mseinstalls.exe

The executable mseinstalls.exe has been detected as malware by 19 anti-virus scanners. The file has been seen being downloaded from www.micerrors.co.
MD5:
b3901bdf433381a1c1bd14d3ef538d6f

SHA-1:
73151450b256dc0c08a6cda7168fed95e28b17fb

SHA-256:
4c64dc1332a115d5ad1e9b1e106fb2f33e53f9bc174d12b550be33cec13d436a

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
12/26/2024 12:55:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.19431
379

Arcabit
Trojan.Barys.D4BE7
1.0.0.646

avast!
BV:KeyboardDisable-C [Trj]
2014.9-160121

AVG
BAT/Disabler.B
2017.0.2857

Bitdefender
Gen:Variant.Barys.19431
1.0.20.105

Dr.Web
BATCH.Virus
9.0.1.021

Emsisoft Anti-Malware
Gen:Variant.Barys.19431
8.16.01.21.09

ESET NOD32
BAT/KeyboardDisable
10.12905

Fortinet FortiGate
MSIL/Agent.OBO!tr
1/21/2016

F-Secure
Gen:Variant.Barys.19431
11.2016-21-01_5

G Data
Gen:Variant.Barys.19431
16.1.25

IKARUS anti.virus
BAT.KillAV
t3scan.1.9.5.0

McAfee
Artemis!B3901BDF4333
5600.6513

Microsoft Security Essentials
Trojan:MSIL/Krolol.A
1.1.12400.0

MicroWorld eScan
Gen:Variant.Barys.19431
17.0.0.63

NANO AntiVirus
Trojan.Script.Agent.cnisov
1.0.14.5380

Qihoo 360 Security
QVM41.1.Malware.Gen
1.0.0.1077

Quick Heal
Ransom.Gimemo.C4
1.16.14.00

Zillya! Antivirus
Trojan.Injector.Win32.326271
2.0.0.2623

File size:
317.7 KB (325,329 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\mseinstalls.exe

File PE Metadata
Compilation timestamp:
10/2/2015 1:17:40 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:4b+v4XzknwCzkizjyj1JTsnjQR2buP2GLagB:4av4XonvzkiPTnEv+GLl

Entry address:
0x1DA6B

Entry point:
E8, 85, 63, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 82, FC, FF, FF, C7, 06, 90, B2, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, 90, B2, 42, 00, E9, 37, FD, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, 90, B2, 42, 00, E8, 24, FD, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 8E, CA, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Entropy:
7.2757

Code size:
163 KB (166,912 bytes)

The file mseinstalls.exe has been seen being distributed by the following URL.

Remove mseinstalls.exe - Powered by Reason Core Security