eevwprok1.exe

Jetico, Inc. BCResident

Jetico, Inc.

The executable eevwprok1.exe has been detected as malware by 25 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘evwprok’.
Publisher:
Jetico, Inc.

Product:
Jetico, Inc. BCResident

Description:
BCResident

Version:
2.11.8

MD5:
e49dc9761c322832eaba560bb6f105e5

SHA-1:
2789f99a21160e1c37f9ebb6d027aa03a953c348

SHA-256:
d6378a5f669218e1d3931fbe9f9fe52bd0ddaf8271de2be631664e4b0a8dfa23

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
4/18/2024 7:26:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11833412
857

AhnLab V3 Security
Trojan/Win32.Necurs
2014.09.29

Avira AntiVirus
TR/Neutrino.A.4
7.11.175.32

avast!
Win32:Dropper-gen [Drp]
2014.9-140930

AVG
Agent5
2015.0.3336

Baidu Antivirus
Trojan.Win32.Yakes
4.0.3.14101

Bitdefender
Trojan.Generic.11833412
1.0.20.1370

Emsisoft Anti-Malware
Trojan.Generic.11833412
8.14.10.01.01

ESET NOD32
Win32/Injector.BMMN (variant)
8.10472

F-Secure
Trojan.Generic.11833412
11.2014-01-10_4

G Data
Trojan.Generic.11833412
14.10.24

IKARUS anti.virus
Trojan.Win32.Inject
t3scan.1.7.8.0

Kaspersky
Worm.Win32.Hamweq
14.0.0.3173

Malwarebytes
Trojan.Ransom.ED
v2014.09.30.08

McAfee
Artemis!598776594DCF
5600.6991

MicroWorld eScan
Trojan.Generic.11833412
15.0.0.822

Norman
Troj_Generic.WAIOS
11.20141001

nProtect
Trojan.Generic.11833412
14.09.28.01

Panda Antivirus
Trj/Chgt.I
14.10.01.01

Qihoo 360 Security
Win32/Trojan.Multi.daf
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.10.1.1

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_FORUCON.BMC
7.2.273

Trend Micro
TROJ_FORUCON.BMC
10.465.30

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
33514

File size:
175.5 KB (179,712 bytes)

Product version:
2.11.8

Copyright:
Copyright © 1997-2011

Original file name:
BCResident.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
9/26/2014 2:11:57 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:jQN8O8dbbNAU0cgHUkXIuF1ulK3GseVXLNCnKNScPr18cMgJf9+2+ogiNKqTEoci:kN8jdj0rU8wVBVL1PMgvvTLKRocgmF/e

Entry address:
0xE1B0

Entry point:
E8, 37, 43, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, A3, 90, 32, 42, 00, 5D, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 10, 12, 42, 00, 33, C5, 89, 45, FC, 53, 8B, 5D, 08, 57, 83, FB, FF, 74, 07, 53, E8, 99, 43, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, 9A, 43, 00, 00, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8...
 
[+]

Entropy:
5.9139

Code size:
101 KB (103,424 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
evwprok

Command:
C:\recycler\{random}\eevwprok1.exe


Remove eevwprok1.exe - Powered by Reason Core Security