adobe.exe

ASUS Products

The executable adobe.exe has been detected as malware by 22 anti-virus scanners. Accoriding to the detections, this has been classified as a kyelogger which is capable of recoring a user's keystrokes.
Publisher:
ASUSTek Computer Inc.*  (Invalid match)

Product:
ASUS Products

Version:
7.14.0.1

MD5:
b46d337a3cad696f9fa80ae6b1424002

SHA-1:
8092a806e1d785c089c24952c95d10924acd6b92

SHA-256:
7ed3eb5c21a3730578212055cc3a4045e7de97001af58d489a544aef50acf39e

Scanner detections:
22 / 68

Status:
Malware

Explanation:
The software cotains keystroke monitoring/logging capablities which may or may not be installed without the user's knowledge.

Analysis date:
4/26/2024 9:16:20 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1748373
889

AhnLab V3 Security
Trojan/Win32.MDA
2014.07.16

Avira AntiVirus
TR/Dropper.MSIL.65218
7.11.160.212

Bitdefender
Trojan.GenericKD.1748373
1.0.20.1205

Emsisoft Anti-Malware
Trojan.GenericKD.1748373
8.14.08.29.03

ESET NOD32
MSIL/Injector.EGM (variant)
8.10099

Fortinet FortiGate
W32/KeyLogger.AVDI!tr
8/29/2014

F-Secure
Trojan.GenericKD.1748373
11.2014-29-08_6

G Data
Trojan.GenericKD.1748373
14.8.24

IKARUS anti.virus
Trojan-Spy.MSIL.Keylogger
t3scan.1.6.1.0

Kaspersky
Trojan-Spy.MSIL.KeyLogger
14.0.0.3332

Malwarebytes
Backdoor.Agent.MSCGen
v2014.08.29.03

McAfee
Artemis!B46D337A3CAD
5600.7023

Microsoft Security Essentials
Trojan:Win32/Malagent!gmb
1.10802

MicroWorld eScan
Trojan.GenericKD.1748373
15.0.0.723

Norman
Injector.HABL
11.20140829

Panda Antivirus
Trj/CI.A
14.08.29.03

Qihoo 360 Security
HEUR/Malware.QVM03.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R0CBC0DGD14
7.2.241

Trend Micro
TROJ_GEN.R0CBC0DGD14
10.465.29

VIPRE Antivirus
Trojan.Win32.Generic
31304

File size:
319 KB (326,656 bytes)

Product version:
7.14.0.1

Copyright:
Copyright (C) 2005-2007

Trademarks:
ASUSTek ® application program

Original file name:
Adobe All products Activator 2014.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\windows server\adobe.exe

File PE Metadata
Compilation timestamp:
7/8/2014 8:07:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:bjImK3/9jfz3Q79z92NKg1Erwuue+/GpM4/:bEX3FjfMRoZGl

Entry address:
0x50FCE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00, 03, 00, 03, 00, 00, 00, 28, 00, 00, 80, 0E, 00, 00, 00, 40, 00, 00, 80, 10, 00, 00, 00, 58, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00, 01, 00, 25, 00, 00, 00, 70, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5037

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
316 KB (323,584 bytes)

Remove adobe.exe - Powered by Reason Core Security