igfxext.exe

TRADE-VAN

The executable igfxext.exe has been detected as malware by 31 anti-virus scanners.
Publisher:
TRADE-VAN  (signed and verified)

MD5:
23d7db6c816ff5c199ae253a6fdc0bca

SHA-1:
5d58b12b030445b43d5c5381485faa69adad7334

SHA-256:
a396293b539ed8bc1bad59da52dbd1d400e6ad028b89961572996675636e7f5f

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/18/2024 3:00:05 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Heur.Jatif.43
477

AhnLab V3 Security
Trojan/Win32.Vundo
2015.09.08

Avira AntiVirus
TR/Agent.60184.4
8.3.2.2

Arcabit
Trojan.Jatif.43
1.0.0.425

avast!
Win32:Malware-gen
2014.9-151016

AVG
Win32/DH{Exd+UIEHeVRPFVGBFYEJHFN8fTAgIiU}
2016.0.2955

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.151016

Bitdefender
Gen:Heur.Jatif.43
1.0.20.1445

Comodo Security
UnclassifiedMalware
23193

Dr.Web
Trojan.Click2.41018
9.0.1.0289

Emsisoft Anti-Malware
Gen:Heur.Jatif.43
8.15.10.16.07

ESET NOD32
Win32/Agent.SEL
9.12213

Fortinet FortiGate
W32/Inject.WKD!tr
10/16/2015

F-Prot
W32/Dropper.6!Generic
v6.4.7.1.166

F-Secure
Gen:Heur.Jatif.43
11.2015-16-10_6

G Data
Gen:Heur.Jatif.43
15.10.25

K7 AntiVirus
Trojan
13.2017129

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1268

McAfee
Generic Dropper.cx
5600.6611

Microsoft Security Essentials
TrojanDownloader:Win32/Nemim.gen!A
1.1.12002.0

MicroWorld eScan
Gen:Heur.Jatif.43
16.0.0.867

NANO AntiVirus
Trojan.Win32.Agent2.bcfrjh
0.30.24.3283

Panda Antivirus
Generic Malware
15.10.16.07

Qihoo 360 Security
Win32/Trojan.204
1.0.0.1015

Quick Heal
TrojanAPT.Nemim.DL4
10.15.14.00

Sophos
Mal/Behav-009
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Injector
9566

Trend Micro House Call
TROJ_NEMIM.C
7.2.289

Trend Micro
Cryp_Xin2
10.465.16

VIPRE Antivirus
Trojan.Win32.Generic
43520

Zillya! Antivirus
Trojan.Injector.Win32.205690
2.0.0.2388

File size:
58.8 KB (60,184 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\microsoft\display\igfxext.exe

Digital Signature
Signed by:

Authority:
TAIWAN-CA.COM Inc.

Valid from:
7/2/2010 2:34:05 AM

Valid to:
7/17/2011 11:59:59 AM

Subject:
CN=www.esupplychain.com.tw, OU=TRADE-VAN, O=TRADE-VAN, L=Taipei, S=Taipei, C=TW

Issuer:
CN=TaiCA Secure CA, OU=SSL Certification Service Provider, O=TAIWAN-CA.COM Inc., C=TW

Serial number:
65C80810

File PE Metadata
Compilation timestamp:
6/2/2012 3:23:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:6TLYWJHGLibjTkDTwxdXq1rhPb0lU47/n3KOHU0n1AWe1WPiwYgY5:6TULibjTkD07oOlDn3b00CWe1WPiw3Y5

Entry address:
0x190B

Entry point:
55, 8B, EC, 6A, FF, 68, 00, 51, 40, 00, 68, 58, 2F, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 58, 50, 40, 00, 33, D2, 8A, D4, 89, 15, B4, D4, 40, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, B0, D4, 40, 00, C1, E1, 08, 03, CA, 89, 0D, AC, D4, 40, 00, C1, E8, 10, A3, A8, D4, 40, 00, 6A, 01, E8, C0, 02, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 17, 14, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
5.7481

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
16 KB (16,384 bytes)

Remove igfxext.exe - Powered by Reason Core Security