windowsphonerecoverytoolinstaller.exe

Windows Phone Recovery Tool 2.1.2

Microsoft

The executable windowsphonerecoverytoolinstaller.exe has been detected as malware by 40 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. Infected by a mass-mailing worm and virus that sends itself to email addresses gathered from the compromised computer and exploits remote vulnerabilities and attempts to infect files. The file has been seen being downloaded from windows-phone-recovery-tool.software.informer.com.
Publisher:
Microsoft

Product:
Windows Phone Recovery Tool 2.1.2

Version:
2.1.2

MD5:
691c46fbca85eb3a1b436453cd24db4a

SHA-1:
cac47b8d739c7f1eea4cac3b41bf66515df0490b

SHA-256:
88af9153dc7c8f45b4e225ac754a079bd2b9cf8258fbfddc86416f6fcc1e8b94

Scanner detections:
40 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/30/2024 10:37:56 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Runouce.B@mm
5745058

Agnitum Outpost
I-Worm.Chir.B
7.1.1

AhnLab V3 Security
Win32/ChiHack.6652
2015.11.11

Avira AntiVirus
W32/Chir.B
8.3.2.2

Arcabit
Win32.Runouce.E2C45E
1.0.0.593

avast!
Win32:Oncer
151028-1

AVG
Win32/Chir.B@mm
2015.0.4355

Baidu Antivirus
Virus.Win32.Runouce.$a
4.0.3.151111

Bitdefender
Win32.Runouce.B@mm
1.0.20.1575

Bkav FE
W32.ChirBPE
1.3.0.7383

Clam AntiVirus
WIN.Worm.Brontok
0.98/21050

Comodo Security
EmailWorm.Win32.Runonce.~v001
23568

Dr.Web
Win32.Runonce.6652
9.0.1.05190

Emsisoft Anti-Malware
Win32.Runouce.B@mm
10.0.0.5366

ESET NOD32
Win32/Chir.B virus
7.0.302.0

Fortinet FortiGate
W32/Chir.B@mm
11/11/2015

F-Prot
W32/Thecid.B@mm
4.6.5.141

F-Secure
Win32.Runouce.B@mm
5.15.21

G Data
Win32.Runouce.B@mm
15.11.25

IKARUS anti.virus
Email-Worm.Win32.Runouce
t3scan.1.9.5.0

K7 AntiVirus
EmailWorm
13.212.17810

Kaspersky
Email-Worm.Win32.Runouce
15.0.0.562

McAfee
Virus.W32/Chir.b@MM
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.209.2360.0

MicroWorld eScan
Win32.Runouce.B@mm
16.0.0.945

NANO AntiVirus
Trojan.Win32.IframeExec.dteiuc
0.30.26.4437

Norman
Win32.Runouce.B@mm
07.10.2015 03:16:12

nProtect
Win32.Runouce.B@mm
15.11.10.01

Panda Antivirus
Generic Malware
15.11.11.05

Qihoo 360 Security
Virus.Win32.CNHacker.C
1.0.0.1077

Quick Heal
W32.Runouce.B
11.15.14.00

Rising Antivirus
PE:Worm.Mail.ChineseHacker!245783 [F]
23.00.65.151109

Sophos
Virus 'W32/Chir-B'
5.20

Total Defense
Win32/Chir.B
37.1.62.1

Trend Micro House Call
PE_Chir.B
7.2.315

Trend Micro
PE_Chir.B
10.465.11

Vba32 AntiVirus
Virus.Win32.Chur.A
3.12.26.4

VIPRE Antivirus
Threat.219451
45000

ViRobot
Win32.Chir.B[h]
2014.3.20.0

Zillya! Antivirus
Worm.RunOnce.Win32.2
2.0.0.2503

File size:
2.2 MB (2,303,836 bytes)

Product version:
2.1.2

Copyright:
Copyright (c) Microsoft. All rights reserved.

Original file name:
Bootstrapper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\windowsphonerecoverytoolinstaller.exe

File PE Metadata
Compilation timestamp:
12/8/2014 2:44:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:Ki+nwxGDdPYl+Ij5XmZHb0HNUMpJvXl1AdtyZnSw+7OTwbR9XWIQZBFdt2/HsTgy:UnwLl+IQdNMF0yRy9XEFbvwi6anqk

Entry address:
0x237960

Entry point:
60, E8, E6, 19, 00, 00, 8B, 74, 24, 20, E8, 08, 00, 00, 00, 61, 68, 5F, 94, 42, 00, C3, E9, 59, E8, 01, 16, 00, 00, 81, E6, 00, F0, FF, FF, 81, EE, 00, 10, 00, 00, 66, 81, 3E, 4D, 5A, 75, F3, 0F, B7, 7E, 3C, 03, FE, 8B, 6F, 78, 03, EE, 8B, 5D, 20, 03, DE, 33, C0, 8B, D6, 83, C3, 04, 40, 8B, 3B, 03, FA, E8, 0F, 00, 00, 00, 47, 65, 74, 50, 72, 6F, 63, 41, 64, 64, 72, 65, 73, 73, 00, 5E, 33, C9, B1, 0F, FC, F3, A6, 75, DA, 8B, F2, 8B, 5D, 24, 03, DE, 0F, B7, 0C, 43, 8B, 5D, 1C, 03, DE, 8B, 1C, 8B, 03, DE, 81...
 
[+]

Entropy:
7.4214

Packer / compiler:
ASPack v1.08.04

Code size:
270.5 KB (276,992 bytes)

The file windowsphonerecoverytoolinstaller.exe has been seen being distributed by the following URL.

Remove windowsphonerecoverytoolinstaller.exe - Powered by Reason Core Security