emusic_installer.exe

The executable emusic_installer.exe has been detected as malware by 10 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from download.nullsoft.com.
MD5:
2ecf15bafd98ccbad5e5fc73e1d90777

SHA-1:
27b605823e6057d98853f369c61d8b1370301e34

SHA-256:
a8a92186d59460faf8955cece892e2e6177e0a7a81f1332bf0e0b98541ac442e

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
12/25/2024 12:01:56 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160414-2

AVG
Win32/Sality
2015.0.4568

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.E.gen
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.755.0

Norman
Win32.Sality.3
19.05.2016 01:04:49

File size:
156.7 KB (160,496 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\emusic_installer.exe

File PE Metadata
Compilation timestamp:
2/8/2008 11:25:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:+d/cyWmJjwCUNN0KoyPTWH22kYS5+2LWd4RmIr3O60DhQLeptS:+aKwVfoKSwYS5+WfFLO60lnLS

Entry address:
0x3225

Entry point:
81, CE, 80, E7, 6D, 64, 69, FD, CC, A2, C7, 36, 88, EC, 2B, FF, 89, D7, 84, C8, 80, F8, 71, 88, E0, EB, 07, 40, 0F, AF, DF, 0F, AF, C2, FE, CB, 69, FF, 42, 34, 37, 14, 8D, 2D, CF, 11, 00, 00, F7, C7, 83, 70, 38, 8F, 81, F5, 66, 0A, 00, 00, 69, DF, C7, 41, 79, 9D, 55, 88, D8, 8A, E1, 1B, D8, 5A, F2, 87, C7, 12, E3, 81, EA, 3C, 0A, 00, 00, F7, C0, AF, E6, 7C, 21, F6, C0, 84, 33, CA, 88, E7, 18, DD, C6, C4, D0, 81, E6, 6B, E2, F9, 0B, 83, E0, 00, F3, 89, FA, 8D, 35, A1, D3, 61, 06, 84, E1, F2, 76, 0D, 87, D6...
 
[+]

Entropy:
7.7666  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file emusic_installer.exe has been seen being distributed by the following URL.

Remove emusic_installer.exe - Powered by Reason Core Security