diagprog.exe

The executable diagprog.exe has been detected as malware by 24 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘{BEDCC14A-1AC1-1455-9341-709E08809D6B}’.
MD5:
7b51b2ae811740d7028f49573abf516f

SHA-1:
fdfcc6a4ac0f8030e5a2d9f8552724e0387d18b4

SHA-256:
1e39d25ae603f3e6fe09886175b7d491f5d07a77018334b8c4a5ed67dc160339

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/29/2024 12:02:42 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Buzus.590972
5.0.

Avira AntiVirus
TR/Dropper.Gen
7.9.0.148

Emsisoft A-Squared
Virus.Packed.Win32.CPEX.based.ds!IK
4.0.0.101

avast!
Win32:Bifrose-DNR
2014.9-170313

AVG
Generic_c
2018.0.2441

Bitdefender
MemScan:Backdoor.Bifrose.AABL
1.0.20.360

Clam AntiVirus
Trojan.Buzus-90
0.98/171

ESET NOD32
Win32/Packed.Themida (variant)
11.4028

Fortinet FortiGate
W32/Buzus.HSD!tr
3/13/2017

F-Prot
W32/Backdoor2.BKIG
v6.4.4.4.56

F-Secure
Trojan.Win32.Buzus.hsd
11.2017-13-03_2

G Data
MemScan:Backdoor.Bifrose.AABL
17.3.19

IKARUS anti.virus
Virus.Packed.Win32.CPEX.based.ds
t3scan.1.2.09.0

K7 AntiVirus
Backdoor.Win32.Small.BVNQ
13.7.10.710

Kaspersky
Trojan.Win32.Buzus
14.0.0.-1302

McAfee
Backdoor-CEP
5600.6097

Microsoft Security Essentials
Backdoor:Win32/Bifrose.EY
1.163.1557.0

Norman
W32/Buzus.EZR
11.20170313

nProtect
Trojan/W32.Buzus.1822582
2009.1.8.0

Prevx
Medium Risk Malware
V2

Quick Heal
Win32.Packed.CPEX-based.ds.5
3.17.10.00

Sophos
Troj/Agent-HCU
4.40

Vba32 AntiVirus
Trojan.Win32.Buzus.hsd
3.12.10.2

ViRobot
Trojan.Win32.Buzus.609768
2009.4.22.1704

File size:
640.2 KB (655,555 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\setup\diagprog.exe

File PE Metadata
Compilation timestamp:
5/18/2008 7:20:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0xB014

Entry point:
E9, 40, 33, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.3135

Packer / compiler:
Xtreme-Protector v1.05

Code size:
2 KB (2,048 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
{BEDCC14A-1AC1-1455-9341-709E08809D6B}

Command:
C:\users\{user}\appdata\roaming\setup\diagprog.exe


Remove diagprog.exe - Powered by Reason Core Security