cmssetup.v21.exe

The executable cmssetup.v21.exe has been detected as malware by 39 anti-virus scanners. This is a setup program which is used to install the application. Infected by the Parite virus, a polymorphic file infecting virus that infects all portable EXE and SCR files found on local and shared network drives. The file has been seen being downloaded from yyp2p.cn.
MD5:
ddbf9e499c7e9286268b12d6ba90cf5f

SHA-1:
49caae9bdc4237e14f55a6c81bf9981f2f3dda77

SHA-256:
e453c0ec8b1b43f8a3167d7295393aad7ccccc4853ff1372f5e19bfb71c64dbc

Scanner detections:
39 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/29/2024 3:31:32 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Parite.B
306

AegisLab AV Signature
W32.Parite
2.1.4+

AhnLab V3 Security
Win32/Parite
2016.04.04

Avira AntiVirus
W32/Parite
8.3.3.4

Arcabit
Win32.Parite.B
1.0.0.666

avast!
Win32:Parite
2014.9-160404

AVG
Win32/Parite
2017.0.2784

Baidu Antivirus
Win32.Virus.Parite
4.0.3.1644

Bitdefender
Win32.Parite.B
1.0.20.475

Bkav FE
W32.Pinfi.B
1.3.0.7744

Clam AntiVirus
Heuristics.W32.Parite.B
0.98/21511

Comodo Security
Virus.Win32.Parite.gen
24736

Dr.Web
Win32.Parite.2
9.0.1.095

Emsisoft Anti-Malware
Win32.Parite
8.16.04.04.02

ESET NOD32
Win32/Parite
10.13277

Fortinet FortiGate
W32/Parite.B
4/4/2016

F-Prot
W32/Parite.B
v6.4.7.1.166

F-Secure
Win32.Parite.B
11.2016-04-04_2

G Data
Win32.Parite
16.4.25

IKARUS anti.virus
Virus.Parite
t3scan.2.0.9.0

K7 AntiVirus
Virus
13.220.19196

Kaspersky
Virus.Win32.Parite
14.0.0.415

McAfee
W32/Pate.b
5600.6440

Microsoft Security Essentials
Virus:Win32/Parite.B
1.1.12603.0

MicroWorld eScan
Win32.Parite.B
17.0.0.285

NANO AntiVirus
Virus.Win32.Parite.bgvo
1.0.18.7201

nProtect
Virus/W32.Parite.C
16.04.01.01

Panda Antivirus
W32/Parite.B
16.04.04.02

Qihoo 360 Security
Virus.Win32.Parite.H
1.0.0.1120

Quick Heal
W32.Perite.A
4.16.14.00

Rising Antivirus
PE:Virus.Parite!1.9B80 [F]
23.00.65.16402

Sophos
W32/Parite-B
4.98

Total Defense
Win32/Pinfi.A
37.1.62.1

Trend Micro House Call
PE_PARITE.A
7.2.95

Trend Micro
PE_PARITE.A
10.465.04

Vba32 AntiVirus
Virus.Win32.Parite.b
3.12.26.4

VIPRE Antivirus
Win32.Parite.b
48362

ViRobot
Win32.Parite.A[h]
2014.3.20.0

Zillya! Antivirus
Virus.Parite.Win32.9
2.0.0.2760

File size:
5.2 MB (5,416,412 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\programs\cmssetup.v21.exe

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:QDv4xufejkgnVgoD8n4oXEuhFkKZsNHKLeeDDqWqD+83g08Nxqo6tFxxeohv1Qyc:JoGjk2VgoY4opkKqBKLdDqdf3g0U3oen

Entry address:
0x32000

Entry point:
68, 62, 75, 8D, D7, 58, 90, 68, 22, 20, 43, 00, 5A, 90, BF, 98, 05, 00, 00, FF, 34, 3A, 31, 04, 24, 8F, 04, 3A, 90, 83, EF, 03, 4F, 90, 90, 75, EE, 90, 8A, 08, 8C, D7, 62, 75, 8D, D7, 62, 75, CD, D7, 5E, 47, 8D, D7, 67, 9B, C2, D7, BE, 80, C2, D7, 62, C5, 8F, D7, 63, 75, 8D, D7, 02, 05, CD, D7, E6, 0D, CD, D7, F4, 0D, CD, D7, DA, 11, 8D, D7, E0, 0D, 8D, D7, F6, 0D, 8D, D7, 02, 15, 8D, D7, E0, 0D, 8D, D7, F6, 0D, 8D, D7, 62, 75, 8D, D7, 62, 75, 8D, D7, 62, 75, 8D, D7, 62, 75, 8D, D7, F2, 05, CD, D7, 62, 75...
 
[+]

Entropy:
7.9991  (probably packed)

Code size:
23 KB (23,552 bytes)

The file cmssetup.v21.exe has been seen being distributed by the following URL.

Remove cmssetup.v21.exe - Powered by Reason Core Security