kxfqjb.exe

Zombie News

Time Lapse Solutions

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The application kxfqjb.exe, “ZombieNews Service” by Time Lapse Solutions has been detected as adware by 9 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “kXfqJB”. According to AVG, this software downloads additional adware offers during setup.
Publisher:
Time Lapse Solutions  (signed and verified)

Product:
Zombie News

Description:
ZombieNews Service

Version:
1.0.0.0

MD5:
da467e8501d0f94533a27117d7f5b46b

SHA-1:
fe4b601264eefd542abd9460812694fc4d4b392a

SHA-256:
73672e8bb7fefc6504fd24b61bd1a0e1131f12b8c6d5e476fd1110414ed002ca

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/19/2024 7:22:45 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen7
7.11.213.12

AVG
Downloader
2016.0.3183

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.1532

Dr.Web
Adware.Yontoo.55
9.0.1.061

ESET NOD32
MSIL/Adware.PullUpdate.G.gen (variant)
9.11252

Malwarebytes
PUP.Optional.ZombieNews.A
v2015.03.02.03

McAfee
Artemis!DA467E8501D0
5600.6839

Reason Heuristics
PUP.Service.Injekt
15.3.2.3

VIPRE Antivirus
MSIL.Adware.PullUpdate
38032

File size:
2.6 MB (2,733,032 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Time Lapse Solutions 2015

Original file name:
ZombieNewsService.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\qxwvcnebw\kxfqjb.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
1/25/2015 4:00:00 PM

Valid to:
4/26/2016 4:59:59 PM

Subject:
CN=Time Lapse Solutions, O=Time Lapse Solutions, L=St. James, S=St. James, C=BB

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
088D68E27F37630FE9E23AD19AC872B3

File PE Metadata
Compilation timestamp:
2/27/2015 8:18:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:oO4SJYln7YI4aHWadmIwOA15y8ulylsi5nNqGFzH2BfQUHtP9x55BET6w86nu:H4EY5Q/Iw11/rlsYNJFzWBfQy/5X6u

Entry address:
0x29B01E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9996

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.6 MB (2,724,352 bytes)

Service
Display name:
kXfqJB

Type:
Win32OwnProcess

Depends on:
Winmgmt CryptSvc


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-54-246-181-97.eu-west-1.compute.amazonaws.com  (54.246.181.97:80)

Remove kxfqjb.exe - Powered by Reason Core Security