easyclicker pro 1.3v.exe

The application easyclicker pro 1.3v.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from s10469.chomikuj.pl.
MD5:
77b82f987dc9b0f291973cad7593ef4f

SHA-1:
9c30def508ca8101c8c56bf5fab5b0d0f0a6fcb6

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
5/9/2025 4:05:24 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Agent-XW [Trj]
160215-2

Emsisoft Anti-Malware
Gen:Trojan.Heur.MR.!qZ@aWCR9!lc
10.0.0.5366

ESET NOD32
Win32/Spy.PerfKey.U.Gen trojan
8.0.319.0

F-Prot
W32/Banker.ALWM
4.6.5.141

Kaspersky
not-a-virus:Monitor.Win32.Perflogger
15.0.0.562

McAfee
Trojan.RapSFX packed app
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.7242.0

Norman
Gen:Trojan.Heur.MR.!qZ@aWCR9!lc
19.02.2016 10:08:15

File size:
1007.6 KB (1,031,774 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\documents and settings\śledzik\moje dokumenty\downloads\easyclicker pro 1.3v.exe

File PE Metadata
Compilation timestamp:
3/2/2001 7:25:22 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
24576:+4NUQLFAwVv/CvccvvtEolTVkKDVeoprL+GIC:+4NUQLaw9/OvNDVaGIC

Entry address:
0x1000

Entry point:
E9, 5F, 10, 00, 00, 00, 00, 00, 00, 90, 90, 90, 6A, 00, 68, 58, 10, 40, 00, 6A, 00, 68, 12, 71, 40, 00, FF, 35, 5C, 78, 40, 00, E8, 8B, 5E, 00, 00, 83, 3D, 64, 78, 40, 00, 00, 75, 1B, 83, 3D, 70, 78, 40, 00, 00, 75, 12, B9, 03, 00, 00, 00, 8B, 15, 40, 70, 40, 00, 33, C0, E8, 84, 06, 00, 00, 80, 3D, 3C, 70, 40, 00, 00, 74, 05, E8, 7D, 0E, 00, 00, C3, 55, 8B, EC, 50, B8, 02, 00, 00, 00, 81, C4, 04, F0, FF, FF, 50, 48, 75, F6, 81, C4, 04, F2, FF, FF, 8B, 45, FC, 53, 56, 57, 8B, 7D, 10, 8B, 5D, 0C, 8B, 75, 08...
 
[+]

Packer / compiler:
WinRAR, 0x32-bit SFX Module

Code size:
24 KB (24,576 bytes)

The file easyclicker pro 1.3v.exe has been seen being distributed by the following URL.

Remove easyclicker pro 1.3v.exe - Powered by Reason Core Security