28395dc6a2ae459386feac2fd5fb3b60.exe

28395dc6a2ae459386feac2fd5fb3b60

The application 28395dc6a2ae459386feac2fd5fb3b60.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named BZQENOXPF triggered daily at a specified time.
Product:
28395dc6a2ae459386feac2fd5fb3b60

Version:
1.0.0.2120

MD5:
2142c88945f45704103948caf7c768e6

SHA-1:
1a1120606f02be15ed8d9bddcaabe00b666f40c0

SHA-256:
8df6572b902499772c03caf45ffbd9df20d240201e0b7b7e4cb9f233758c6fce

Scanner detections:
21 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 10:15:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.537663
6496598

Agnitum Outpost
PUA.PicColor
7.1.1

Avira AntiVirus
Adware/PicColor.506880.2
7.11.204.220

avast!
Win32:Malware-gen
150129-1

AVG
Adware Generic6.LEM
2014.0.4257

Baidu Antivirus
Adware.Win32.PicColor
4.0.3.15131

Bitdefender
Gen:Variant.Kazy.537663
1.0.20.155

Emsisoft Anti-Malware
Gen:Variant.Kazy.537663
9.0.0.4799

ESET NOD32
Win32/Adware.PicColor.J application
7.0.302.0

Fortinet FortiGate
Riskware/PicColor
1/31/2015

F-Secure
Gen:Variant.Kazy.537663
5.13.68

G Data
Gen:Variant.Kazy.537663
15.1.24

IKARUS anti.virus
PUA.PicColor
t3scan.1.8.6.0

Malwarebytes
PUP.Optional.JellySplit.A
v2015.01.31.06

McAfee
Artemis!CF4BE54B11F3
5600.6869

MicroWorld eScan
Gen:Variant.Kazy.537663
16.0.0.93

NANO AntiVirus
Riskware.Win32.PicColor.dmiwyt
0.30.0.64812

Qihoo 360 Security
Win32/Virus.Adware.cd6
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.1.31.6

Trend Micro House Call
TROJ_GEN.R08NH09AN15
7.2.31

VIPRE Antivirus
Trojan.Win32.Generic
36934

File size:
542 KB (555,008 bytes)

Product version:
1.0.0.2120

Copyright:
Copyright (C) 2014

Original file name:
28395dc6a2ae459386feac2fd5fb3b60.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Application data\28395dc6a2ae459386feac2fd5fb3b60\28395dc6a2ae459386feac2fd5fb3b60.exe

File PE Metadata
Compilation timestamp:
1/30/2015 10:11:53 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:2gQ6dpQoYFZq+6417gTZARbY00d6dyUoN12xvjO:+6dpQi+6I7YQk0Yuy8r

Entry address:
0x4B620

Entry point:
E8, AE, CF, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 74, 10, 8B, 55, 0C, 85, D2, 74, 09, 8B, 4D, 10, 85, C9, 75, 16, 88, 0E, E8, D4, 44, 00, 00, 6A, 16, 5E, 89, 30, E8, 62, D2, 00, 00, 8B, C6, 5E, 5D, C3, 57, 8B, FE, 2B, F9, 8A, 01, 88, 04, 0F, 41, 84, C0, 74, 03, 4A, 75, F3, 5F, 85, D2, 75, 0B, 88, 16, E8, A7, 44, 00, 00, 6A, 22, EB, D1, 33, C0, EB, D7, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 64, B3, 48, 00, FF, 15, F0, D0, 46, 00, 85, C0, 75, 18, 56, E8, 7B...
 
[+]

Code size:
431.5 KB (441,856 bytes)

Scheduled Task
Task name:
BZQENOXPF

Path:
C:\WINDOWS\Tasks\BZQENOXPF.job

Trigger:
Daily (Runs daily at 14:24)


Remove 28395dc6a2ae459386feac2fd5fb3b60.exe - Powered by Reason Core Security