ashquick_mwqfmr.exe

WLE DESENVOLVIMENTO DE SOFTWARE E ASSESSORIA LTDA EPP

The executable ashquick_mwqfmr.exe has been detected as malware by 3 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ashQuick_MWQFMR’.
MD5:
78e5b95aa7b6d6410cefee4acb949153

SHA-1:
7fcd2e3c5cbcf6fd2776b50f177bd440bfc0adef

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
4/25/2024 7:45:57 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Delf-TQV [Trj]
2014.9-140723

AVG
Luhe.Fiha.A
2015.0.3404

ESET NOD32
Win32/Spy.Banker.AAPJ
8.9454

File size:
543.6 KB (556,632 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\documents and settings\all users\riiivb0qptx8\ashquick_mwqfmr.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/31/2013 10:00:00 PM

Valid to:
11/1/2014 9:59:59 PM

Subject:
CN=WLE DESENVOLVIMENTO DE SOFTWARE E ASSESSORIA LTDA EPP, O=WLE DESENVOLVIMENTO DE SOFTWARE E ASSESSORIA LTDA EPP, STREET="RUA BARAO DO CERRO AZUL, 661", STREET=CENTRO, L=UNIAO DA VITORIA, S=PARANA, PostalCode=84600000, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00864196F01971DBEC7002B48642A7013A

File PE Metadata
Compilation timestamp:
2/17/2014 9:20:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:4e+aKNtsuNBFqfGzJvgWV3/aHLKwyPvMl3VpyExyyDT:rGzqfGzJvgWVCewyPv4ldUC

Entry address:
0x747D4

Entry point:
55, 8B, EC, 83, C4, F0, B8, 94, 37, 47, 00, E8, A0, 1F, F9, FF, A1, B8, 75, 47, 00, 8B, 00, E8, BC, 1B, FE, FF, A1, B8, 75, 47, 00, 8B, 00, B2, 01, E8, 76, 39, FE, FF, A1, B8, 75, 47, 00, 8B, 00, C6, 40, 5B, 00, 8B, 0D, F4, 76, 47, 00, A1, B8, 75, 47, 00, 8B, 00, 8B, 15, 3C, 29, 47, 00, E8, A3, 1B, FE, FF, A1, B8, 75, 47, 00, 8B, 00, E8, CF, 1C, FE, FF, E8, 86, 00, F9, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
461 KB (472,064 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ashQuick_MWQFMR

Command:
C:\documents and settings\all users\riiivb0qptx8\ashquick_mwqfmr.exe


Remove ashquick_mwqfmr.exe - Powered by Reason Core Security