acikmao.dll

The library acikmao.dll has been detected as malware by 12 anti-virus scanners.
MD5:
2839f17198b013aec30f6c89221cab1c

SHA-1:
0f785447ff82e4658140597a95b5ea0979d892c1

SHA-256:
5f6fc79c8e5cc90179465d12799041c3eeede5f2ac95e578da8dec56666ceaee

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
5/17/2024 5:22:22 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.331056
819

AhnLab V3 Security
Trojan/Win32.Proxy
2014.11.08

Bitdefender
Gen:Variant.Kazy.331056
1.0.20.1555

Emsisoft Anti-Malware
Gen:Variant.Kazy.331056
8.14.11.07.08

ESET NOD32
Win32/TrojanProxy.Agent.NYP (variant)
8.10689

F-Secure
Gen:Variant.Kazy.331056
11.2014-07-11_6

G Data
Gen:Variant.Kazy.331056
14.11.24

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2981

Malwarebytes
Trojan.Proxy.Bunitu
v2014.11.07.08

MicroWorld eScan
Gen:Variant.Kazy.331056
15.0.0.933

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.7.20

SUPERAntiSpyware
Trojan.Agent/Gen-Troprox
10251

File size:
23 KB (23,552 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\acikmao.dll

File PE Metadata
Compilation timestamp:
11/7/2014 2:31:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
192:GinLK/YOdEyUKFWF31QJsTSJWalhU1WE0cpMVdZ2x9dC1c7TmbT5y6:GCLbO2eg6JL8P1v0bKxeQEy

Entry address:
0x3DA7

Entry point:
55, 8B, EC, 83, C4, EC, FF, 75, 0C, 59, B8, 91, F1, EC, 01, 23, D1, 52, 8F, 05, 52, 60, 00, 10, 2D, 90, F1, EC, 01, C9, C2, 0C, 00, 25, 3C, 46, 80, 05, 55, 8B, EC, AD, 60, 8D, 34, 11, 83, EE, 01, 83, EE, 01, 68, F5, 3D, 00, 10, 83, 04, 24, 01, C3, 55, 60, 8B, EC, 64, 8B, 15, 30, 00, 00, 00, 8B, 52, 0C, 8B, 52, 14, 8B, 72, 28, FF, 75, 28, 59, 8B, F6, BF, 00, 00, 00, 00, 0F, B6, 06, 46, 3C, 61, 7C, 05, 2C, 10, 48, 2C, 0F, C1, CF, 0D, 03, F8, 8B, FF, E2, EA, 3B, 7D, 24, 8B, 5A, 10, 8B, 12, 75, AE, 89, 5C, 24...
 
[+]

Entropy:
4.7482

Developed / compiled with:
Microsoft Visual C++

Code size:
12.5 KB (12,800 bytes)

Remove acikmao.dll - Powered by Reason Core Security