ehptwqhx.exe

The application ehptwqhx.exe has been detected as a potentially unwanted program by 34 anti-malware scanners.
MD5:
9259037b6b99782356edeffe70451ee6

SHA-1:
aa722f73f9a3af0b0e4e998d7960b0fc63f26a1f

SHA-256:
851d6caca31b8922dc7761f9e6ee1dfda6768340366064db25d1e1d0cfa30aa5

Scanner detections:
34 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 3:09:00 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Downloader.JRKI
701

Agnitum Outpost
Trojan.Staser
7.1.1

AhnLab V3 Security
Trojan/Win32.Upatre
2015.03.02

Avira AntiVirus
TR/Crypt.ZPACK.24577
7.11.213.12

avast!
Win32:Malware-gen
2014.9-150306

AVG
SHeur4
2016.0.3179

Baidu Antivirus
Trojan.Win32.Staser
4.0.3.1536

Bitdefender
Trojan.Downloader.JRKI
1.0.20.325

Comodo Security
TrojWare.Win32.UMal.~A
21258

Dr.Web
Trojan.Dyre.43
9.0.1.065

Emsisoft Anti-Malware
Trojan.Downloader.JRKI
8.15.03.06.06

ESET NOD32
Win32/Battdil
9.11252

Fortinet FortiGate
W32/Staser.AYMW!tr
3/6/2015

F-Secure
Trojan.Downloader.JRKI
11.2015-06-03_6

G Data
Trojan.Downloader.JRKI
15.3.25

IKARUS anti.virus
Trojan.Inject
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.1915120

Kaspersky
Trojan.Win32.Staser
14.0.0.2389

Malwarebytes
Trojan.Dropper.ED
v2015.03.06.06

McAfee
RDN/Generic PWS.y!bcr
5600.6835

Microsoft Security Essentials
PWS:Win32/Dyzap
1.1.11400.0

MicroWorld eScan
Trojan.Downloader.JRKI
16.0.0.195

NANO AntiVirus
Trojan.Win32.Staser.dnpsez
0.30.0.296

Norman
Troj_Generic.YQAWC
11.20150306

nProtect
Trojan.Downloader.JRKI
15.02.27.01

Panda Antivirus
Trj/Genetic.gen
15.03.06.06

Quick Heal
Trojan.Staser.r4
3.15.14.00

Sophos
Troj/Dyreza-BR
4.98

Total Defense
Win32/Tnega.AdNBVO
37.0.11471

Trend Micro House Call
TROJ_SPNV.01BD15
7.2.65

Trend Micro
TROJ_SPNV.01BD15
10.465.06

Vba32 AntiVirus
Trojan.Staser
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
38028

Zillya! Antivirus
Trojan.Staser.Win32.3042
2.0.0.2085

File size:
528 KB (540,672 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\ehptwqhx.exe

File PE Metadata
Compilation timestamp:
6/19/2015 5:13:30 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:DCqo3ypZ+Hh4Oevu6VXGi8SsnO5OoYRX3Lz7povap1XHbt4kkQ19OJdUAuBgmjOs:YoZG3cuuWiJs1ouX3O0HDp+JCLe3

Entry address:
0xDDD0

Entry point:
55, 8B, EC, 6A, FF, 68, 08, F8, 46, 00, 68, 30, DD, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 54, 50, 46, 00, 59, 83, 0D, C0, 8E, 47, 00, FF, 83, 0D, C4, 8E, 47, 00, FF, FF, 15, 58, 50, 46, 00, 8B, 0D, BC, 8E, 47, 00, 89, 08, FF, 15, 5C, 50, 46, 00, 8B, 0D, B8, 8E, 47, 00, 89, 08, A1, 60, 50, 46, 00, 8B, 00, A3, C8, 8E, 47, 00, E8, F9, 58, 01, 00, 39, 1D, B0, 80, 47, 00, 75, 0C, 68, B0, D0, 44, 00, FF, 15, 64, 50...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
400 KB (409,600 bytes)

Remove ehptwqhx.exe - Powered by Reason Core Security