ctrlskype.exe

The executable ctrlskype.exe has been detected as malware by 3 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘CtrlSkype’.
MD5:
68836e4ee6b897adf4b92e54ca34ad2c

SHA-1:
44d630010bfe0b6494dab4d472240c9258ed901a

SHA-256:
afb7a0808654c2458da7c98b05a5e0498a43ea6ca98acd89a665dd64a4367222

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
4/26/2024 10:21:30 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Straftoz
8.10355

Malwarebytes
Trojan.Agent.ED
v2014.09.02.06

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.14831

File size:
333 KB (340,992 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\skype\ctrlskype.exe

File PE Metadata
Compilation timestamp:
9/2/2014 7:59:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:0HHB48pzgS2VuIPczGY2UrhN2uv1ytaNtAle+dAIJIsdGoQwu5:AH+8p8S2VnytrhN2uvJileHKIUa

Entry address:
0x58DD

Entry point:
E8, 70, 6B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 44, A7, 44, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, C4, A1, 44, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 56, 8B, 75, 0C, 56, E8, 65, 5B, 00, 00, 89, 45, 0C, 8B, 46, 0C, 59, A8, 82, 75, 17, E8, BD, 0F, 00, 00, C7, 00, 09, 00, 00, 00, 83, 4E, 0C, 20...
 
[+]

Entropy:
7.4475

Code size:
291 KB (297,984 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CtrlSkype

Command:
C:\users\{user}\appdata\roaming\skype\ctrlskype.exe


Remove ctrlskype.exe - Powered by Reason Core Security