vremover.exe

The executable vremover.exe has been detected as malware by 9 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from www.analogx.com.
MD5:
f004d11e6b0734b7650d86206a87e1ac

SHA-1:
04c7f13b5944f665585769399e51be7304a6afd1

SHA-256:
012a8c6776b62efb638891daa56ecc5047e69d01a2392a45a6f56d1dfe54a0f8

Scanner detections:
9 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
12/26/2024 5:09:56 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160326-0

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.217.399.0

Norman
Win32.Sality.3
29.03.2016 06:29:16

File size:
424.1 KB (434,248 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\vremover.exe

File PE Metadata
Compilation timestamp:
5/23/2009 10:13:39 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:eefdDoDLMnowxc2mDvJQThwUbviBzbEZFPCDTPhVewTc5JH2VM0jp0jQ9p6c789V:XRoDLmO2mDAwUOFYa/PhMwI2Vbzpd8r

Entry address:
0x12357

Entry point:
8D, 1D, ED, 2D, D6, 76, FF, C5, EB, 04, B1, 6B, FF, C1, C6, C4, E9, EB, 0A, 81, DE, 28, 5C, 10, 44, 85, D9, 34, AC, F6, C4, 9F, 8A, C2, 12, EE, 68, 33, 0C, C8, 00, 53, 4A, 80, F3, 92, E8, 2C, 00, 00, 00, 89, F0, 81, FF, 75, 2A, 00, 00, 73, 02, 87, CE, 05, B0, D7, 5F, E0, B8, 1C, 2E, 37, AF, 8D, 15, 5F, AC, 00, 00, C6, C1, 60, F7, C5, DA, CB, EB, EE, 4E, 81, C2, B1, 0B, 00, 00, FF, C1, 8A, C8, 77, 02, FF, C8, 85, DE, 3B, D6, 83, E6, 00, F6, C2, 4F, 85, D5, 73, 06, 40, 80, EA, 26, 87, DB, 1D, 89, 35, AF, 0D...
 
[+]

Code size:
119.5 KB (122,368 bytes)

The file vremover.exe has been seen being distributed by the following URL.

Remove vremover.exe - Powered by Reason Core Security