openal32.exe

Proxomitron

SBIS

The application openal32.exe by SBIS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Groom-A-Zebu (tm)   (signed by SBIS)

Product:
Proxomitron

Description:
The Proxomitron

Version:
4, 5, 0, 4

MD5:
77f3ede8a253ef2616d22b46b4d93a23

SHA-1:
851f181aa1b03a69e86c7ff41abc106d1ef5c57a

SHA-256:
54bb6bc8b0ae2bfb696b951fa46934c3f48506bbddee99212ba38f5c05a6de52

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 7:46:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.20.10

File size:
578.4 KB (592,312 bytes)

Product version:
Naoko-4.5 2003-6-1

Copyright:
Copyright © 1999 - 2003 By Scott R. Lemmon

Trademarks:
Proxomitron, The, and the letters A-Z

Original file name:
Proxomitron.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\openal32.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/3/2015 4:00:00 AM

Valid to:
5/3/2016 3:59:59 AM

Subject:
CN=SBIS, O=SBIS, STREET="PR-T MOSKOVSKIJ, 12", L=YAROSLAVL, S=YAROSLAVL REGION, PostalCode=150001, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009CA0BE54A9516364680AD45D6408C6A2

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x75F1E

Entry point:
60, 55, E8, A5, 15, 00, 00, 00, 00, 53, 65, 74, 53, 79, 73, 74, 65, 6D, 54, 69, 6D, 65, 00, 46, 68, 0F, 0B, D9, 3D, 47, 68, 1A, 82, 86, 81, 66, 89, 0C, 24, C6, 44, 24, 0C, BD, 88, 44, 24, 0C, 8D, 64, 24, 2C, E9, 0E, A2, 00, 00, 00, 00, 49, 6D, 61, 67, 65, 4C, 69, 73, 74, 5F, 53, 65, 74, 49, 63, 6F, 6E, 53, 69, 7A, 65, 00, 83, C7, 01, F8, 10, E0, 00, D8, 34, D2, 8A, 07, 60, E9, 1A, 3C, 00, 00, 00, 00, 6C, 73, 74, 72, 63, 6D, 70, 69, 41, 00, BB, 7A, E5, 8E, 82, E7, B1, BB, 2A, 0E, F5, 72, DC, 98, A7, FE, C1...
 
[+]

Code size:
404.5 KB (414,208 bytes)

Remove openal32.exe - Powered by Reason Core Security