Threat Database Malware Malware.NSPack.Gen

Malware.NSPack.Gen

By CagedTech in Malware

Threat Scorecard

Popularity Rank: 5,629
Threat Level: 100 % (High)
Infected Computers: 1,266
First Seen: July 24, 2009
Last Seen: January 12, 2026
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Sunbelt Packer.NSAnti.Gen (v)
McAfee-GW-Edition Win32.Malware.gen!92 (suspicious)
Ikarus Virus.Win32.PcClient.WS
eSafe Suspicious File
AVG Generic10.ABBC
Authentium W32/Heuristic-210!Eldorado
a-squared Virus.Win32.PcClient.WS!IK
TrendMicro BKDR_GRAYBIR.AGS
Symantec Backdoor.Graybird
Sophos Mal/Packer
Panda Bck/Hupigon.AZG
McAfee-GW-Edition Trojan.Spy.LooksLike.Banker
K7AntiVirus Trojan.Win32.Malware.1
Comodo Unclassified Malware
Authentium W32/Threat-IKNP.gen!Eldorado

File System Details

Malware.NSPack.Gen may create the following file(s):
# File Name MD5 Detections
1. hmonitor.exe 0ad8b8c94bd8a83dc9f1e6aeaf416351 0

Analysis Report

General information

Family Name: Malware.NSPack.Gen
Signature status: No Signature

Known Samples

MD5: 1ca3b76e8fd91ffe9217b87a5c936466
SHA1: d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8
SHA256: 1462390A12DBEF03CC7B37465EFB012A4D86DA2E99FE4AE7AB2CBDCAE52107BA
File Size: 902.78 KB, 902780 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Shareware
Company Name ABF software, Inc.
File Description ABF Outlook Express Backup
File Version 2.6.9.51
Internal Name ABF Outlook Express Backup
Legal Copyright Copyright © 2000-2008 ABF software, Inc.
Legal Trademarks ABF™
Original Filename abfOutlookExpressBackup.exe
Product Name ABF Outlook Express Backup
Product Version 2.69

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 5
Potentially Malicious Blocks: 3
Whitelisted Blocks: 2
Unknown Blocks: 0

Visual Map

x x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HEUR.Malware.Win32.Posin
  • NSPack.Gen
  • PcClient.L

Files Modified

File Attributes
c:\users\user\downloads\$_temp_$.$$$ Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\log.txt Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\abf software\abf outlook express backup\2.0::localizerext EXE RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
HKLM\software\classes\oeb file:: RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
HKLM\software\classes\oeb file:: ABF Outlook Express Backup data file RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
HKLM\software\classes\oeb file:: ABF Outlook Express Backup data file RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open:: RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open\command:: "c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780" "%1" RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
Show More
HKLM\software\classes\oeb file:: ABF Outlook Express Backup data file RegNtPreCreateKey
HKLM\software\classes\oeb file\defaulticon:: c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780,0 RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open:: RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open\command:: "c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780" "%1" RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
HKLM\software\classes\oeb file:: ABF Outlook Express Backup data file RegNtPreCreateKey
HKLM\software\classes\oeb file\defaulticon:: c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780,1 RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open:: RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open\command:: "c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780" "%1" RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
HKLM\software\classes\oeb file:: ABF Outlook Express Backup data file RegNtPreCreateKey
HKLM\software\classes\oeb file\defaulticon:: c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780,1 RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open:: RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open\command:: "c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780" "%1" RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetComputerName
  • GetUserName
  • GetUserObjectInformation

Trending

Most Viewed

Loading...