MicroProProc.exe

NextProject

MicroNames Ltd.

The application MicroProProc.exe by MicroNames has been detected as a potentially unwanted program by 29 anti-malware scanners. It is also typically executed from an Internet Explorer cache folder.
Publisher:
.  (signed by MicroNames Ltd.)

Product:
NextProject

Version:
1.00

MD5:
f599496094203a36382f5a79e29b7095

SHA-1:
3e4f82c125f1eeab40cf0dfdfd6328d8eed2b51d

SHA-256:
a232c54dc8240c1662448839bed838b5b1d04a5819cac9c657de9dfa6bc1c35a

Scanner detections:
29 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 7:10:19 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.VB
7.1.1

AhnLab V3 Security
PUP/Win32.MicroLab
2013.10.10

Avira AntiVirus
TR/VB.Downloader.Gen
7.11.106.210

avast!
Win32:MicroLab-A [PUP]
2014.9-150802

AVG
Generic5
2016.0.3029

Bitdefender
Application.Generic.548409
1.0.20.1070

Comodo Security
Application.Win32.Downware.KG
17079

Dr.Web
Adware.Siggen.25981
9.0.1.0214

ESET NOD32
Win32/Adware.DownloadWare (variant)
9.8898

Fortinet FortiGate
Adware/VB
8/2/2015

F-Prot
W32/VB-Backdoor-HRS-based!Maxim
v6.4.7.1.166

F-Secure
Application.Generic.548409
11.2015-02-08_1

G Data
Application.Generic.548409
15.8.22

IKARUS anti.virus
AdWare.Win32.Hebogo
t3scan.2.0.127

K7 AntiVirus
Virus
13.173.9829

Kaspersky
not-a-virus:AdWare.Win32.VB
14.0.0.1642

Malwarebytes
Adware.KorAd
v2015.08.02.03

McAfee
Artemis!F59949609420
5600.6685

Microsoft Security Essentials
Adware:Win32/Hebogo
1.163.1557.0

MicroWorld eScan
Application.Generic.548409
16.0.0.642

NANO AntiVirus
Trojan.Win32.Siggen.brrrde
0.26.0.55366

Panda Antivirus
Trj/Genetic.gen
15.08.02.03

Reason Heuristics
PUP.MicroNames (M)
15.8.2.15

Rising Antivirus
Trojan.Win32.Generic.14AA5CD3
23.00.65.15731

Sophos
Mal/GamePSW-C
4.93

Trend Micro House Call
TROJ_GEN.R02KH0AI313
7.2.214

Trend Micro
TROJ_GEN.R0CBC0RFF13
10.465.02

Vba32 AntiVirus
TScope.Trojan.VB
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
22236

File size:
775.5 KB (794,072 bytes)

Product version:
1.00

Original file name:
MicroProProc.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\microproproc.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
11/28/2011 9:00:00 AM

Valid to:
12/28/2013 8:59:59 AM

Subject:
CN=MicroNames Ltd., OU=IT, O=MicroNames Ltd., L=Guro-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
71EADF6347D76C842389C834D3A58AEB

File PE Metadata
Compilation timestamp:
5/25/2013 8:50:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:heolunAz2zVnzDXMYkTBcdnAuRkqumDxUiAirMXu4fz2s96Ar6LukEkkWgKQ6o:heqz2zVnzD7kTBc1AQvFUifMJ6LuYkH

Entry address:
0x6B00

Entry point:
68, B0, 7C, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, BE, 7E, 65, AB, C1, A0, 1A, 44, 83, D8, EF, 19, FA, 31, D1, 05, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4E, 65, 78, 74, 50, 72, 6F, 6A, 65, 63, 74, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 04, F4, 78, 1E, 94, 3A, 8F, 5F, 43, A8, EF, 85, 61, A8, 41, CC, B1, D0, 63, 1D, 5C, B3, BC, 6A, 46, 8B, E4, 48, CD, 62, BF, 54, 0E, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
5.8401

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
756 KB (774,144 bytes)

Remove MicroProProc.exe - Powered by Reason Core Security