znwtubvd.dll

The library znwtubvd.dll has been detected as malware by 31 anti-virus scanners.
MD5:
6677ca65220fde36df7eb60df57128a0

SHA-1:
00377dad6aa92a5c1da54821033db4e6029bfb0c

SHA-256:
43978f02fe4f1484b492dfdf355f95a07af958900f6f3630d7c193aa35e850d4

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/27/2024 3:20:42 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Miuref.3
-40

AhnLab V3 Security
Trojan/Win32.Agent.C840544
3.8.1.16

Avira AntiVirus
TR/Miuref.opmdj
8.3.3.4

Arcabit
Trojan.Miuref.3
1.0.0.788

avast!
Win32:Malware-gen
2014.9-170315

AVG
Crypt_s
2018.0.2438

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.17315

Bitdefender
Gen:Variant.Miuref.3
1.0.20.370

Bkav FE
W32.FamVT.LocktETTc
1.3.0.8455

Comodo Security
TrojWare.Win32.Amtar.WRAP
26138

Emsisoft Anti-Malware
Gen:Variant.Miuref
8.17.03.15.10

ESET NOD32
Win32/Boaxxe.CO.gen (variant)
11.14466

F-Prot
W32/Symmi.BR.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Miuref.3
11.2017-15-03_4

G Data
Gen:Variant.Miuref
17.3.25

IKARUS anti.virus
Trojan.Win32.Miuref
t3scan.2.1.16.0

K7 AntiVirus
Trojan
13.245.21559

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.-1315

Malwarebytes
Trojan.Miuref
v2017.03.15.10

McAfee
Miuref-FAD!6677CA65220F
5600.6094

Microsoft Security Essentials
Trojan:Win32/Miuref.C
1.1.13303.0

MicroWorld eScan
Gen:Variant.Miuref.3
18.0.0.222

NANO AntiVirus
Trojan.Win32.Boaxxe.eiisgb
1.0.70.13328

Panda Antivirus
Trj/Genetic.gen
17.03.15.10

Qihoo 360 Security
HEUR/QVM39.1.0000.Malware.Gen
1.0.0.1120

Reason Heuristics
Packed.Boaxxe.ET (M)
17.3.15.22

Rising Antivirus
Trojan.Miuref!8.B7E-OX6cnneauyE (cloud)
23.00.65.17313

Sophos
Mal/EncPk-DW
4.98

Trend Micro House Call
TROJ_GEN.R028C0DKE16
7.2.74

Trend Micro
TROJ_GEN.R028C0DKE16
10.465.15

VIPRE Antivirus
Trojan.Win32.Generic
53868

File size:
1.2 MB (1,284,608 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\ebtion\znwtubvd.dll

File PE Metadata
Compilation timestamp:
5/5/2015 12:24:00 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x318000

Entry point:
56, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, 80, 13, 00, 2D, 08, DC, 0B, 10, 05, FF, DB, 0B, 10, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, 1B, 84, C3, 75, 68, 22, 8A, 77, 07, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 20, 75, 6C, 18, B6, 69, 9D, 3C, EE, 60, D4, DA, 0B, 6B, 67, 1A...
 
[+]

Entropy:
7.9414  (probably packed)

Code size:
5.5 KB (5,632 bytes)

Remove znwtubvd.dll - Powered by Reason Core Security