BoyFineKiller.exe

贝壳木马专杀

Beike Internet Security Technology Co.,Ltd

Publisher:
贝壳网际(北京)安全技术有限公司  (signed by Beike Internet Security Technology Co.,Ltd)

Product:
贝壳木马专杀

Description:
暴风一号(BoyFine)U盘病毒专杀工具

Version:
2009.11.6.18

MD5:
d6ec44bc13a3cd4c332851e4e2d4e18c

SHA-1:
9258733cc6ded56932fc3f526cf2c977ce54f1fc

SHA-256:
a9efd4ff2799b349ef949c7d0318fc468a1e3827507d81bb00ba586ed865249c

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/18/2024 11:24:51 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
281.3 KB (288,064 bytes)

Product version:
1.0.3330.18

Copyright:
Beike Internet Security Technology Co.,Ltd

Original file name:
BoyFineKiller.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\boyfinekiller.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/15/2009 8:00:00 AM

Valid to:
5/16/2010 7:59:59 AM

Subject:
CN="Beike Internet Security Technology Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beike Internet Security Technology Co.,Ltd", L=BEIJING, S=BEIJING, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1327C649F41D2E2D8D892F1EB1DF4A32

File PE Metadata
Compilation timestamp:
11/6/2009 12:02:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:JXvKcO0Kp1jPMa43EFbxxv5wEnabnLip2Qx3bEsj5rmK5HNCs/QchOw5kn:JbM1jPOUFbxIhebxj5/NhLhOwe

Entry address:
0xE643

Entry point:
E8, 37, 5D, 00, 00, E9, 17, FE, FF, FF, 55, 8B, EC, 8B, 45, 14, 56, 57, 33, FF, 3B, C7, 74, 47, 39, 7D, 08, 75, 1B, E8, 70, 1D, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 72, 21, 00, 00, 83, C4, 14, 8B, C6, EB, 29, 39, 7D, 10, 74, E0, 39, 45, 0C, 73, 0E, E8, 4B, 1D, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, D7, 50, FF, 75, 10, FF, 75, 08, E8, 61, EE, FF, FF, 83, C4, 0C, 33, C0, 5F, 5E, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84...
 
[+]

Entropy:
6.4736

Code size:
200 KB (204,800 bytes)

Scan BoyFineKiller.exe - Powered by Reason Core Security