wmi_logoff.exe

The executable wmi_logoff.exe has been detected as malware by 16 anti-virus scanners.
MD5:
9f39116a6a2d62e3352b48d08a18d85e

SHA-1:
636b50a65c16e10e525e53a6417abc3feb786fe7

SHA-256:
1c87db91d3d681da21d12ece513811708158f91bb5590d70f3d80e3e3a78faf6

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
4/28/2024 7:56:28 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Agent.13923
2011.03.05

avast!
Win32:Malware-gen
2014.9-170311

Comodo Security
TrojWare.Win32.TrojanDropper.Small.ug
7872

F-Prot
W32/Backdoor2.GXJR
v6.4.6.2.117

G Data
Win32:Malware-gen
17.3.21

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.1.97.0

McAfee
Generic.dx!vda
5600.6099

nProtect
Trojan/W32.Agent.14202
11.02.10.01

Panda Antivirus
Joke/Shutdown
17.03.11.02

Prevx
Medium Risk Malware
3.0

Rising Antivirus
Trojan.Win32.Undef.uoh
23.00.65.17309

Trend Micro House Call
TROJ_GEN.R47C3L9
7.2.70

Trend Micro
TROJ_GEN.R47C3L9
10.465.11

Vba32 AntiVirus
Trojan.Win32.StartPage.hd
3.12.14.3

VIPRE Antivirus
Trojan.Win32.Generic
8600

ViRobot
Trojan.Win32.Agent.13916.B
2011.3.4.4340

File size:
13.9 KB (14,202 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\windows\files\wmi_logoff.exe

File PE Metadata
Compilation timestamp:
5/14/2008 11:26:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

Entry address:
0x1000

Entry point:
68, 2C, 00, 00, 00, 68, 00, 00, 00, 00, 68, 18, 45, 40, 00, E8, F4, 0F, 00, 00, 83, C4, 0C, 68, 00, 00, 00, 00, E8, F9, 0F, 00, 00, A3, 1C, 45, 40, 00, 68, 00, 00, 00, 00, 68, 00, 10, 00, 00, 68, 00, 00, 00, 00, E8, E6, 0F, 00, 00, A3, 18, 45, 40, 00, E8, BC, 1B, 00, 00, E8, 4F, 1B, 00, 00, E8, DD, 14, 00, 00, E8, BD, 13, 00, 00, E8, C8, 10, 00, 00, E8, DB, 0F, 00, 00, E8, 9E, 12, 00, 00, 89, C3, 83, FB, 0A, 74, 0E, E8, 92, 12, 00, 00, 89, C3, 83, FB, 1E, 74, 02, EB, 07, B8, 01, 00, 00, 00, EB, 02, 31, C0...
 
[+]

Entropy:
4.5767

Packer / compiler:
PKLITE32, 0x1.1

Code size:
7 KB (7,168 bytes)

Remove wmi_logoff.exe - Powered by Reason Core Security