consettings.exe

QUANTO SOLUCOES E SISTEMA LTDA

The executable consettings.exe has been detected as malware by 7 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ConSettings.exe’.
Publisher:
QUANTO SOLUCOES E SISTEMA LTDA  (signed and verified)

MD5:
04ad818767a41ba797e222539f5d7e5f

SHA-1:
37c92fadde87079b038a77359ff22b52680a7838

SHA-256:
dd92173988489f55adbcfd9f53f12aaad84f2322c0c7a61b6a794ea3be70cf1d

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/19/2024 8:00:27 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Heur.Kelios.1
892

avast!
Win32:Banker-KYB [Trj]
140813-1

Bitdefender
Gen:Heur.Kelios.1
1.0.20.1190

Emsisoft Anti-Malware
Gen:Heur.Kelios
9.0.0.4324

F-Secure
Gen:Heur.Kelios.1
11.2014-26-08_3

G Data
Gen:Heur.Kelios
14.8.24

MicroWorld eScan
Gen:Heur.Kelios.1
15.0.0.714

File size:
615.3 KB (630,112 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\utorrent\consettings.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/2/2014 9:00:00 PM

Valid to:
4/3/2015 8:59:59 PM

Subject:
CN=QUANTO SOLUCOES E SISTEMA LTDA, O=QUANTO SOLUCOES E SISTEMA LTDA, L=PRESIDENTE PRUDENTE, S=SAO PAULO, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
00B87EDE3281FFB1EE77DF86B54A8CB0

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:JqnWKKaRpcgs64tIZRbLlaclW8riLX643T+4nd9+w2lBRaNf9EtJNbzLmlBE5H5v:Gdp4tIfBlWnXn+wpNStJpLn5v

Entry address:
0x82290

Entry point:
FE, C0, EB, 03, DE, EE, C2, 60, 39, FB, 8D, 1D, 31, 5C, A0, D1, 0F, AC, CB, 4F, C1, F8, 27, C0, C8, 7D, B8, 97, 77, 01, 00, 0F, BE, CD, BD, 9B, 90, 1F, D2, F6, C5, 13, 86, DF, BE, F6, 8A, 0E, 96, 88, F9, 0F, BC, FF, C7, C3, AF, E7, CF, BD, 09, EA, 68, 6A, 00, 00, 00, 0F, AC, FB, B1, 80, E1, 95, F7, C6, A2, 3E, 47, 89, 0F, AC, D2, 55, 59, E8, 09, 00, 00, 00, 13, B8, 0D, 5D, 72, 8B, CF, 4A, 65, 5B, 0F, AD, DF, 0F, B7, FE, 0F, AB, D7, 8B, D3, F7, C3, 80, 2F, CE, CA, 88, CB, 0F, CF, 80, E7, 65, 03, CA, 21, FA...
 
[+]

Code size:
420 KB (430,080 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ConSettings.exe

Command:
C:\users\{user}\appdata\roaming\utorrent\consettings.exe


Remove consettings.exe - Powered by Reason Core Security