lksowgnzpmd.exe

Zombie Alert

Creative Island Media, LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The application lksowgnzpmd.exe by Creative Island Media has been detected as adware by 7 anti-malware scanners. According to AVG, this software downloads additional adware offers during setup.
Publisher:
Creative Island Media, LLC  (signed and verified)

Product:
Zombie Alert

Description:
ZombieAlert

Version:
1.0.0.0

MD5:
440b2d568e0532712a9cf93c4edd9f8c

SHA-1:
eaf250e483a546dd519e6179484387d765f4c54c

SHA-256:
61430370ddaf07457489696562d90427a0648a5cf297156075db39cb9e749535

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/27/2024 2:44:20 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Potentially harmful program Downloader.BSH
2014.0.4040

ESET NOD32
probably MSIL/Adware.PullUpdate.E application
7.0.302.0

IKARUS anti.virus
PUA.Downloader
t3scan.1.7.8.0

Malwarebytes
PUP.Optional.ZombieAlert.A
v2014.10.22.01

Reason Heuristics
PUP.CreativeIslandMedia.L
14.10.22.1

Sophos
Search Donkey
4.98

VIPRE Antivirus
Threat.4784449
33706

File size:
48.9 KB (50,040 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Creative Island Media, LLC 2014

Original file name:
ZombieAlert.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\application data\fdcdqtshocz\dat\lksowgnzpmd.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/24/2014 11:00:00 AM

Valid to:
6/24/2015 9:59:59 AM

Subject:
CN="Creative Island Media, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Creative Island Media, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0ED42A15C608C5CB28B1EF56CE392E5E

File PE Metadata
Compilation timestamp:
10/2/2014 11:53:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:+f/R/66bDIK5xI3uyeh0XSBFKe5sLhwIDDdfQDNK0dC/S3FuoSg:IzHYk0iBFf4lDuw0ISVuQ

Entry address:
0xBF5E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6457

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
40 KB (40,960 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-50-112-218-190.us-west-2.compute.amazonaws.com  (50.112.218.190:80)

Remove lksowgnzpmd.exe - Powered by Reason Core Security