kuzar.exe

The executable kuzar.exe has been detected as malware by 31 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
f1b81637d199a49a2ea5cbe9b43cd9b2

SHA-1:
7a9033a37978932884a6f61433266d118e3005b1

SHA-256:
80a08a3bf4f44c075c0f67cd6b129549782078783765ad8eef063204d1275e23

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/19/2024 8:29:01 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12055242
827

Agnitum Outpost
Trojan.Kryptik
7.1.1

AhnLab V3 Security
Trojan/Win32.ZBot
2014.10.31

Avira AntiVirus
TR/Crypt.ZPACK.Gen
7.11.30.172

avast!
Win32:Dropper-gen [Drp]
141025-0

AVG
Win32/Cryptor
2014.0.4189

Bitdefender
Trojan.Generic.12055242
1.0.20.1515

Bkav FE
HW32.Packed
1.3.0.6185

Clam AntiVirus
Win.Trojan.Agent-808490
0.98/21411

Comodo Security
TrojWare.Win32.Kryptik.COAW
19945

Dr.Web
Trojan.Siggen6.22973
9.0.1.0322

Emsisoft Anti-Malware
Trojan.Generic.12055242
8.14.10.30.08

ESET NOD32
Win32/Kryptik.COUB (variant)
8.10646

Fortinet FortiGate
W32/Kryptik.CJJL!tr
10/30/2014

F-Prot
W32/A-2a902b6a
v6.4.7.1.166

F-Secure
Trojan.Generic.12055242
11.2014-30-10_5

G Data
Trojan.Generic.12055242
14.10.24

K7 AntiVirus
Trojan
13.185.13943

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3021

Malwarebytes
Trojan.FakeMS
v2014.10.30.08

McAfee
PWSZbot-FADO!F1B81637D199
5600.6961

Microsoft Security Essentials
Threat.Undefined
1.187.1631.0

NANO AntiVirus
Trojan.Win32.Siggen6.dhzdga
0.28.6.62995

Norman
Kryptik.CEOE
11.20141118

nProtect
Trojan.Agent.BGHR
14.11.06.01

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.18.2

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141028

SUPERAntiSpyware
Trojan.Agent/Gen-Kryptik
10231

Total Defense
Win32/Zbot.PdaJYNC
37.0.11269

VIPRE Antivirus
Trojan.Win32.Generic
34626

File size:
284.6 KB (291,431 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\eratufqo\kuzar.exe

File PE Metadata
Compilation timestamp:
1/16/2012 7:44:03 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:RsvK8nvqAMlIuEt/JAHrWMtNIGKUTbI+BRGzBlwbvbua6oCtwtqcZ5ag:RsvXny59EtKLWGNmOTymtqWAg

Entry address:
0xD6B4

Entry point:
55, 8B, EC, 81, EC, 20, 01, 00, 00, B9, 6D, 00, 00, 00, 68, 00, 64, 52, CD, 51, 6A, C8, E8, 8D, 19, 00, 00, 83, C4, 0C, 53, B8, 8C, 00, 00, 00, EB, 2A, 83, FF, C6, 74, 25, 33, DE, 81, FB, 98, 6E, 00, 00, 74, 1B, 83, F3, 22, E8, 6B, 19, 00, 00, 8B, 35, C4, 4A, 43, 00, 83, FB, 83, 74, 08, 33, DE, 89, 9D, E8, FE, FF, FF, 56, 0B, C3, 83, F8, A5, 75, 2D, 83, F0, 4D, BA, 49, 00, 00, 00, EB, 23, 83, F6, 82, F7, C6, AF, 00, 00, 00, 74, 18, 81, C6, 00, 22, 00, EF, 8B, 05, 2C, 4A, 43, 00, 89, B5, 7C, FF, FF, FF, 89...
 
[+]

Entropy:
7.8680

Developed / compiled with:
Microsoft Visual C++

Code size:
100 KB (102,400 bytes)

Scheduled Task
Task name:
Security Center Update - 1906712510

Trigger:
Daily (Runs daily at 2:00 AM)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove kuzar.exe - Powered by Reason Core Security