autoclk.EXE

autoclk Application

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘autoclk’.
Product:
autoclk Application

Description:
autoclk MFC Application

Version:
1, 0, 0, 1

MD5:
ecac8517507370b82abf68894594bc5d

SHA-1:
ed9d5b1e500e87728e42ae514a455625e3861728

SHA-256:
cadcd20e40f8381c51a6e612be1636dd81f9b0d5dae89bab429143f6142824fc

Scanner detections:
7 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/12/2025 6:12:33 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Xema.variant
2013.07.09

Clam AntiVirus
Trojan.Klacc-1
0.98/18155

Comodo Security
UnclassifiedMalware
16570

McAfee
Artemis!ECAC85175073
5600.7210

Rising Antivirus
Trojan.Win32.Generic.1251B759
23.00.65.14221

Trend Micro House Call
ADWARE_HIWIRE
7.2.54

Trend Micro
ADWARE_HIWIRE
10.465.23

File size:
120 KB (122,880 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2002

Original file name:
autoclk.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\autoclk.exe

File PE Metadata
Compilation timestamp:
2/13/2004 7:33:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:bP++D9ybvVThxIYPlAddIabIWzytn3wHsyzIdywIrgtocbrlyWZg4PkPia:b2w9yb/Oe+dIN37yzCfIeocbI8g4PKi

Entry address:
0x271F

Entry point:
55, 8B, EC, 6A, FF, 68, A0, 4D, 41, 00, 68, E8, 53, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 18, 31, 41, 00, 33, D2, 8A, D4, 89, 15, 0C, B4, 41, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 08, B4, 41, 00, C1, E1, 08, 03, CA, 89, 0D, 04, B4, 41, 00, C1, E8, 10, A3, 00, B4, 41, 00, 6A, 01, E8, 27, 2C, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 0D, 1F, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
72 KB (73,728 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
autoclk

Command:
autoclk.exe


Scan autoclk.EXE - Powered by Reason Core Security