adhelp_zhfhsk.exe

Qzoneinteractive

The application adhelp_zhfhsk.exe by Qzoneinteractive has been detected as a potentially unwanted program by 25 anti-malware scanners.
Publisher:
Qzoneinteractive  (signed and verified)

MD5:
79ed120a3ac19046a518b3172dfc8399

SHA-1:
46d10ac0b1a2125cabe19c4ace59f788c56c6a33

SHA-256:
b7b2fa2fa6649ccc3f88f766ad48c94b3dfeaa2c32da61b15e93abe7a2a6775f

Scanner detections:
25 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 4:51:07 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.409765
1007

Agnitum Outpost
Adware.Kraddare
7.1.1

Avira AntiVirus
DR/Delphi.Gen
7.11.117.90

avast!
Win32:Malware-gen
2014.9-140504

AVG
Generic5
2015.0.3485

Baidu Antivirus
AdWare.Win32.Kraddare
4.0.3.1454

Bitdefender
Application.Generic.409765
1.0.20.620

Comodo Security
UnclassifiedMalware
17376

ESET NOD32
Win32/Adware.Kraddare.GK (variant)
8.9122

Fortinet FortiGate
Riskware/Kraddare
5/4/2014

F-Prot
W32/AdHelper.C.gen
v6.4.7.1.166

F-Secure
Application.Generic.409765
11.2014-04-05_1

G Data
Application.Generic.409765
14.5.22

IKARUS anti.virus
Trojan-Banker.Win32.Banker
t3scan.2.2.29

K7 AntiVirus
Riskware
13.174.10380

Malwarebytes
Adware.Korad
v2014.05.04.04

McAfee
GenericTRA-BM!79ED120A3AC1
5600.7141

Microsoft Security Essentials
Adware:Win32/Kremiumad
1.163.1557.0

MicroWorld eScan
Application.Generic.409765
15.0.0.372

Panda Antivirus
Trj/Genetic.gen
14.05.04.04

Sophos
Generic PUA EG
4.95

Trend Micro House Call
ADW_KRADDARE
7.2.124

Trend Micro
TROJ_GEN.R0CBC0CFF13
10.465.04

Vba32 AntiVirus
TrojanDownloader.Genome
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
23960

File size:
894.4 KB (915,848 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\adhelp_zhfhsk.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/14/2011 9:00:00 AM

Valid to:
11/14/2012 8:59:59 AM

Subject:
CN=Qzoneinteractive, OU=EC Team, O=Qzoneinteractive, L=Gwangjin-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
51790DE8CFF3FB8E48D3E671F9021D0B

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:h/U9AxknBCv+lmje/48PYXGUvS6gFyNP6ZDXpfmOynDkDrai1AKz1AKb1AKua6:BmZkFe49200A69XpfmDnISRKuK2KL6

Entry address:
0x982D4

Entry point:
55, 8B, EC, 83, C4, E8, 53, 33, C0, 89, 45, EC, 89, 45, E8, B8, D4, 7D, 49, 00, E8, AF, DF, F6, FF, 33, C0, 55, 68, 88, 83, 49, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, A1, 28, BA, 49, 00, 8B, 00, E8, 42, 55, FC, FF, 8B, 45, E8, 8D, 55, EC, E8, CF, 0B, F7, FF, 8B, 45, EC, E8, 9F, C2, F6, FF, 50, 6A, FF, 6A, 00, E8, B5, E1, F6, FF, 8B, D8, E8, B6, E2, F6, FF, 3D, B7, 00, 00, 00, 75, 08, 53, E8, C9, E3, F6, FF, EB, 30, A1, 28, BA, 49, 00, 8B, 00, E8, 5B, 4E, FC, FF, 8B, 0D, 88, B5, 49, 00, A1, 28, BA, 49, 00...
 
[+]

Entropy:
6.9393

Developed / compiled with:
Microsoft Visual C++

Code size:
605 KB (619,520 bytes)

Remove adhelp_zhfhsk.exe - Powered by Reason Core Security