3zsv8.exe

Gadu-Gadu

{9C1F8E52-00A6-4A3A-90CA-F8EC53FAC0E8}

The executable 3zsv8.exe has been detected as malware by 30 anti-virus scanners.
Publisher:
sms-express.com  (signed by {9C1F8E52-00A6-4A3A-90CA-F8EC53FAC0E8})

Product:
Gadu-Gadu

Description:
GG.exe

Version:
1.0.0.0

MD5:
1ceff890195e4bc2d318509353ec5cf0

SHA-1:
3de88c0fd15fdff125b62eb114f04618ab746add

SHA-256:
11770f6ae1ced1824859f386650f5b29973f4007bf0efd8d01badeb6aa2a077e

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/25/2024 4:36:37 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1592590
295

Avira AntiVirus
TR/Injector.cvj.31
7.11.148.234

AVG
Generic35
2017.0.2773

Baidu Antivirus
Trojan.Win32.Inject
4.0.3.16414

Bitdefender
Trojan.GenericKD.1592590
1.0.20.525

Comodo Security
UnclassifiedMalware
18254

Dr.Web
Trojan.DownLoader9.28365
9.0.1.0105

Emsisoft Anti-Malware
Trojan.GenericKD.1592590
8.16.04.14.06

ESET NOD32
MSIL/Injector.CVJ (variant)
10.9785

Fortinet FortiGate
W32/Inject.IBKF!tr
4/14/2016

F-Secure
Trojan.GenericKD.1592590
11.2016-14-04_5

G Data
Trojan.GenericKD.1592590
16.4.24

IKARUS anti.virus
Backdoor.Win32.DarkKomet
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.177.12041

Kaspersky
Trojan.Win32.Inject
14.0.0.361

Malwarebytes
Trojan.MSIL
v2016.04.14.06

McAfee
RDN/Generic.dx!czh
5600.6429

Microsoft Security Essentials
TrojanSpy:MSIL/Clipug.A
1.10502

MicroWorld eScan
Trojan.GenericKD.1592590
17.0.0.315

NANO AntiVirus
Trojan.Win32.Inject.cvgbvc
0.28.0.59608

Norman
Injector.FHGS
11.20160414

nProtect
Trojan.GenericKD.1592590
14.05.11.01

Panda Antivirus
Generic Malware
16.04.14.06

Qihoo 360 Security
HEUR/Malware.QVM03.Gen
1.0.0.1015

Sophos
Mal/Cleaman-B
4.98

Trend Micro House Call
TROJ_SPNR.03DP14
7.2.105

Trend Micro
TROJ_SPNR.03DP14
10.465.14

Vba32 AntiVirus
Trojan.Inject.ibkf
3.12.26.0

VIPRE Antivirus
Trojan.MSIL.Injector.cvj
29082

Zillya! Antivirus
Trojan.Inject.Win32.71687
2.0.0.1785

File size:
264.5 KB (270,880 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (C) 1999,2005 sms-express.com

Original file name:
GG.exe.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\3zsv8.exe

Digital Signature
Authority:
{9C1F8E52-00A6-4A3A-90CA-F8EC53FAC0E8}

Valid from:
2/19/2014 4:00:11 AM

Valid to:
2/19/2015 10:00:11 AM

Subject:
CN={9C1F8E52-00A6-4A3A-90CA-F8EC53FAC0E8}

Issuer:
CN={9C1F8E52-00A6-4A3A-90CA-F8EC53FAC0E8}

Serial number:
274683BF421F748E4C53A26F410E5243

File PE Metadata
Compilation timestamp:
2/24/2014 9:49:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:FG4oIk7WyHc0gZ19OefPuaBW4qXnQiEDa1ikGCmBcdVa/lgfkq6DhfoWicQLdgSZ:E7WyH1KHGQi1iAmidVa/lgfiwWq/ld

Entry address:
0x42E9E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
260 KB (266,240 bytes)

Remove 3zsv8.exe - Powered by Reason Core Security