garenatotal.exe

The executable garenatotal.exe has been detected as malware by 10 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from download.garenatotal.com.
MD5:
7a22ef56259a0797a48c5b8fc51b3ae1

SHA-1:
71a6eda663efe452cfa97e23110dbf04683b6c9b

SHA-256:
9a8730b3800c94d99607ba411ea5d44852836c83b8724900e8a563a0cb0001ad

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/28/2024 5:54:59 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

AVG
Win32/Sality
2015.0.4568

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.735.0

Norman
Win32.Sality.3
28.05.2016 15:32:18

File size:
959.4 KB (982,464 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\garenatotal.exe

File PE Metadata
Compilation timestamp:
8/12/2014 6:50:09 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:xF6kcjUE/DeUD6O+wvqEHDgvZmo3w8bydCHkHItNtFoL:2fBbEoqEjnolbkDHIHkL

Entry address:
0x10BBA

Entry point:
69, F8, BD, 58, 0D, F6, 8D, 15, 3C, BC, 9D, B9, F2, F7, C2, 44, 6C, 94, A0, 8A, E0, 0F, AF, D8, 84, CB, 0F, AF, D5, 87, F1, E8, 23, 00, 00, 00, 20, E1, 8B, DB, F6, C0, BF, 69, E9, EC, 39, BC, 25, 05, 62, 89, F7, FF, C7, C1, 97, 62, AC, 47, F7, C2, 60, 66, 26, 29, 05, 6D, 34, 09, 00, 81, FB, 61, C0, EE, 0F, 85, EE, 77, 07, B0, 84, 80, E6, CA, 12, F3, F6, C1, 29, 1B, C6, 81, ED, 63, 9C, 00, 00, 89, D8, 81, ED, 3E, 13, 00, 00, 5E, 81, EF, B8, EE, 02, 37, FF, C9, 0F, AF, EE, 81, CD, 78, 2E, E2, 36, FE, C7, B3...
 
[+]

Entropy:
7.8609  (probably packed)

Code size:
112 KB (114,688 bytes)

The file garenatotal.exe has been seen being distributed by the following URL.

Remove garenatotal.exe - Powered by Reason Core Security