edg57d0.exe

Операционная система Microsoft Windows

Корпорация Майкрософт

The executable edg57d0.exe, “Программа Запуск от имени” has been detected as malware by 30 anti-virus scanners.
Publisher:
Корпорация Майкрософт

Product:
Операционная система Microsoft® Windows®

Description:
Программа Запуск от имени

Version:
5.6.1830.1 (xpclient.010817-1148)

MD5:
adac1acd630ef7956f3c879d8238d9ad

SHA-1:
43b8ac61c931a3629349742dd96b9a5c35fc31b8

SHA-256:
a4339aada83decdb65f807e141cd1cd4163054bfd8f07b905fa897093648b4ab

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/23/2024 10:59:06 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1936255
834

Avira AntiVirus
TR/Yakes.gtmu
7.11.180.234

avast!
Win32:Malware-gen
2014.9-141024

AVG
Pakes2_c
2015.0.3312

Baidu Antivirus
Trojan.Win32.Yakes
4.0.3.141024

Bitdefender
Trojan.GenericKD.1936255
1.0.20.1485

Comodo Security
TrojWare.Win32.UMal.~A
19887

Dr.Web
Trojan.Mayachok.18888
9.0.1.0297

Emsisoft Anti-Malware
Trojan.GenericKD.1936255
8.14.10.24.06

ESET NOD32
Win32/Dridex
8.10613

Fortinet FortiGate
W32/Dridex.C!tr
10/24/2014

F-Secure
Trojan.GenericKD.1936255
11.2014-24-10_6

G Data
Trojan.GenericKD.1936255
14.10.24

IKARUS anti.virus
Trojan-Spy.Agent
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.185.13789

Kaspersky
Trojan.Win32.Yakes
14.0.0.3054

Malwarebytes
Backdoor.Bot
v2014.10.24.06

McAfee
RDN/Generic BackDoor!b2i
5600.6968

Microsoft Security Essentials
Backdoor:Win32/Drixed.A
1.11104

MicroWorld eScan
Trojan.GenericKD.1936255
15.0.0.891

Norman
Dridex.C
11.20141024

nProtect
Trojan.GenericKD.1936255
14.10.24.01

Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.18.20

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141022

Sophos
Troj/Cridex-EJ
4.98

Total Defense
Win32/Cridex.dXWKdJD
37.0.11246

Trend Micro House Call
TROJ_GEN.R0C2C0DJN14
7.2.297

Trend Micro
TROJ_SPNR.11JN14
10.465.24

VIPRE Antivirus
Win32.Malware!Drop
34202

File size:
52 KB (53,248 bytes)

Product version:
5.6.1830.1

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
test.EXE

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\users\{user}\appdata\local\edg57d0.exe

File PE Metadata
Compilation timestamp:
11/10/2012 10:14:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
768:26kUlQov/FX4MUI99pOAe9IRyzJqezkd14D5cMeR+DEmF3T9:26LlBv/o2RylqezC146bItZ

Entry address:
0x5CC0

Entry point:
55, 89, E5, 56, 53, 57, 81, EC, 20, 02, 00, 00, C7, 85, 50, FE, FF, FF, 00, 00, 00, 00, 31, C0, C7, 85, 20, FE, FF, FF, 00, 00, 00, 00, C7, 85, 34, FE, FF, FF, 00, 00, 00, 00, C7, 85, 28, FE, FF, FF, 01, 00, 00, 00, B9, 01, 00, 00, 00, C7, 85, 2C, FE, FF, FF, 01, 00, 00, 00, C7, 45, E8, 00, 00, 00, 00, 66, C7, 85, 26, FE, FF, FF, 32, 18, C7, 85, 38, FE, FF, FF, 00, 00, 00, 00, C7, 45, F0, 00, 00, 00, 00, C7, 85, 44, FE, FF, FF, F3, FF, FF, FF, C7, 85, 40, FE, FF, FF, 00, 00, 00, 00, C7, 85, 48, FE, FF, FF...
 
[+]

Entropy:
6.6057

Code size:
44.5 KB (45,568 bytes)

Remove edg57d0.exe - Powered by Reason Core Security