enhancer.exe

The executable enhancer.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. This file is typically installed with the program 360Amigo System Speedup PRO by 360Amigo. The file has been seen being downloaded from www.gameszone.ro and multiple other hosts.
MD5:
9d41c4d1a835d09e99b42447e0b25b26

SHA-1:
0ec39e0fdec8ab92af50c58335a164d4466c0bca

SHA-256:
0779289aea5a2056ec435a1354f693fcbd1a152add3c9de21d8117585f6f3862

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
11/5/2024 10:44:15 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.Downloader.W32.Agent
2.1.4+

Agnitum Outpost
Trojan.DL.Agent
7.1.1

Avira AntiVirus
TR/Rogue.7285000.24
7.11.135.168

Bkav FE
W32.Clodd5c.Trojan
1.3.0.4959

Clam AntiVirus
Trojan.Agent-294391
0.98/21411

K7 AntiVirus
Backdoor
13.182.12911

McAfee
Artemis!15B15251E282
5600.7008

Norman
Troj_Generic.HLRKP
11.20140914

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.11.18

Rising Antivirus
PE:Trojan.Agent!6.96D
23.00.65.14103

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
10361

File size:
104.4 KB (106,870 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\enhancer.exe

File PE Metadata
Compilation timestamp:
1/4/2000 10:34:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:fCvfhIu6+dxJ9j9LnO6P5hgrNLSolEEzwvCj2ydgTMyA4WDPbLZHuS5lh:f+fhIuXjVO6eLVUajDaLCPFn5n

Entry address:
0x3669

Entry point:
55, 8B, EC, 81, EC, 18, 03, 00, 00, 56, 57, 6A, 06, BE, 0C, 75, 40, 00, 59, 8D, BD, F0, FE, FF, FF, F3, A5, 6A, 3B, 33, C0, 59, 8D, BD, 08, FF, FF, FF, F3, AB, 8D, 85, E8, FC, FF, FF, 68, 04, 01, 00, 00, 33, F6, 50, 56, FF, 15, 54, 50, 40, 00, 50, FF, 15, 24, 50, 40, 00, 8D, 85, E8, FC, FF, FF, 68, 00, 90, 00, 00, 50, E8, 87, F9, FF, FF, 59, 85, C0, 59, 74, 18, 6A, 30, 68, 24, 75, 40, 00, 68, 34, 75, 40, 00, 56, FF, 15, A4, 50, 40, 00, E9, C4, 01, 00, 00, 80, 3D, 60, 78, 40, 00, 00, 74, 18, 8D, 85, F0, FE...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
16 KB (16,384 bytes)

The file enhancer.exe has been discovered within the following program.

360Amigo System Speedup is a tool of Windows that works quickly in identifying the problem and fix it if there are some mistakes that result in slow system performance.
www.360amigo.com
56% remove it
 
Powered by Should I Remove It?

The file enhancer.exe has been seen being distributed by the following 7 URLs.

http://www.gameszone.ro/.../Enhancer_017.exe

http://indir.gezginler.net/i/1176/.../

Remove enhancer.exe - Powered by Reason Core Security