garenatotal.exe

The executable garenatotal.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from download.garenatotal.com.
MD5:
e9698195e92cee8b63f2faafc95b2f1a

SHA-1:
18dbf49832c1e44e0945540a7b41dbb9304e0b63

SHA-256:
3149a096928d400b68fed1678db0bfc396674b1f7b315e1d7e56815ee3f73272

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/28/2024 5:43:57 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

AVG
Win32/Sality
2015.0.4604

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
16.06.27

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.E.gen
4.6.5.141

F-Secure
Win32.Sality.3
5.15.96

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.2717.0

Norman
Win32.Sality.3
28.05.2016 15:32:18

VIPRE Antivirus
Threat.4721115
49498

File size:
959.4 KB (982,464 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\garenatotal.exe

File PE Metadata
Compilation timestamp:
8/12/2014 6:50:09 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:tF6kc4UEzrO+wvqEHDgvZmo3w8bydCHkHItNtFoL:KcdoqEjnolbkDHIHkL

Entry address:
0x10BBA

Entry point:
85, F1, 33, FF, 0F, AF, C8, 0F, BF, DD, 69, FD, 47, 1A, E5, 36, 11, ED, 86, D6, 81, C1, 26, 74, F4, FF, 81, FA, 9B, 1E, 00, 00, 71, 08, 81, F8, 7B, 20, 24, 7A, 21, DB, 81, C1, 6E, 5E, 0C, 00, B1, 5B, B3, A7, 69, F1, D5, 21, 0D, 25, B3, D4, C7, C6, 9A, F0, 93, 2D, 87, E8, 81, E9, 7D, E3, 07, 23, E8, 21, 00, 00, 00, 33, C0, 40, 71, 0A, 22, FC, 69, D3, B7, DA, AB, 23, 2B, FD, 45, C6, C6, 15, 0F, AF, EB, 3D, 8F, 02, 00, 00, 0F, 82, E1, FF, FF, FF, 0F, AF, C1, 0F, AF, EE, 4A, F6, C2, 63, 69, EE, 9B, FD, C6, 4C...
 
[+]

Entropy:
7.8609  (probably packed)

Code size:
112 KB (114,688 bytes)

The file garenatotal.exe has been seen being distributed by the following URL.

Remove garenatotal.exe - Powered by Reason Core Security