nirsoft_package_1.18.41.zip

The file nirsoft_package_1.18.41.zip has been detected as a potentially unwanted program by 27 anti-malware scanners. The file has been seen being downloaded from download.nirsoft.net.
MD5:
083f758043d5342aa36a2429bb36693d

SHA-1:
797d01cdd4ccb0d36d546f9b090b3fecbadb4ab1

SHA-256:
582539b0dfb43327e7899c646888ae9718e7fd0fcf1062d3b50f0b4bef369909

Scanner detections:
27 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 6:06:31 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Heur.nq1@bW27KWfO
1110

Agnitum Outpost
Riskware.PSWTool
7.1.1

Avira AntiVirus
SPR/PSW.Asterisk.C
7.11.125.108

avast!
Win32:PSWtool-D [PUP]
2014.9-140121

AVG
Logger
2015.0.3588

Baidu Antivirus
HackTool.Win32.WinPassViewer
4.0.3.14121

Bitdefender
Gen:Application.Heur.nq1@bW27KWfO
1.0.20.105

Comodo Security
UnclassifiedMalware
17619

ESET NOD32
Win32/PSWTool.AsteriskLogger.104
8.9296

Fortinet FortiGate
Riskware/PassView
1/21/2014

F-Prot
W32/Pwstool.J
v6.4.7.1.166

F-Secure
Gen:Application.Heur.nq1@bW27KWfO
11.2014-21-01_3

G Data
Gen:Application.Heur.nq1@bW27KWfO
14.1.24

IKARUS anti.virus
not-a-virus:Monitor.Win64
t3scan.2.2.29

K7 AntiVirus
Password-Stealer
13.175.10852

Kaspersky
not-a-virus:PSWTool.Win32.Asterisk
14.0.0.4433

Malwarebytes
HackTool.Asterisk
v2014.01.21.09

McAfee
Tool-PassView
5600.7244

Microsoft Security Essentials
HackTool:Win32/Dialupas
1.165.247.01

MicroWorld eScan
Gen:Application.Heur.nq1@bW27KWfO
15.0.0.63

NANO AntiVirus
Riskware.Win32.PassView.cbiwl
0.28.0.57029

Norman
Suspicious_Gen2.VYJX
11.20140121

Panda Antivirus
Application/RemoteDesktopPassView
14.01.21.09

Rising Antivirus
PE:Stealer.Netpass!6.E49
23.00.65.14119

Sophos
Adapter Watch
4.96

Trend Micro House Call
TROJ_GEN.F47V0114
7.2.21

VIPRE Antivirus
Trojan.Win32.Generic
25462

File size:
18.7 MB (19,630,623 bytes)

Common path:
C:\users\{user}\downloads\nirsoft.net\nirlauncher\nirsoft_package_1.18.41.zip

The file nirsoft_package_1.18.41.zip has been seen being distributed by the following URL.

Remove nirsoft_package_1.18.41.zip - Powered by Reason Core Security