FMAPP.EXE

FMAPP Application

Fortemedia Inc

The executable FMAPP.EXE has been detected as malware by 7 anti-virus scanners.
Publisher:
Fortemedia Inc  (signed and verified)

Product:
FMAPP Application

Version:
1, 64, 0, 1

MD5:
75edb79e64806bd718493c50531f90fa

SHA-1:
2df7c1d0ab8d4b510ba6fc8d9c537077365ce915

SHA-256:
784ad8bb2d7de7b3c7c57d7ec0352398975e6178bd6dc13a1bb038a2f3f70aa2

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/26/2024 3:49:48 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Patched-HO [Trj]
160111-0

AVG
Win32/Slugin.A
2015.0.4489

Dr.Web
Trojan.MulDrop3.48024
9.0.1.05190

Emsisoft Anti-Malware
Win32.SlugIn.A.Dam
10.0.0.5366

F-Prot
W32/Slugin.A.gen!Eldorado (generic, damaged, not disinfectable)
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.213.2982.0

Norman
Win32.SlugIn.A.Dam
11.01.2016 17:30:26

File size:
140.4 KB (143,747 bytes)

Product version:
1, 64, 0, 1

Copyright:
Copyright (C) 2010

Original file name:
FMAPP.EXE

File type:
Executable application (Win64 EXE)

Language:
Chinese (Traditional, Taiwan)

Common path:
C:\users\{user}\appdata\local\s-1-5-31-1286970278978-5713669491-166975984-320\rotinom\quy\bo cai\chuong trinh\aspire 4752 13-02-2012 11-47-29 sa\media\realtek high definition audio\fmapp.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/27/2009 12:00:00 AM

Valid to:
11/27/2010 11:59:59 PM

Subject:
CN=Fortemedia Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Fortemedia Inc, L=Sunnyvale, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
312D884C6B08CD6E07B744C2DA7A07C2

File PE Metadata
Compilation timestamp:
10/26/2010 10:58:38 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:N4k5mXUVXjnPiW55f5phYZ4z1sxJbjIUWnoRz2:NmEVznnhYZ4zyJbLC

Entry address:
0x1664

Entry point:
48, 83, EC, 28, E8, AF, 18, 00, 00, 48, 83, C4, 28, E9, 1A, FE, FF, FF, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, 95, 9A, 00, 00, FF, 15, 27, 5A, 00, 00, 4C, 8B, 1D, 80, 9B, 00, 00, 4C, 89, 5C, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, AB, 54, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24, 50, 00, 74, 41, 48, C7, 44, 24, 38, 00, 00, 00, 00, 48, 8D, 44, 24, 48, 48, 89, 44, 24, 30, 48, 8D, 44, 24, 40, 48, 89, 44, 24, 28, 48, 8D, 05, 40, 9A, 00, 00, 48, 89, 44, 24...
 
[+]

Code size:
23.5 KB (24,064 bytes)

Remove FMAPP.EXE - Powered by Reason Core Security