avkeys.exe

Avkeys

Staf4

The executable avkeys.exe has been detected as malware by 31 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.avkeys.org.
Publisher:
Staf4

Product:
Avkeys

Version:
1.8.0.0

MD5:
ab07226f0236ba5286f5c47c62655db2

SHA-1:
e2d97c321a40ff841290ee9d822f490440e2ffac

SHA-256:
8753849466df5194debbcfe955fe94c495b170a861f6ed9ef5ce94edd78ebeee

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/25/2024 9:26:25 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.269728
1135

Agnitum Outpost
Trojan.Badur
7.1.1

AhnLab V3 Security
Trojan/Win32.Badur
2013.12.24

Avira AntiVirus
TR/Kazy.269728.1
7.11.125.168

avast!
Win32:Malware-gen
2014.9-131226

AVG
Generic35
2014.0.3613

Baidu Antivirus
Trojan.Win32.Badur
4.0.3.131226

Bitdefender
Gen:Variant.Kazy.269728
1.0.20.1800

Bkav FE
W32.Clod4de.Trojan
1.3.0.4677

Comodo Security
UnclassifiedMalware
17630

Dr.Web
Trojan.DownLoader9.11339
9.0.1.019

Emsisoft Anti-Malware
Gen:Variant.Kazy.269728
8.13.12.26.05

ESET NOD32
MSIL/Riskware.HackAV (variant)
7.9306

Fortinet FortiGate
MSIL/Riskware_HackAV.G
12/26/2013

F-Secure
Gen:Variant.Kazy.269728
11.2013-26-12_5

G Data
Gen:Variant.Kazy.269728
13.12.24

IKARUS anti.virus
Trojan.Win32.Badur
t3scan.2.2.29

K7 AntiVirus
Trojan
13.175.10881

Kaspersky
Trojan.Win32.Badur
14.0.0.4561

Malwarebytes
Trojan.MSIL
v2013.12.26.05

McAfee
RDN/Generic.dx!c2s
5600.7269

MicroWorld eScan
Gen:Variant.Kazy.269728
14.0.0.1080

NANO AntiVirus
Trojan.Win32.Badur.cqmaeg
0.28.0.57029

Norman
Troj_Generic.RPENT
11.20131226

Panda Antivirus
Generic Malware
13.12.26.05

Sophos
Mal/Generic-S
4.96

Trend Micro House Call
TROJ_SPNV.03L813
7.2.360

Trend Micro
TROJ_SPNV.03L813
10.465.26

Vba32 AntiVirus
Trojan.Badur
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
25526

ViRobot
Trojan.Win32.A.Badur.450560.C
2011.4.7.4223

File size:
440 KB (450,560 bytes)

Product version:
1.8.0.0

Copyright:
Copyright © Staf4, 2013

Original file name:
avkeys.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
12/4/2013 10:06:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:9aJZ+Qi9XThVXyemeXWgbHv75h6GKzbK:98Z+XpTWemeXWg7jTKzu

Entry address:
0x6B8FA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
422.5 KB (432,640 bytes)

The file avkeys.exe has been seen being distributed by the following URL.

Remove avkeys.exe - Powered by Reason Core Security