File Name | Data USER.exe |
File Type |
MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.172.174 |
Database Version | 2024-04-21 21:00:34 UTC |
Malware family: Brontok
Hash Type | Value | Action |
---|---|---|
MD5 |
483fcf432217d71544246aa760d98cdc
|
|
SHA1 |
591b0ec52ad2a306f1cf8af2fc04125642b1a00b
|
|
SHA256 |
70d98b736c32160617e8e272c2f5b2c10c72789fe40e27ec16f94ffa09394cd7
|
|
SHA512 |
c416acf7af8eaf9c6e331e4097bdc79ffb5fc07f8b932649683ecacc5db94f6b9208cd4795da5b488e9b86336940f62b7414432a38a63d57c963697ad868eebd
|
|
ImpHash |
87bed5a7cba00c7e1f4015f1bdae2183
|
Icon |
Hash: cb8ca8744b35c8e1d033f74621df0f24
Fuzzy: c2868c2d812011c6df4676a5be1951a7 dHash: 00ccc4d4ccf4fc0c |
Image Base | 0x00400000 |
Entry Point | 0x0042f4a6 |
Compilation Time | 1970-01-01 00:00:00 |
Checksum | 0x00000000 (Actual: 0x00011d8b) |
OS Version | 4.0 |
PEiD Signatures |
MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | The PE file does not contain a certificate table. |
Imports |
1 libraries
kernel32 |
Exports | 0 functions |
Resources | 4 Resources |
Sections | 0 Sections |
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 3 | 11,448 bytes | |
RT_GROUP_ICON | 1 | 48 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
The PE file does not contain a certificate table.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Worm.Win32.Brontok.vb without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system