kb01841123.exe

Pleasure

Vote stranger - www.Pleasure.com

The executable kb01841123.exe, “Halfway pictured slept transportation bound” has been detected as malware by 6 anti-virus scanners.
Publisher:
Vote stranger - www.Pleasure.com

Product:
Pleasure

Description:
Halfway pictured slept transportation bound

Version:
8.0.0.5

MD5:
e713067e30975d7263b54a0f41281f0b

SHA-1:
32c77630eb5fd02236437bd0431e1f98f1b5da98

SHA-256:
d621bb588911e91904b6c1016006eceff57307472986a4bd443b4f20a9c0b1ba

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
4/25/2024 3:46:34 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-150306

ESET NOD32
Win32/Injector.BVTN (variant)
9.11277

K7 AntiVirus
Trojan
13.200.15178

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2389

Malwarebytes
Trojan.Agent.DED
v2015.03.06.06

Sophos
Mal/Wonton-AS
4.98

File size:
268.5 KB (274,944 bytes)

Product version:
8.0

Copyright:
Copyright (C) Pleasure 2001-2013

File type:
Executable application (Win32 EXE)

Language:
Arabic (Saudi Arabia)

Common path:
C:\users\{user}\appdata\local\temp\kb01841123.exe

File PE Metadata
Compilation timestamp:
3/6/2015 5:05:07 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:YZVW3sdd4MkJYz47VwAO7T0sgHtEjJOpgVqn6/QloJsqREVSAmM4:YZ8cdd4MkJLa5gHtEjJOWd/HJs/SAmv

Entry address:
0xADA2

Entry point:
E8, 1E, 76, 00, 00, E9, 78, FE, FF, FF, 55, 8B, EC, 83, EC, 08, 89, 7D, FC, 89, 75, F8, 8B, 75, 0C, 8B, 7D, 08, 8B, 4D, 10, C1, E9, 07, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66, 0F, 6F, 4E, 10, 66, 0F, 6F, 56, 20, 66, 0F, 6F, 5E, 30, 66, 0F, 7F, 07, 66, 0F, 7F, 4F, 10, 66, 0F, 7F, 57, 20, 66, 0F, 7F, 5F, 30, 66, 0F, 6F, 66, 40, 66, 0F, 6F, 6E, 50, 66, 0F, 6F, 76, 60, 66, 0F, 6F, 7E, 70, 66, 0F, 7F, 67, 40, 66, 0F, 7F, 6F, 50, 66, 0F, 7F, 77, 60, 66, 0F, 7F, 7F, 70, 8D, B6, 80, 00, 00, 00, 8D, BF...
 
[+]

Code size:
109 KB (111,616 bytes)

Remove kb01841123.exe - Powered by Reason Core Security