ntuser.log

The file ntuser.log has been detected as malware by 18 anti-virus scanners.
MD5:
631aebc636b8fea21f23e69177724c39

SHA-1:
a339e678e02b38cc0e4c829c537c8f824c9790b8

SHA-256:
0d56ca60249af2ce0c9668c097238fa32939a92ff84f51d9e412209127d411e3

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
4/1/2025 8:05:46 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Insight
2013.07.21

Avira AntiVirus
TR/Black.Gen2
7.11.91.90

avast!
Win32:Malware-gen
2014.9-170315

Bitdefender
Gen:Trojan.Heur.ezW@rrSwG8nGb
1.0.20.370

Clam AntiVirus
BC.Heuristic.Trojan.SusPacked.BF-6.A
0.98/18155

Emsisoft Anti-Malware
Gen:Trojan.Heur.ezW@rrSwG8nGb
8.17.03.15.06

ESET NOD32
Win32/Packed.VMProtect.AAN (variant)
11.8590

F-Secure
Gen:Trojan.Heur.ezW@rrSwG8nGb
11.2017-15-03_4

G Data
Gen:Trojan.Heur.ezW@rrSwG8nGb
17.3.22

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1314

McAfee
Artemis!631AEBC636B8
5600.6094

Microsoft Security Essentials
Backdoor:Win32/PcClient.CP
1.163.1557.0

Norman
Obfuscated.CC!genr
11.20170315

Panda Antivirus
Trj/Thed.V
17.03.15.06

Rising Antivirus
Worm.Win32.VBInjectEx.a
23.00.65.17313

Sophos
Mal/Behav-363
4.91

Total Defense
Win32/FakeFLDR_i
37.0.10498

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
19742

File size:
1.1 MB (1,121,792 bytes)

Common path:
C:\windows\ntuser.log

File PE Metadata
Compilation timestamp:
12/21/2012 11:22:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x235BB9

Entry point:
9C, E8, 02, D1, F0, FF, E8, F9, 9A, F0, FF, 8D, 64, 24, 04, 0F, 82, 54, FC, FF, FF, 60, F8, 80, 7F, FF, 00, 9C, 66, 89, 0C, 24, C6, 44, 24, 04, F3, 8D, 64, 24, 24, 0F, 85, BA, 9A, F0, FF, 66, 09, CF, 8B, 7A, 24, 0F, BA, E0, 01, 84, C4, 01, C7, E9, 43, D6, F0, FF, 68, FC, F9, DE, EF, 8D, 64, 24, 38, E8, B6, F4, EF, FF, 60, E9, 4B, C9, F0, FF, E8, 4C, D8, F0, FF, 80, 3F, 23, E8, 4C, BB, F0, FF, 98, 4C, CD, 3B, F2, 69, CB, DB, 34, 49, 21, 83, AB, 6C, 24, 5E, 99, 4D, 0A, FC, B7, 7A, 26, EA, 09, DB, C2, 72, A2...
 
[+]

Entropy:
7.8406  (probably packed)

Code size:
24.5 KB (25,088 bytes)

Remove ntuser.log - Powered by Reason Core Security