danfemon.EXE

DANFE Mon

UNIMAKE SOLUCOES CORPORATIVAS LTDA - EPP

The executable danfemon.EXE, “Monitor do UniDANFE / DANFE View” has been detected as malware by 6 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DANFEViewMon’.
Publisher:
Unimake Software  (signed by UNIMAKE SOLUCOES CORPORATIVAS LTDA - EPP)

Product:
DANFE Mon

Description:
Monitor do UniDANFE / DANFE View

Version:
1.4.4.645

MD5:
dd005170d154f6feb146b040d4e15f44

SHA-1:
beba4e1b13186639b1b81bb4cb2f33400282dc1f

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
4/25/2024 9:35:14 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Patched-JI
160917-0

AVG
Win32/Slugin.A
2013.0.4477

Clam AntiVirus
Win.Spyware.59563-2
0.98/22861

Dr.Web
Win32.Wplugin.2
9.0.1.05190

ESET NOD32
Win32/Slugin.A virus
6.3.12010.0

F-Prot
W32/Slugin.B
4.6.5.141

File size:
4.3 MB (4,461,171 bytes)

Product version:
1.4.4.645

Copyright:
Copyright © Unimake Softwares

Trademarks:
Todos os direitos reservados

Original file name:
danfemon.EXE

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/23/2014 1:39:38 PM

Valid to:
1/24/2015 1:39:38 PM

Subject:
CN=UNIMAKE SOLUCOES CORPORATIVAS LTDA - EPP, OU=T.I, O=UNIMAKE SOLUCOES CORPORATIVAS LTDA - EPP, L=PARANAVAI, S=PARANA, C=BR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E4AEA5267F75002C315FE337269D6D37

File PE Metadata
Compilation timestamp:
8/6/2014 3:19:45 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

Entry address:
0xAA48C

Entry point:
60, E8, 00, 00, 00, 00, 5B, 81, EB, D0, 48, 44, 01, 83, EC, 74, 8B, EC, 8B, 83, AB, 4B, 44, 01, 89, 45, 00, 8B, 83, B3, 4B, 44, 01, 03, 45, 00, 89, 45, 2C, 8B, 83, B7, 4B, 44, 01, 03, 45, 00, 89, 45, 30, C7, 45, 14, 00, 00, 00, 00, C7, 45, 18, 00, 00, 00, 00, C7, 45, 1C, 00, 00, 00, 00, 8B, 45, 14, FF, 45, 14, 66, 33, C9, 8A, 8C, 03, FF, 4B, 44, 01, 84, C9, 74, 7A, 8B, 45, 1C, 66, 01, 4D, 1C, 03, C3, 05, 13, 4C, 44, 01, 50, 8B, 45, 2C, FF, 10, 85, C0, 0F, 84, 5E, 02, 00, 00, 89, 45, 10, 8B, 45, 1C, 03, C3...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
1.1 MB (1,183,744 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DANFEViewMon

Command:
C:\danfeview\danfemon.exe


Remove danfemon.EXE - Powered by Reason Core Security