6900.tmp

Imagine

Chun Sejin

The file 6900.tmp, “Image & Animation Viewer” has been detected as malware by 20 anti-virus scanners.
Publisher:
Chun Sejin

Product:
Imagine

Description:
Image & Animation Viewer

Version:
1.0.8

MD5:
b75f6b65ee7c3f2507d079c948196c25

SHA-1:
0e0d619324253039c99a5ddc38f6b066f60034fa

SHA-256:
d854334ca6323dac18a5938978e9ea2f4be233596800542db5319f5722989c67

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
5/10/2024 5:15:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.518815
778

Avira AntiVirus
TR/Crypt.XPACK.Gen7
7.11.196.48

avast!
Win32:Dropper-gen [Drp]
141214-1

AVG
Crypt3
2015.0.3256

Bitdefender
Gen:Variant.Graftor.167438
1.0.20.1750

Dr.Web
Trojan.Rodricter.153
9.0.1.0353

Emsisoft Anti-Malware
Gen:Variant.Graftor.167438
9.0.0.4668

ESET NOD32
Win32/Kryptik.CTDV trojan
7.0.302.0

F-Secure
Gen:Variant.Graftor.167438
5.13.68

G Data
Gen:Variant.Graftor.167438
14.12.24

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2775

Malwarebytes
Trojan.Agent.FSAVXGen
v2014.12.16.06

Microsoft Security Essentials
Threat.Undefined
1.191.219.0

MicroWorld eScan
Gen:Variant.Graftor.167438
15.0.0.1050

Norman
Gen:Variant.Graftor.167438
04.12.2014 14:30:06

Panda Antivirus
Trj/Genetic.gen
14.12.19.01

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.19.0

Sophos
Virus 'Troj/Agent-AKUK'
59

VIPRE Antivirus
Threat.4150696
35418

File size:
672.5 KB (688,640 bytes)

Product version:
1.0.8

Copyright:
Copyright (c) 2003-2010 Chun Sejin

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\6900.tmp

File PE Metadata
Compilation timestamp:
12/16/2014 3:42:26 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:qGIIftsP7uUOyKbZ9v8Pftrg9s+y7Z243:qGNOjuGo9vCftk9s+y7Z243

Entry address:
0xA0BD0

Entry point:
55, 8B, EC, 83, EC, 0C, C7, 45, FC, 00, 00, 00, 00, 68, 88, 20, 4A, 00, 6A, 00, FF, 15, 20, 10, 40, 00, 68, 90, 20, 4A, 00, FF, 15, 14, 10, 40, 00, 8B, 4D, 08, 89, 0D, 7C, 5F, 4A, 00, 89, 2D, 5C, 5F, 4A, 00, C7, 05, 40, 5F, 4A, 00, 1C, 00, 02, 00, E8, ED, 03, 00, 00, A1, 00, 10, 40, 00, A3, 98, 5F, 4A, 00, C7, 45, F4, 00, 00, 00, 00, 68, CC, 60, 4A, 00, 8B, 0D, 40, 5F, 4A, 00, 83, E9, 03, 51, 6A, 00, 8B, 15, 44, 20, 4A, 00, 52, A1, 08, 20, 4A, 00, 83, E8, 01, 50, FF, 15, 98, 5F, 4A, 00, 89, 45, F8, 83, 7D...
 
[+]

Entropy:
6.4374

Developed / compiled with:
Microsoft Visual C++

Code size:
641 KB (656,384 bytes)

Remove 6900.tmp - Powered by Reason Core Security