abmessengerv9.8.exe

Microsoft Windows DNS

Product:
Microsoft Windows DNS

Version:
1.0.0.0

MD5:
cedd3b6c86907948aeaeefb76af7fadd

SHA-1:
a75f4c21eda58a12511ad11906ea667ec5ef69b8

SHA-256:
7981661b75ec361aea0faa61f87cd210022cbcbd3df1060b5d8d3146b48cbd0d

Scanner detections:
18 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/26/2024 8:20:33 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Nirsoft.K
779

Avira AntiVirus
SPR/PSW.Gen
7.11.189.36

avast!
Win32:PassView-U [PUP]
2014.9-141217

AVG
HackTool
2015.0.3257

Baidu Antivirus
HackTool.Win32.IEPassView
4.0.3.141217

ESET NOD32
Win32/PSWTool.IEPassView.NAE (variant)
8.10789

Fortinet FortiGate
Riskware/IEPassView
12/17/2014

F-Secure
Application.Nirsoft.K
11.2014-17-12_4

IKARUS anti.virus
not-a-virus:PSWTool.Win32.IEPassView.m
t3scan.1.8.3.0

K7 AntiVirus
Riskware
13.186.14150

Kaspersky
not-a-virus:PSWTool.Win32.IEPassView
14.0.0.2781

McAfee
Artemis!CEDD3B6C8690
5600.6913

Microsoft Security Essentials
HackTool:Win32/IEPassview
1.11202

MicroWorld eScan
Application.Nirsoft.K
15.0.0.1053

NANO AntiVirus
Riskware.Win32.PassFox.dcnsis
0.28.6.63726

Qihoo 360 Security
Win32/Virus.RiskTool.008
1.0.0.1015

Quick Heal
PSWTool.IEPassView.r4 (Not a Virus)
12.14.14.00

VIPRE Antivirus
Trojan.Win32.Generic
35170

File size:
512 KB (524,288 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
Microsoft Windows DNS.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\abmessengerv9.8.exe

File PE Metadata
Compilation timestamp:
11/14/2013 6:38:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:421IVZQLvs4p1IVZQLvhNXIm3RgDfkme8Gr9:421IVZQLvXp1IVZQLvh1IAufkme8m

Entry address:
0x707DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 44, B6, 84, 52, 00, 00, 00, 00, 02, 00, 00, 00, 87, 00, 00, 00, 1C, 20, 07, 00, 1C, EC, 06, 00, 52, 53, 44, 53, 83, D7, 6F, B5, F3, 19, 05, 49, AE, D6, 15, 33, 6E, 7F, D0, C5, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 41, 5A, 4D, 4F, 4C, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 73, 6F, 66, 74, 20, 35, 35, 5C, 4D, 69, 63, 72, 6F, 73, 6F, 66, 74, 20, 57...
 
[+]

Entropy:
6.3491

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
442 KB (452,608 bytes)

The file abmessengerv9.8.exe has been seen being distributed by the following 2 URLs.

Scan abmessengerv9.8.exe - Powered by Reason Core Security