ewatse.exe

Mesrisift Visaal Studio 2010

Mesrisift Corporatien

The executable ewatse.exe, “Mesrisift Visaal Studie 2010” has been detected as malware by 34 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Mesrisift Corporatien

Product:
Mesrisift® Visaal Studio® 2010

Description:
Mesrisift Visaal Studie 2010

Version:
1.9.43074.5121 built by: SP1Rel

MD5:
9266225dec5db131b7b058c24bf66480

SHA-1:
1ada7a3421ccd2c267cba593e0bf4418caead9a8

SHA-256:
d1a819d79f72bf2f153db705ccf1200eae024394455611360a22af9c7c0544af

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
4/26/2024 3:04:11 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11622707
885

Agnitum Outpost
TrojanSpy.Zbot
7.1.1

AhnLab V3 Security
Trojan/Win32.Zbot
2014.08.26

Avira AntiVirus
TR/Crypt.ZPACK.Gen2
7.11.30.172

avast!
Win32:Malware-gen
140813-1

AVG
Trojan horse Zbot.NAW
2014.0.4015

Bitdefender
Trojan.Generic.11622707
1.0.20.1225

Bkav FE
HW32.CDB
1.3.0.4959

Comodo Security
TrojWare.Win32.Kryptik.CJVP
19398

Dr.Web
Trojan.Packed
9.0.1.0245

Emsisoft Anti-Malware
Trojan.Generic.11622707
9.0.0.4324

ESET NOD32
Win32/Spy.Zbot.ABA
8.10316

Fortinet FortiGate
W32/Kryptik.CJED!tr
9/2/2014

F-Prot
W32/A-f655044e
v6.4.7.1.166

F-Secure
Trojan.Generic.11622707
11.2014-02-09_3

G Data
Trojan.Generic.11622707
14.9.24

K7 AntiVirus
Riskware
13.183.13160

Kaspersky
Trojan-Spy.Win32.Zbot
15.0.0.494

Malwarebytes
Trojan.Zbot.gen
v2014.09.02.06

McAfee
PWSZbot-FABW!507D85E03F05
5600.7019

Microsoft Security Essentials
Threat.Undefined
1.183.1287.0

MicroWorld eScan
Trojan.Generic.11622707
15.0.0.735

NANO AntiVirus
Trojan.Win32.Zbot.decnmn
0.28.2.61861

nProtect
Trojan.Generic.11622707
14.08.25.01

Panda Antivirus
Trj/Genetic.gen
14.09.02.06

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.2.18

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14831

Sophos
Troj/Zbot-HGR
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Falcomp[i]
10383

Total Defense
Win32/Zbot.eRdZQI
37.0.11158

Vba32 AntiVirus
TrojanSpy.Zbot
3.12.26.3

VIPRE Antivirus
Threat.4789469
32210

Zillya! Antivirus
Trojan.ZBot.Win32.12
2.0.0.1908

File size:
299 KB (306,201 bytes)

Product version:
1.9.43074.5121

Copyright:
© Mesrisift Corporatien. All rights reserved.

Original file name:
divanv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\esagudgu\ewatse.exe

File PE Metadata
Compilation timestamp:
4/27/2011 8:35:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:frpraQi2XLoc6Lry04hUzCmbgPWhpFqDDVrTIfHybEi+fHF6ul:DprY3c6fyfUzCPPW1qDxgyI3HF3l

Entry address:
0xCA20

Entry point:
55, 8B, EC, 81, EC, 80, 01, 00, 00, EB, 2F, 33, DA, 8B, C7, 68, 00, 30, CD, 12, E8, A1, 20, 00, 00, 83, C4, 04, E8, 18, 1F, 00, 00, 89, 45, D4, EB, 14, 6A, B3, 51, 6A, EE, 6A, E4, 68, 00, 69, 97, B2, E8, DC, 16, 00, 00, 83, C4, 14, 53, 89, 85, C4, FE, FF, FF, 56, 03, C0, 8B, 95, C4, FE, FF, FF, 83, FA, 02, 74, 21, 33, C2, 8B, B5, C4, FE, FF, FF, 3B, 85, 90, FE, FF, FF, 75, 11, 89, 85, C4, FE, FF, FF, 8B, CE, 3B, CE, 74, 05, E8, B1, 15, 00, 00, 57, 89, B5, C4, FE, FF, FF, 83, F6, 2A, 8B, 15, 0C, CA, 42, 00...
 
[+]

Entropy:
7.8596

Developed / compiled with:
Microsoft Visual C++

Code size:
139.5 KB (142,848 bytes)

Scheduled Task
Task name:
Security Center Update - 1053635127

Trigger:
Daily (Runs daily at 1:00 PM)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove ewatse.exe - Powered by Reason Core Security