57f2.tmp

Imagine

Chun Sejin

The file 57f2.tmp, “Image & Animation Viewer” has been detected as a potentially unwanted program by 20 anti-malware scanners.
Publisher:
Chun Sejin

Product:
Imagine

Description:
Image & Animation Viewer

Version:
1.0.8

MD5:
00cd185f4a9744e2e1cb03f838a43880

SHA-1:
d3c08db048736209e5b4ed0c334f2f3d111ca1e7

SHA-256:
d463bda505420239bcdd6f913b51e2aaf21442b7d450c5416f8f8af31661249f

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 3:40:25 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Downloader.UW
6175498

Avira AntiVirus
TR/Crypt.XPACK.Gen7
7.11.196.118

avast!
Win32:Malware-gen
141214-1

AVG
Simda
2015.0.3257

Bitdefender
Application.Downloader.UW
1.0.20.1755

Dr.Web
Trojan.Rodricter.153
9.0.1.05190

Emsisoft Anti-Malware
Application.Downloader.UW
9.0.0.4668

ESET NOD32
Win32/Simda.B trojan
7.0.302.0

F-Secure
Riskware.Application.Downloader.UW
5.13.68

G Data
Application.Downloader.UW
14.12.24

Kaspersky
Backdoor.Win32.Simda
15.0.0.543

Malwarebytes
Trojan.Agent.FSAVXGen
v2014.12.17.12

Microsoft Security Essentials
Threat.Undefined
1.191.219.0

MicroWorld eScan
Application.Downloader.UW
15.0.0.1053

Norman
Application.Downloader.UW
04.12.2014 14:30:06

Panda Antivirus
Trj/Genetic.gen
14.12.17.12

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.19.0

Sophos
Virus 'Troj/Agent-AKUK'
59

VIPRE Antivirus
Threat.4150696
35418

File size:
671 KB (687,104 bytes)

Product version:
1.0.8

Copyright:
Copyright (c) 2003-2010 Chun Sejin

Common path:
C:\users\{user}\appdata\local\temp\57f2.tmp

File PE Metadata
Compilation timestamp:
12/17/2014 9:26:42 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:cnu1fSe4VA85yP6Ejykek2qA0oe2LN+V/I+d79FrV6Ki0sYBo5MidOvFJbs4cd:cu1fsle6EwYAZeEN+V/frVCQoMJbs4c

Entry address:
0xA05F0

Entry point:
55, 8B, EC, 83, EC, 0C, C7, 45, FC, 00, 00, 00, 00, 68, 88, 10, 4A, 00, 6A, 00, FF, 15, 20, 10, 40, 00, 68, 9C, 10, 4A, 00, FF, 15, 14, 10, 40, 00, 8B, 4D, 08, 89, 0D, 7C, 4F, 4A, 00, 89, 2D, 5C, 4F, 4A, 00, C7, 05, 40, 4F, 4A, 00, 1C, 00, 02, 00, E8, DD, 03, 00, 00, A1, 00, 10, 40, 00, A3, 98, 4F, 4A, 00, C7, 45, F4, 00, 00, 00, 00, 68, CC, 50, 4A, 00, 8B, 0D, 40, 4F, 4A, 00, 83, E9, 03, 51, 6A, 00, 8B, 15, 44, 10, 4A, 00, 52, A1, 08, 10, 4A, 00, 83, E8, 01, 50, FF, 15, 98, 4F, 4A, 00, 89, 45, F8, 83, 7D...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
639.5 KB (654,848 bytes)

Remove 57f2.tmp - Powered by Reason Core Security