garenatotal.exe

The executable garenatotal.exe has been detected as malware by 5 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download.garenatotal.com.
MD5:
1b55759d6c0c3c6008c5c05c80eca94f

SHA-1:
e02ec21dbd3244b54673cd62088802df49093072

SHA-256:
b33ee039b79ae1337b3b50fe4024c73aff0b45cf8e5b938738c0b32ea17bdff3

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
11/28/2024 5:35:53 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160708-3

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.1693.0

VIPRE Antivirus
Threat.4758034
50516

File size:
963.4 KB (986,560 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\garenatotal.exe

File PE Metadata
Compilation timestamp:
8/12/2014 2:50:09 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:hF6kciUESqaLsO+wvqEHDgvZmo3w8bydCHkHItNtFoL:G+eKoqEjnolbkDHIHkL

Entry address:
0x10BBA

Entry point:
B6, 64, 0F, CE, 73, 03, 41, 86, DC, 33, E8, 45, 57, 43, F6, DE, 68, 80, 2A, 07, 00, 3D, 71, 32, 00, 00, 72, 06, 8D, 05, C1, A3, AC, 07, E8, 2F, 00, 00, 00, 81, EF, 70, 44, 9A, 33, FE, C6, 71, 03, 0F, BE, EC, 2B, F2, C6, C5, 55, 8D, 01, 87, F1, F7, C7, 30, 56, 41, E8, 50, 75, 06, 8D, 35, B6, A7, 9B, 69, 5A, F7, D7, 3C, 91, 33, DA, 0F, AF, CA, 8D, 0D, 37, 99, 7E, 0A, 85, F0, BF, E8, 9E, D1, 09, 68, AE, 6B, 00, 00, 5E, 81, F6, 24, 37, 00, 00, 5E, 81, E9, 65, 18, C6, 4B, F7, D9, 81, FF, 01, 1A, 00, 00, 0F, 6E...
 
[+]

Code size:
112 KB (114,688 bytes)

The file garenatotal.exe has been seen being distributed by the following URL.

Remove garenatotal.exe - Powered by Reason Core Security