Threat Database Malware Malware.NSPack.Gen

Malware.NSPack.Gen

By CagedTech in Malware

Threat Scorecard

Popularity Rank: 5,375
Threat Level: 100 % (High)
Infected Computers: 1,287
First Seen: July 24, 2009
Last Seen: March 1, 2026
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Sunbelt Packer.NSAnti.Gen (v)
McAfee-GW-Edition Win32.Malware.gen!92 (suspicious)
Ikarus Virus.Win32.PcClient.WS
eSafe Suspicious File
AVG Generic10.ABBC
Authentium W32/Heuristic-210!Eldorado
a-squared Virus.Win32.PcClient.WS!IK
TrendMicro BKDR_GRAYBIR.AGS
Symantec Backdoor.Graybird
Sophos Mal/Packer
Panda Bck/Hupigon.AZG
McAfee-GW-Edition Trojan.Spy.LooksLike.Banker
K7AntiVirus Trojan.Win32.Malware.1
Comodo Unclassified Malware
Authentium W32/Threat-IKNP.gen!Eldorado

File System Details

Malware.NSPack.Gen may create the following file(s):
# File Name MD5 Detections
1. hmonitor.exe 0ad8b8c94bd8a83dc9f1e6aeaf416351 0

Analysis Report

General information

Family Name: Malware.NSPack.Gen
Signature status: No Signature

Known Samples

MD5: 1ca3b76e8fd91ffe9217b87a5c936466
SHA1: d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8
SHA256: 1462390A12DBEF03CC7B37465EFB012A4D86DA2E99FE4AE7AB2CBDCAE52107BA
File Size: 902.78 KB, 902780 bytes
MD5: c0efa71dea51369f0d6f8912f4849959
SHA1: b579e3577e891eb447324602c1b1b59abbcd3929
SHA256: 7E5A929065441BF4AABF60BAF95636D40B40123DD0CD77F93C334ADD7C90C67D
File Size: 695.57 KB, 695567 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Shareware
Company Name
  • ABF software, Inc.
  • ElcomSoft Co.Ltd.
File Description
  • ABF Outlook Express Backup
  • AVPR Application
File Version
  • 2.6.9.51
  • 1.63
Internal Name
  • ABF Outlook Express Backup
  • AVPR
Legal Copyright
  • Copyright © 2000-2008 ABF software, Inc.
  • © 1999-2007 ElcomSoft Co.Ltd.
Legal Trademarks ABF™
Original Filename
  • abfOutlookExpressBackup.exe
  • AVPR.exe
Product Name
  • ABF Outlook Express Backup
  • Advanced VBA Password Recovery
Product Version
  • 2.69
  • 1.63

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 5
Potentially Malicious Blocks: 3
Whitelisted Blocks: 2
Unknown Blocks: 0

Visual Map

x x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HEUR.Malware.Win32.Posin
  • NSPack.Gen
  • PcClient.L

Files Modified

File Attributes
c:\users\user\downloads\$_temp_$.$$$ Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\log.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\avpr.ini Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\abf software\abf outlook express backup\2.0::localizerext EXE RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
HKLM\software\classes\oeb file:: RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
HKLM\software\classes\oeb file:: ABF Outlook Express Backup data file RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
HKLM\software\classes\oeb file:: ABF Outlook Express Backup data file RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open:: RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open\command:: "c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780" "%1" RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
Show More
HKLM\software\classes\oeb file:: ABF Outlook Express Backup data file RegNtPreCreateKey
HKLM\software\classes\oeb file\defaulticon:: c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780,0 RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open:: RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open\command:: "c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780" "%1" RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
HKLM\software\classes\oeb file:: ABF Outlook Express Backup data file RegNtPreCreateKey
HKLM\software\classes\oeb file\defaulticon:: c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780,1 RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open:: RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open\command:: "c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780" "%1" RegNtPreCreateKey
HKLM\software\classes\.oeb2:: OEB File RegNtPreCreateKey
HKLM\software\classes\oeb file:: ABF Outlook Express Backup data file RegNtPreCreateKey
HKLM\software\classes\oeb file\defaulticon:: c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780,1 RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open:: RegNtPreCreateKey
HKLM\software\classes\oeb file\shell\open\command:: "c:\users\user\downloads\d6a2d6688fbfffe8d7cdcb3373c16e502b4a77e8_0000902780" "%1" RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetComputerName
  • GetUserName
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState

Trending

Most Viewed

Loading...