gategs.dll

The library gategs.dll has been detected as malware by 3 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘gategs’.
MD5:
3d460af807090ade13c66de24c3bf232

SHA-1:
e0af3ccc033e6ae4b426695f9dd4afd691905b08

SHA-256:
73bae9878ddc354f8550887e46d1493b77e3d33d05b8cdc9b2146afd1afdeeff

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
4/24/2024 9:40:20 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

ESET NOD32
Win32/TrojanProxy.Agent.NZR trojan
7.0.302.0

Sophos
Virus 'Mal/RansomDl-A'
5.22

File size:
8.5 KB (8,704 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\gategs.dll

File PE Metadata
Compilation timestamp:
1/31/2016 6:52:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
192:oiRMwe/MVqF3zicCbUMm6Daj8yLF3FDjYG:oiRMwecqebUMmEyL38G

Entry address:
0x23F6

Entry point:
55, 8B, EC, 83, C4, E8, FF, 35, 15, 40, 00, 10, 58, C9, C2, 0C, 00, B8, 81, 36, 90, 00, 6A, FF, E8, DD, 00, 00, 00, 6A, 03, 01, B8, FD, FF, FF, FF, 49, 40, 40, F7, D8, 50, FF, 15, 9C, A2, 00, 10, 55, 8B, EC, BF, 00, 00, 00, 00, 4F, AD, 60, 60, 8B, EC, E8, 70, 00, 00, 00, 8B, 52, 0C, 8B, 52, 14, FF, 72, 28, 5E, FF, 75, 28, 59, 8B, F6, BF, 00, 00, 00, 00, 0F, B6, 06, 46, 3C, 61, 7C, 07, 2C, 0F, 2C, 01, 48, 2C, 0F, C1, CF, 0D, 03, F8, 8B, FF, E2, E8, 3B, 7D, 24, 8B, 5A, 10, FF, 32, 5A, 0F, 85, 8D, F8, FF, FF...
 
[+]

Entropy:
5.5314

Developed / compiled with:
Microsoft Visual C++

Code size:
5.5 KB (5,632 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
gategs

Command:
rundll32.exe "C:\users\{user}\appdata\local\gategs.dll",gategs


Remove gategs.dll - Powered by Reason Core Security