wmi_rundll.exe

The executable wmi_rundll.exe has been detected as malware by 16 anti-virus scanners.
MD5:
81aca520f9d4558a6422fd559d59ae82

SHA-1:
8fefa27ffd400fb81296fb423f8fda3ced280ccf

SHA-256:
75870f5e5634af48e4dd785df1e38b7681f5de9469d9f6bc5d5e2b6dbfa26865

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
4/29/2024 3:55:19 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Agent.13923
2011.03.04

avast!
Win32:Malware-gen
2014.9-170311

Comodo Security
TrojWare.Win32.TrojanDropper.Small.ug
7864

F-Prot
W32/Backdoor2.GXJR
v6.4.6.2.117

G Data
Win32:Malware-gen
17.3.21

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.1.97.0

McAfee
Generic.dx!vda
5600.6099

nProtect
Trojan/W32.Agent.15290
11.02.10.01

Panda Antivirus
Joke/Shutdown
17.03.11.02

Prevx
Medium Risk Malware
3.0

Rising Antivirus
Trojan.Win32.Undef.uoh
23.00.65.17309

Trend Micro House Call
TROJ_GEN.R92C3L9
7.2.70

Trend Micro
TROJ_GEN.R92C3L9
10.465.11

Vba32 AntiVirus
Trojan.Win32.StartPage.hd
3.12.14.3

VIPRE Antivirus
Trojan.Win32.Generic
8600

ViRobot
Trojan.Win32.Agent.13916.B
2011.3.4.4338

File size:
14.9 KB (15,290 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\windows\files\wmi_rundll.exe

File PE Metadata
Compilation timestamp:
5/14/2008 11:26:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

Entry address:
0x1000

Entry point:
68, 2C, 00, 00, 00, 68, 00, 00, 00, 00, 68, 18, 45, 40, 00, E8, F4, 0F, 00, 00, 83, C4, 0C, 68, 00, 00, 00, 00, E8, F9, 0F, 00, 00, A3, 1C, 45, 40, 00, 68, 00, 00, 00, 00, 68, 00, 10, 00, 00, 68, 00, 00, 00, 00, E8, E6, 0F, 00, 00, A3, 18, 45, 40, 00, E8, BC, 1B, 00, 00, E8, 4F, 1B, 00, 00, E8, DD, 14, 00, 00, E8, BD, 13, 00, 00, E8, C8, 10, 00, 00, E8, DB, 0F, 00, 00, E8, 9E, 12, 00, 00, 89, C3, 83, FB, 0A, 74, 0E, E8, 92, 12, 00, 00, 89, C3, 83, FB, 1E, 74, 02, EB, 07, B8, 01, 00, 00, 00, EB, 02, 31, C0...
 
[+]

Entropy:
4.9545

Packer / compiler:
PKLITE32, 0x1.1

Code size:
7 KB (7,168 bytes)

Remove wmi_rundll.exe - Powered by Reason Core Security