winregistorss.exe

gizli chromee

The executable winregistorss.exe has been detected as malware by 17 anti-virus scanners. The file has been seen being downloaded from feidowns.com.
Product:
gizli chromee

Version:
1.0.0.0

MD5:
99816c94af76aa54ca804ec0344fb806

SHA-1:
08da073a01145d98d73a4fae8df5fde577bd50e7

SHA-256:
5f53abe362a5b32dd7b63261b4f561ca8aec071574f31242f1366960bdb93956

Scanner detections:
17 / 68

Status:
Malware

Analysis date:
11/27/2024 8:48:46 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.DownLoader
7.1.1

avast!
Win32:Malware-gen
2014.9-160115

AVG
Generic36
2017.0.2864

Bkav FE
W32.Clodbd3.Trojan
1.3.0.7237

Dr.Web
Trojan.DownLoader13.1583
9.0.1.015

ESET NOD32
MSIL/TrojanClicker.Agent.NLU
10.12293

Fortinet FortiGate
Tfr.EM!tr
1/15/2016

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.9.5.0

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.815

McAfee
RDN/Generic.tfr!em
5600.6520

NANO AntiVirus
Trojan.Win32.DownLoader13.drctem
0.30.24.3283

Panda Antivirus
Trj/Chgt.O
16.01.15.02

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D[F1]
23.00.65.16113

Trend Micro
TROJ_GEN.R02ZC0OE415
10.465.15

VIPRE Antivirus
Trojan.Win32.Generic
43966

ViRobot
Trojan.Win32.S.Agent.10752.HK[h]
2014.3.20.0

File size:
10.5 KB (10,752 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Chrome.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\winregistorss.exe

File PE Metadata
Compilation timestamp:
4/22/2015 10:30:23 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
192:W+AryGNQ/m6yj4e/eWFJI/8VX+y14Lj6Mh9:X+6he/nJY8B+Y4LjJ

Entry address:
0x3F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.9937

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
8 KB (8,192 bytes)

The file winregistorss.exe has been seen being distributed by the following URL.

Remove winregistorss.exe - Powered by Reason Core Security