biciod.exe

Marsukife Visatl 2010

The executable biciod.exe has been detected as malware by 14 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
Product:
Marsukife® Visatl 2010

Version:
6.38.6132.31732

MD5:
a879d5727bc1dd1bc085d0771312cb9d

SHA-1:
5654ade01f81b1363fbce84f2f6466712d297d84

SHA-256:
4a01285b0a70af38780a025f7109b884558bd57db869e5fc3362f101702d79ad

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
4/23/2024 3:36:52 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.480787
835

Avira AntiVirus
TR/Crypt.ZPACK.Gen2
7.11.180.154

avast!
Win32:Dropper-gen [Drp]
141003-0

AVG
Win32/Cryptor
2014.0.4040

Bitdefender
Gen:Variant.Kazy.480787
1.0.20.1475

Bkav FE
HW32.Packed
1.3.0.4959

Emsisoft Anti-Malware
Gen:Variant.Kazy.480787
8.14.10.22.03

ESET NOD32
probably unknown NewHeur_PE virus
7.0.302.0

G Data
Gen:Variant.Kazy.480787
14.10.24

Malwarebytes
Trojan.FakeMS
v2014.10.22.03

McAfee
PWSZbot-FADO!A879D5727BC1
5600.6969

MicroWorld eScan
Gen:Variant.Kazy.480787
15.0.0.885

Quick Heal
FraudTool.Security
10.14.14.00

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141020

File size:
286.2 KB (293,102 bytes)

Product version:
6.38.6132.31732

Original file name:
desinko.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\ypymhov\biciod.exe

File PE Metadata
Compilation timestamp:
5/29/2011 3:18:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:3VJKAe61qzBfSV5JpjkXp/aoNUGSkiz/DQMbA+OuQAXIkz8vu6GA:FIlSV5JFkXphNizMMbA+OviIkzsVGA

Entry address:
0xCD14

Entry point:
55, 8B, EC, 81, EC, 48, 03, 00, 00, B9, 51, 00, 00, 00, 89, 8D, 3C, FD, FF, FF, 53, EB, 40, 2B, C6, 3B, 85, 68, FD, FF, FF, 74, 36, 89, 8D, A0, FD, FF, FF, 3B, 85, DC, FE, FF, FF, 75, 28, 83, F0, 13, EB, 23, 2B, C6, BE, FC, 00, 00, 00, 89, B5, 04, FD, FF, FF, 3B, 8D, 04, FE, FF, FF, 74, 0E, 83, C0, 92, 83, F9, 8A, 75, 06, 89, 85, 94, FE, FF, FF, 56, 83, E8, C4, 89, 85, 3C, FD, FF, FF, 57, 8B, 3D, F8, 4E, 43, 00, 89, 85, 3C, FD, FF, FF, 89, BD, 3C, FD, FF, FF, 83, F8, AF, 75, 06, 89, BD, 0C, FE, FF, FF, 8D...
 
[+]

Entropy:
7.8835

Developed / compiled with:
Microsoft Visual C++

Code size:
100.5 KB (102,912 bytes)

Scheduled Task
Task name:
Security Center Update - 3243547444

Trigger:
Daily (Runs daily at 3:00 PM)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove biciod.exe - Powered by Reason Core Security