help_1.exe

The executable help_1.exe has been detected as malware by 25 anti-virus scanners.
MD5:
58839fda6bfeb397f34ae5828069544a

SHA-1:
f3583227f5cacb73d1fcf09d31d526a81d36d191

SHA-256:
0f88ee0b353602a44daf8d1eef5e3c47b7ba6bcbcb511b17e6a3ca567521b1aa

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
4/1/2025 8:05:47 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Foreign
7.1.1

Avira AntiVirus
TR/Rogue.KD.828641
7.11.61.126

AVG
Generic31
2018.0.2439

Bitdefender
Trojan.Generic.KD.828641
1.0.20.370

Comodo Security
UnclassifiedMalware
15287

Dr.Web
Trojan.DownLoad.64645
9.0.1.074

ESET NOD32
Win32/TrojanDownloader.Agent.RPE
11.8020

Fortinet FortiGate
W32/Foreign.XVI!tr
3/15/2017

F-Secure
Trojan.Generic.KD.828641
11.2017-15-03_4

G Data
Trojan.Generic.KD.828641
17.3.22

IKARUS anti.virus
Trojan-Ransom.Win32.Foreign
t3scan.2.0.0.0

K7 AntiVirus
Trojan
13.160.8224

Kaspersky
Trojan-Ransom.Win32.Foreign
14.0.0.-1312

McAfee
Artemis!58839FDA6BFE
5600.6095

MicroWorld eScan
Trojan.Generic.KD.828641
18.0.0.222

NANO AntiVirus
Trojan.Win32.DownLoad.berjsp
0.22.8.50287

Norman
Downloader.HEDS
11.20170315

nProtect
Trojan/W32.Small.4608.JH
13.02.17.01

Panda Antivirus
Trj/CI.A
17.03.15.10

Quick Heal
TrojanRansom.Foreign.xvi
3.17.12.00

Sophos
Mal/Generic-S
4.86

Trend Micro House Call
TROJ_GEN.RCBZ7AP
7.2.74

Trend Micro
TROJ_GEN.RCBZ7AP
10.465.15

Vba32 AntiVirus
Hoax.Foreign.xvi
3.12.20.2

VIPRE Antivirus
Trojan.Win32.Generic
15606

File size:
4.5 KB (4,608 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\autoplay\docs\help_1.exe

File PE Metadata
Compilation timestamp:
12/15/2012 10:33:59 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

Entry address:
0x105D

Entry point:
C7, 05, 51, 32, 40, 00, 08, 00, 00, 00, C7, 05, 59, 32, 40, 00, 08, 00, 00, 00, 68, 51, 32, 40, 00, E8, 91, 04, 00, 00, BE, 00, 00, 60, 00, 6A, 00, 6A, 00, E8, 89, 04, 00, 00, 4E, 75, F4, 6A, 00, 6A, 00, 6A, 00, 6A, 00, 6A, 02, E8, 7D, 04, 00, 00, 6A, 00, 6A, 00, 6A, 00, 6A, 00, 6A, 04, E8, 6E, 04, 00, 00, 68, 59, 32, 40, 00, E8, 58, 04, 00, 00, 6A, 00, 6A, 40, 6A, 76, 68, 00, 30, 40, 00, E8, 30, 04, 00, 00, 68, 01, 32, 40, 00, E8, 32, FF, FF, FF, 68, 0C, 32, 40, 00, E8, 28, FF, FF, FF, 8D, 05, 00, 30, 40...
 
[+]

Entropy:
3.1656

Code size:
1.5 KB (1,536 bytes)

Remove help_1.exe - Powered by Reason Core Security