d2.exe

D2

JANDER PINTO DA SILVA

The application d2.exe by JANDER PINTO DA SILVA has been detected as adware by 4 anti-malware scanners.
Publisher:
Tronic.inc  (signed by JANDER PINTO DA SILVA)

Product:
D2

Version:
6.2.8.1

MD5:
16ba1860a58f105ceb037fb9032663fc

SHA-1:
ed01706b73f0a9c8cc1bd08214fc6d8edcdd680b

SHA-256:
8655e5f85bbe875bdfc898addb958486d6ed64c1cd1e1597cab8a3d0145fc49f

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
4/26/2024 2:16:51 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Banker
14.04.16

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.6.1.0

Reason Heuristics
PUP.JANDERPINTODASILVA.C
14.4.16.21

VIPRE Antivirus
Trojan.Compcert.121913
28115

File size:
379.8 KB (388,952 bytes)

Product version:
6.2.8.1

Copyright:
Tronic.inc

Trademarks:
Tronic.inc

Original file name:
D2

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\windows\d2.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/12/2013 9:00:00 PM

Valid to:
9/12/2014 8:59:59 PM

Subject:
CN=JANDER PINTO DA SILVA, OU=Individual Developer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=No Organization Affiliation, L=PALMAS, S=TOCANTINS, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1FC6AD26672CBA136E6B00334840CA37

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:cYXvL4oko8ASaPmYrKxlONq43GV6bYiU+T1+Q4CdurB/NGILYpr6hJ0Ol+:VT4oz8ASa83/96so1+IujGEYiJ0k+

Entry address:
0x4FA10

Entry point:
55, 8B, EC, 83, C4, F0, B8, 30, F8, 44, 00, E8, A8, 61, FB, FF, A1, 00, 10, 45, 00, 8B, 00, E8, B0, E3, FF, FF, 8B, 0D, DC, 10, 45, 00, A1, 00, 10, 45, 00, 8B, 00, 8B, 15, 7C, F3, 44, 00, E8, B0, E3, FF, FF, A1, 00, 10, 45, 00, 8B, 00, E8, 24, E4, FF, FF, E8, CB, 42, FB, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
315 KB (322,560 bytes)

Remove d2.exe - Powered by Reason Core Security