knsk1f6d.tmp

The file knsk1f6d.tmp has been detected as a potentially unwanted program by 9 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Capital Letters Brightness”.
MD5:
d983b9465919fb35b80943e0e7cfba2c

SHA-1:
7bcb9dd0768028148467bc7136c3208a0edfede7

SHA-256:
2c56d7617dcd9fab9714846b3053798c64fbaafa7e7b9c49a3d9749ffcd5cc35

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 3:06:26 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Kazy.642419
550

Arcabit
Trojan.Application.Kazy.D9CD73
1.0.0.425

Baidu Antivirus
Adware.Win32.ConvertAd
4.0.3.1584

Bitdefender
Gen:Variant.Application.Kazy.642419
1.0.20.1080

ESET NOD32
Win32/Adware.ConvertAd.SB (variant)
9.12032

F-Secure
Gen:Variant.Application.Kazy
11.2015-04-08_3

G Data
Gen:Variant.Application.Kazy.642419
15.8.25

MicroWorld eScan
Gen:Variant.Application.Kazy.642419
16.0.0.648

Rising Antivirus
PE:Trojan.Win32.Generic.18E9DB7E!417979262
23.00.65.15802

File size:
286 KB (292,864 bytes)

Common path:
C:\Program Files\1c6c4418-1438439599-df11-a69d-001e8ca6808c\knsk1f6d.tmp

File PE Metadata
Compilation timestamp:
8/2/2015 1:32:10 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:oR+mQsVTzpRbiE1w7v0PquSTYkqGi8hdHJFFFFvJ:oR+fiTviEEv0P18Ykdi6dHz

Entry address:
0x224C1

Entry point:
E8, 16, 75, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 55, 08, 56, 57, 85, D2, 74, 07, 8B, 7D, 0C, 85, FF, 75, 13, E8, 23, 23, 00, 00, 6A, 16, 5E, 89, 30, E8, C7, 22, 00, 00, 8B, C6, EB, 33, 8B, 45, 10, 85, C0, 75, 04, 88, 02, EB, E2, 8B, F2, 2B, F0, 8A, 08, 88, 0C, 06, 40, 84, C9, 74, 03, 4F, 75, F3, 85, FF, 75, 11, C6, 02, 00, E8, ED, 22, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, C6, 33, C0, 5F, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 34, 54, 44, 00, 00...
 
[+]

Code size:
201 KB (205,824 bytes)

Service
Display name:
Capital Letters Brightness

Service name:
goloqiwe

Description:
Convert Recycle Bin

Type:
Win32OwnProcess


Remove knsk1f6d.tmp - Powered by Reason Core Security