NewFolder.exe

winexploer

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘win’.
Product:
winexploer

Version:
1.00

MD5:
2d6b73a733a5baf9e1db75cab2d3f74a

SHA-1:
b2df9f2aa0f176ddaab3cff2216239c5d2c642ce

SHA-256:
e94d6972eb07a2d4094c1037f3935076a38dda22feed67b6cd1acea2b75281fb

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/1/2025 8:28:15 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Worm.Agent-337485
0.98/23207

File size:
732 KB (749,568 bytes)

Product version:
1.00

Original file name:
NewFolder.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\newfolder.exe

File PE Metadata
Compilation timestamp:
7/5/1997 11:27:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x9F02F

Entry point:
03, C7, C6, C0, 53, 87, F6, 70, 03, 0F, BE, EC, 8A, C9, F6, C6, 1F, 40, 69, DE, 77, D9, 48, B2, 2B, F5, BA, AF, 01, 00, 00, 12, C7, 41, 81, C2, C2, 02, 00, 00, 69, EF, CE, 05, 79, ED, 86, EA, 4E, F7, C0, 46, 70, 2F, 15, 6B, F6, 00, C7, C0, 30, DB, 61, 8A, 89, CD, 85, CB, 0F, BF, EE, 86, F1, 41, BD, 23, 0E, E4, 1A, 88, D5, 8B, C9, F6, C2, D5, 0F, AF, FE, 88, E1, BB, 2E, 00, 00, 00, F2, 6B, DB, 02, 87, CD, F7, C5, 4A, 7D, D8, 7E, 0F, BF, EF, 53, 45, 5A, 85, F5, 76, 09, 8D, 3D, 51, 26, 28, F9, 80, FD, F0, F3...
 
[+]

Entropy:
2.3669

Code size:
36 KB (36,864 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
win

Command:
C:\windows\newfolder.exe


Scan NewFolder.exe - Powered by Reason Core Security