DuoLa.exe

Zhenjiang ChangYou Network Technology Co., Ltd.

The executable DuoLa.exe has been detected as malware by 10 anti-virus scanners.
Publisher:
多啦影视  (signed by Zhenjiang ChangYou Network Technology Co., Ltd.)

Product:
多啦影视

Version:
1.0.0.2

MD5:
6fa6c60faee54f7b2c833d0237f1967b

SHA-1:
62d397c0836797cb66b83c83ccd5f1b10a8b6118

SHA-256:
92583f39fe46916326783c654bfe7c7653922d7700e775765ef8515ec976eaa4

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
4/19/2024 6:38:05 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.MDA
2015.01.25

avast!
Win32:Trojan-gen
2014.9-150317

AVG
Generic
2016.0.3168

Baidu Antivirus
Trojan.Win32.ShouQu
4.0.3.15317

Comodo Security
UnclassifiedMalware
20831

ESET NOD32
Win32/RiskWare.ShouQu (variant)
9.11067

McAfee
Artemis!6FA6C60FAEE5
5600.6824

Sophos
Generic PUA GC
4.98

Trend Micro House Call
Suspicious_GEN.F47V0116
7.2.76

VIPRE Antivirus
Trojan.Win32.Generic
36940

File size:
1.9 MB (1,984,032 bytes)

Product version:
1.0.0.2

Copyright:
多啦影视 (C)2014

Original file name:
DuoLa.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\duola\201503171144\duola.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/7/2014 6:00:00 AM

Valid to:
3/8/2015 5:59:59 AM

Subject:
CN="Zhenjiang ChangYou Network Technology Co., Ltd.", OU=技术部, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Zhenjiang ChangYou Network Technology Co., Ltd.", L=Zhenjiang, S=Jiangsu, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E647F3525E873BEEE27CE28AD420537

File PE Metadata
Compilation timestamp:
12/3/2014 6:54:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:w1Bpv2DJOwMvw8XfMxcu69iuk9Lmoo+1ikfM7Y159o:w1BN4JOwMvwWIpRo+1ikfM7+I

Entry address:
0x2D08

Entry point:
68, 80, 2F, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, E7, 19, 43, AE, B5, AD, 8C, 47, B9, F8, 4A, BB, 36, 35, FE, F2, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 44, 75, 6F, 4C, 61, 00, 30, 30, 00, 00, 00, 00, 01, 00, 0B, 00, 74, 96, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, D8, 98, 40, 00, 8C, 30, 5C, 00, 00, 00, 00, 00, C0, 7B, 7B, 06, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 88, 2D, 40, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
1.8 MB (1,843,200 bytes)

Remove DuoLa.exe - Powered by Reason Core Security