akxjzoksyu.dll

The library akxjzoksyu.dll has been detected as malware by 24 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘akxjzoksyu’. According to AVG, this software downloads additional adware offers during setup.
MD5:
73f153745cbc7e689a78936b57ba3eef

SHA-1:
c4f3ea4fce85ed311a2f515c06888168e2d36778

SHA-256:
ea0893bb2ec77eddf4d23f144dda9d675e3ff942943a14b3989ce6803ee3f958

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
5/7/2024 11:09:41 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1864231
776

Agnitum Outpost
Trojan.DL.Tracur
7.1.1

Avira AntiVirus
TR/Rogue.238592.5
7.11.192.154

avast!
Win32:Malware-gen
2014.9-141221

AVG
Downloader.Generic14
2015.0.3254

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.141221

Bitdefender
Trojan.GenericKD.1864231
1.0.20.1775

Bkav FE
HW32.Packed
1.3.0.6267

Comodo Security
UnclassifiedMalware
20282

ESET NOD32
Win32/TrojanDownloader.Tracur.AL
8.10826

Fortinet FortiGate
W32/Tracur.AL!tr.dldr
12/21/2014

F-Secure
Trojan.GenericKD.1864231
11.2014-21-12_1

G Data
Trojan.GenericKD.1864231
14.12.24

IKARUS anti.virus
Trojan-Downloader.Win32.Tracur
t3scan.1.8.5.0

Kaspersky
Trojan.Win32.Agent
14.0.0.2763

McAfee
Downloader-FAJE!73F153745CBC
5600.6910

MicroWorld eScan
Trojan.GenericKD.1864231
15.0.0.1065

Norman
Tracur.PH
11.20141221

nProtect
Trojan.GenericKD.1864231
14.12.03.01

Quick Heal
Trojan.Agen.r7
12.14.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_TRACUR.WPH
7.2.355

Trend Micro
TROJ_TRACUR.WPH
10.465.21

VIPRE Antivirus
Trojan.Win32.Generic
35420

File size:
233 KB (238,592 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\broadcom\akxjzoksyu.dll

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:t3O57TDjiwUi61r1LTAVSRnmqN6RxvpUzf:8jOwU3BZTkYZN6RxU

Entry address:
0x34D0D

Entry point:
55, 8B, EC, 83, C4, D4, B8, AF, 46, 8C, 40, E8, 95, E9, FF, FF, E8, 7D, FA, FF, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.3176

Developed / compiled with:
Microsoft Visual C++

Code size:
207.5 KB (212,480 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
akxjzoksyu

Command:
rundll32.exe "C:\users\{user}\appdata\local\broadcom\akxjzoksyu.dll",dllregisterserver


Remove akxjzoksyu.dll - Powered by Reason Core Security