AutoPico.exe

AutoPico

@ByELDI

The application AutoPico.exe by @ByELDI has been detected as a potentially unwanted program by 15 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
Publisher:
@ByELDI  (signed and verified)

Product:
AutoPico

Version:
12.1.0.0

MD5:
4f3b5c2cda1b13e08d542bc74c5a18b7

SHA-1:
217d2a7c1b161dee37bba78d5b330e3a3ac8484b

SHA-256:
5e5405b686f2837d9a9c8efc45d3f2ab378bd1e0367d6940daa09fd61e25b681

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 7:55:39 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Unwanted/Win32.HackTool
2015.09.28

Avira AntiVirus
SPR/Hacktool.9621
8.3.1.6

avast!
Win32:PUP-gen [PUP]
2014.9-151014

Bkav FE
W32.HfsAdware
1.3.0.7237

ESET NOD32
MSIL/HackTool.IdleKMS.E potentially unsafe (variant)
9.12296

Fortinet FortiGate
Riskware/RPCHook
10/14/2015

K7 AntiVirus
Unwanted-Program
13.207.16854

McAfee
Artemis!E457A67454F6
5600.6612

NANO AntiVirus
Trojan.Win32.IdleKMS.deinya
0.28.2.62440

Panda Antivirus
Generic Suspicious
15.10.14.02

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Reason Heuristics
KeycodeTool.ByELDI.Meta (M)
15.10.14.14

Rising Antivirus
PE:Trojan.MSIL.Injector!1.9E1B
23.00.65.151012

Trend Micro House Call
TROJ_GEN.F47V0303
7.2.287

VIPRE Antivirus
Trojan.Win32.Generic
44102

File size:
954.7 KB (977,600 bytes)

Product version:
12.1.0.0

Original file name:
AutoPico.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\kmspico\autopico.exe

Digital Signature
Signed by:

Authority:
@ByELDI Certificate Authority

Valid from:
2/3/2014 1:17:06 PM

Valid to:
2/3/2044 1:17:06 PM

Subject:
CN=@ByELDI

Issuer:
CN=@ByELDI Certificate Authority

Serial number:
DC0E43711C7C40D18044372CAF69F6A1

File PE Metadata
Compilation timestamp:
3/2/2014 11:56:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:5fomT1omoVSl9TrWUk2NHXTrw9cHSPxHwYEWqtn6BjEUHZEQQo:5ZToYlxbjr20wqtn6B46Qo

Entry address:
0xEB43E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
933.5 KB (955,904 bytes)

Scheduled Task
Task name:
AutoPico Daily Restart

Trigger:
Daily (Runs daily at 05:29 p.m.)


Remove AutoPico.exe - Powered by Reason Core Security