f61721032.exe threat report

MD5 a9442b195443f8ef912d04ee36c54d2f
Latest seen 2023-04-01 23:06:28 (3 years ago)
First seen 2023-04-01 23:06:28 (3 years ago)
Size 6 MB
Publisher Intel Corporation

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Generic. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Generic
Recommended action
Scan and remove
Last analysis
2023-04-01 23:06:28 (3 years ago)
File hash
a9442b195443f8ef912d04ee36c54d2f
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Generic.

Timeline

First seen 2023-04-01 23:06:28 (3 years ago); latest analysis 2023-04-01 23:06:28 (3 years ago).

Publisher context

Company metadata: Intel Corporation. Product metadata: Intel® Wireless WiFi Link Adapter.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

f61721032.exe is a Windows file recorded in the ThreatInfo database. It is associated with Intel® Wireless WiFi Link Adapter. The reported company name is Intel Corporation. The current detection status is Trojan.Generic, based on the latest analysis from 2023-04-01 23:06:28 (3 years ago).

If f61721032.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Generic.

Product Name: Intel® Wireless WiFi Link Adapter
Company Name: Intel Corporation
MD5: a9442b195443f8ef912d04ee36c54d2f
Size: 6 MB
First Published: 2023-04-01 23:06:28 (3 years ago)
Latest Published: 2023-04-01 23:06:28 (3 years ago)
Status: Trojan.Generic (on last analysis)
Analysis Date: 2023-04-01 23:06:28 (3 years ago)
f61721032.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%desktop%\recuperados

ThreatInfo has observed f61721032.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Mexico with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for f61721032.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

f61721032.exe is identified as pe for 64 systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x00024a28

PE Sections:

Name Size of data MD5
.text 2896384 312737e565a57eba0d9ba8fa386cec51
.rdata 632320 a8eced0e902e3c644060f8356e435f3c
.data 127488 e39fc37bfcd9b142c32291eac4645b89
.pdata 183808 9b09e22e8d913c27c354e9b79c82e0c0
PAGEcsrv 86016 5fbeda553a1a9db47b83b36ba166f3dc
PAGEcjaw 88576 72417909c875ec98f7a925ae70558bb3
PAGEcwfd 61952 0303f97faed74cf9ac62d68658cbb1e5
PAGE 1536 4726c51a7277c45be05b4ab63f5a04b4
PAGEcnlo 1024 39b2d1768036f8a1746c12c3a6edff33
PAGEccln 52224 e8e4a8d22eadac5c3eb33f8f7d200ca0
PAGEcsec 30208 7a8ffcd82bebe21a13ead58d9cdc43b2
PAGEcsv_ 57856 866a603cbad05e9cd6a48a1f75f37ec6
PAGEcimg 5120 59d45eb37d294e3cc594a4e87c0e4cb7
PAGEcast 10752 9e1a109d787b934b4bfce9426552ec16
PAGEcpsm 7168 170bad2b57f36eabb3b95990f227b515
PAGEcctw 2560 a250e4e26efa79ae06ddcb2fb59f4b58
PAGEdoid 28672 faf756010b4912d671e0122eb26dc05e
PAGEdcln 3584 c9d738cf2be7831065c21a072d3e7444
PAGEdsv_ 2560 f160403194d5fabee31246df7fa27088
PAGEdreg 256000 05cd0d9623f9c875593cb2da97f9b6a7
PAGEdscn 512 8672a4d2ffffe8b8c4936f2ef2b283f0
PAGEdwi1 2560 885122e78c3de96f398e20f238ada489
PAGEdwi2 2560 62801ac4f90f228e52922027fc3a6e4c
PAGEdStn 2560 a81f25edd843b9a509ba55c9af821d32
PAGEdSnF 2560 d5ff6a0e2b764b981f1446c2184ce18f
PAGEdPsr 2048 98a96eb2a848fd5c1e09215dd4bfae15
PAGEdjaw 1536 34e2efc4fc1d289ae6689d219cedf857
PAGEdimg 2048 ef6625aa7ea09c0fc9c3a7c54ab3f176
PAGEdctw 512 f794dcd5b00d814d12cac3ee63e5039c
PAGEdrlg 2097152 b2d1236c286a3c0704224fe4105eca49
INIT 4608 1a040caf07a10070e540c3d68efa37c8
.rsrc 27648 d8556a3bc5f20f7ef39995bb6dd633ff
.reloc 20480 d0f4a050fe5c18eb648e980c76da7034

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: