knsk38f5.tmpfs

The file knsk38f5.tmpfs has been detected as a potentially unwanted program by 26 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Connect Plug-in”.
MD5:
f48d1405fa2f514ceecd6de5d45a621e

SHA-1:
134aa0b9e5d2f9bbc2cefe332e63ecfacb1da04d

SHA-256:
96a1bf8cfc419159c8f3605e16c420917112a16c31dfd911bd483a5a200f2578

Scanner detections:
26 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 10:18:15 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.ConvertAd.21
484

Agnitum Outpost
PUA.Agent
7.1.1

Avira AntiVirus
ADWARE/ConvertAd.858624
8.3.2.2

Arcabit
Trojan.Adware.ConvertAd.21
1.0.0.525

AVG
Generic6
2016.0.2962

Baidu Antivirus
Adware.Win32.ConvertAd
4.0.3.1593

Bitdefender
Gen:Variant.Adware.ConvertAd.21
1.0.20.1410

Comodo Security
ApplicUnwnt
23207

Dr.Web
Adware.ClickMeIn.2256
9.0.1.0285

Emsisoft Anti-Malware
Gen:Variant.Adware.ConvertAd.21
8.15.10.09.10

ESET NOD32
Win32/Adware.ConvertAd.WY (variant)
9.12194

Fortinet FortiGate
Riskware/ConvertAd
10/9/2015

F-Secure
Gen:Variant.Adware.ConvertAd
11.2015-09-10_6

G Data
Gen:Variant.Adware.ConvertAd.21
15.10.25

K7 AntiVirus
Adware
13.2017166

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.1303

McAfee
Artemis!F48D1405FA2F
5600.6618

MicroWorld eScan
Gen:Variant.Adware.ConvertAd.21
16.0.0.846

NANO AntiVirus
Riskware.Win32.Agent.dwoxaa
0.30.24.3283

Panda Antivirus
Generic Suspicious
15.10.09.10

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.10.12.16

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D[F1]
23.00.65.151007

Sophos
Generic PUA BD (PUA)
4.98

Trend Micro
TROJ_GEN.R00XC0EI615
10.465.09

VIPRE Antivirus
Adware.Agent
43610

File size:
838.5 KB (858,624 bytes)

Common path:
C:\Program Files\03000200-1441257409-0500-0006-000700080009\knsk38f5.tmpfs

File PE Metadata
Compilation timestamp:
9/3/2015 9:57:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:pNoRl8G1iB65roBbnDaosUzzDjpJTBmezw1wNZKlmGD:768RamakzQ1wN1GD

Entry address:
0x8C1E8

Entry point:
E8, FB, 9B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 4C, 23, 4B, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 78, 21, 4B, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 8B, 55, 08, 56, 57, 85, D2, 74, 07, 8B, 7D, 0C, 85, FF, 75, 13, E8, D7, 16, 00, 00, 6A, 16, 5E, 89, 30, E8, 42, 16, 00, 00, 8B, C6, EB, 33, 8B, 45...
 
[+]

Entropy:
6.6294

Code size:
706 KB (722,944 bytes)

Service
Display name:
Connect Plug-in

Service name:
sorokedi

Description:
Digital Photo Electricity

Type:
Win32OwnProcess


Remove knsk38f5.tmpfs - Powered by Reason Core Security