiVirus
Worm/Mabezat.b
8.2.4.26

avast!
Win32:Mabezat-AM
2014.9-170314

AVG
Worm/Mabezat.A
2018.0.2440

Bitdefender
Worm.Generic.256883
1.0.20.365

Clam AntiVirus
W32.Mabezat-2
0.98/170.3

Comodo Security
Worm.Win32.Mabezat.b
5522

Dr.Web
Win32.HLLW.Tazebama
9.0.1.073

Emsisoft Anti-Malware
Worm.Win32.Mabezat!IK
8.17.03.14.12

ESET NOD32
Win32/Mabezat
11.5308

Fortinet FortiGate
W32/Mabezat.B
3/14/2017

F-Prot
W32/Mabezat.A
v6.4.6.1.107

F-Secure
Worm.Generic.256883
11.2017-14-03_3

G Data
Worm.Generic.256883
17.3.21

IKARUS anti.virus
Worm.Win32.Mabezat
t3scan.1.1.84.0

Kaspersky
Worm.Win32.Mabezat
14.0.0.-1305

McAfee
W32/Mabezat
5600.6096

Microsoft Security Essentials
Virus:Win32/Mabezat.B
1.163.1557.0

Norman
Mabezat.B
11.20170314

nProtect
Worm.Generic.256883
10.07.24.02

Panda Antivirus
W32/Mabezat.C.worm
17.03.14.12

Prevx
Medium Risk Malware
3.0

Quick Heal
W32.Mabezat.Dr
3.17.11.00

Rising Antivirus
Worm.Win32.Autorun.gcy
23.00.65.17312

Sophos
W32/Mabezat-B
4.55

SUPERAntiSpyware
Trojan.Agent/Gen-VirutZ
8537

Trend Micro House Call
PE_MABEZAT.B-O
7.2.73

Trend Micro
PE_MABEZAT.B-O
10.465.14

Vba32 AntiVirus
Worm.Win32.Mabezat.b
3.12.12.6

ViRobot
Worm.Win32.Mabezat.154751
2010.7.23.3956

File size:
151.2 KB (154,781 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\editpdf\js\nls\pl-pl\pl-pl.exe

File PE Metadata
Compilation timestamp:
10/29/2007 9:17:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1000

Entry point:
53, 83, EC, 44, B8, 23, 10, 40, 00, B9, 00, 00, 00, 00, 8A, 18, 80, C3, D0, 88, 18, 83, C0, 01, 83, C1, 01, 81, F9, 37, D1, 00, 00, 75, EB, E8, 30, 30, 71, 30, E9, 30, 30, 30, 30, BA, 48, B0, F3, 90, B8, 48, B3, F1, 31, B3, F0, 31, B1, 29, 2F, 57, 30, 30, A5, 1B, E8, 30, 40, 70, 30, EB, F3, F3, F3, F3, B9, 48, E8, 05, 0A, 70, 30, B3, F0, 30, B3, F4, 74, 2F, 00, F3, 8B, F3, 18, 35, 30, 30, 30, 19, 3A, 30, 30, 30, E9, 08, 57, 71, 30, 19, 9B, E5, 30, 30, 98, AE, 40, 70, 30, 18, 5F, F9, 30, 30, 89, F3, E9, 08...
 
[+]

Entropy:
7.0619

Code size:
52.5 KB (53,760 bytes)

Remove pl-pl.exe - Powered by Reason Core Security