xplorer.exe

The executable xplorer.exe has been detected as malware by 27 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Xplorer’.
Version:
0.0.0.2

MD5:
7bd1f265d4eb7d97610b8a1cdbe4e5e0

SHA-1:
68fc7aaef2c1a3f1f03470212924a36d0fecc15c

SHA-256:
66c27a50c542bcd0dbe18d02b673a82c0554648b86f2aea36976e167f3814678

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/30/2024 6:14:38 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Autorun.506687
5.0.

Avira AntiVirus
TR/Autoit.mjc
8.2.1.194

Emsisoft A-Squared
Trojan-Dropper.Win32.Autoit!IK
4.5.0.50

avast!
Win32:Sality
2014.9-170307

Bitdefender
Win32.Worm.Autoit.CZ
1.0.20.330

Clam AntiVirus
Trojan.Autoit-75
0.98/17011

Comodo Security
Worm.Win32.Autorun.Autoit_AH0
4316

Dr.Web
WORM.Virus
9.0.1.066

ESET NOD32
Win32/AutoRun.Autoit.AH
11.4957

F-Prot
W32/Dropper.AHOI
v6.4.5.1.85

F-Secure
Win32.Worm.Autoit.CZ
11.2017-07-03_3

G Data
Win32.Worm.Autoit.CZ
17.3.19

IKARUS anti.virus
Trojan-Dropper.Win32.Autoit
t3scan.1.1.80.0

K7 AntiVirus
Trojan-Dropper.Win32.Autoit.k
13.7.10.1001

Kaspersky
Trojan-Dropper.Win32.Autoit
14.0.0.-1271

McAfee
W32/Yahlover.worm.gen.i
5600.6103

Microsoft Security Essentials
Worm:Win32/Abfewsm.A
1.163.1557.0

Norman
Sohanad.BEW
11.20170307

nProtect
Trojan-Dropper/W32.AutoIt.609087
2009.1.8.0

Panda Antivirus
W32/Sohanat.IW
17.03.07.06

Prevx
Medium Risk Malware
3.0

Quick Heal
Trojan.Agent.WD
3.17.10.00

Rising Antivirus
Trojan.Win32.Autoit.dwc
23.00.65.17305

Sophos
W32/Autoit-BP
4.51

Trend Micro
WORM_UTOTI.AU
10.465.07

Vba32 AntiVirus
Trojan-Dropper.Win32.Autoit.k
3.12.12.2

ViRobot
Dropper.Autoit.506687.B
2010.3.19.2236

File size:
594.8 KB (609,087 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\windows\xplorer.exe

File PE Metadata
Compilation timestamp:
11/15/2008 3:30:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x1000

Entry point:
B8, 14, 56, 4B, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 14, 93, 9D, 82, B6, 27, E3, 84, FE, 3D, 05, 1F, 0B, 52, 28, C8, C7, D4, 94, 99, DA, 0E, C0, BE, 22, 8C, BB, 44, 24, A8, 45, 68, 2C, E0, CF, DA, FE, B9, 52, 3D, 77, 1A, 8F, 6F, C8, BA, 45, D4, CE, 28, D1, 95, 12, B3, F0, F2, DF, B6, 2C, 9C, 83, 1A, D2, F3, B9, D3, 71, BD, 5C, 52, F3, 09, 66, DA, 43, 0D, 89, DB, 58, C6, 64, 50, 2F, 8A, 17, BF, F4, 9E, EF, 09, 3A, 24, 74...
 
[+]

Entropy:
6.9683

Packer / compiler:
PECompact v2

Code size:
408 KB (417,792 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Xplorer

Command:
"C:\windows\xplorer.exe" \windows


Remove xplorer.exe - Powered by Reason Core Security