microsoft toolkit.exe

Asper

C Vital

The application microsoft toolkit.exe has been detected as a potentially unwanted program by 32 anti-malware scanners. The file has been seen being downloaded from files-download-71.com.
Publisher:
C Vital

Product:
Asper

Description:
LeaveLoadLoud

Version:
4, 10, 30, 0

MD5:
baaa7a3d620809e570e4cd80890cf0e0

SHA-1:
82bb179cfe93b3ab07c59e1284e791e58a38a358

SHA-256:
7a7e5bf5c2f5bd06e0d27ec3b64cba394d98af15a2b62819e2dc7b5fffb10e31

Scanner detections:
32 / 68

Status:
Potentially unwanted

Analysis date:
5/10/2024 11:55:29 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.13044758
6341897

Agnitum Outpost
PUA.4Shared
7.1.1

AhnLab V3 Security
PUP/Win32.Downloader
2015.02.19

Avira AntiVirus
APPL/Downloader.Gen4
7.11.202.28

avast!
Win32:PUP-gen [PUP]
150319-1

AVG
Generic
2016.0.3153

Baidu Antivirus
Adware.Win32.4Shared
4.0.3.1541

Bitdefender
Trojan.Generic.13044758
1.0.20.430

Clam AntiVirus
Win.Trojan.Symmi-987
0.98/20249

Comodo Security
Application.Win32.4shared.GSP
20900

Dr.Web
Trojan.DownLoader12.49702
9.0.1.086

Emsisoft Anti-Malware
Trojan.Generic.13044758
9.0.0.4799

ESET NOD32
Win32/4Shared.AL potentially unwanted (variant)
9.11388

Fortinet FortiGate
W32/Badur.AGGOH!tr
3/27/2015

F-Prot
W32/S-367fc245
v6.4.7.1.166

F-Secure
Trojan.Generic.13044758
5.13.68

G Data
Trojan.Generic.13044758
15.3.25

IKARUS anti.virus
PUA.4Shared
t3scan.1.8.6.0

K7 AntiVirus
Adware
13.202.15407

Kaspersky
Trojan.Win32.Badur
15.0.0.543

McAfee
4shared
5600.6813

MicroWorld eScan
Trojan.Generic.13044758
16.0.0.258

NANO AntiVirus
Riskware.Win32.Downware.dpmgxv
0.30.8.659

nProtect
Trojan.Generic.13044758
15.03.27.01

Panda Antivirus
Trj/Genetic.gen
15.03.27.06

Qihoo 360 Security
Malware.QVM07.Gen
1.0.0.1015

Reason Heuristics
Adware.Maxiget.CVital.Meta
15.4.24.0

Sophos
Downloader
4.98

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4150696
38552

Zillya! Antivirus
Backdoor.CPEX.Win32.30311
2.0.0.2076

File size:
115.4 KB (118,156 bytes)

Product version:
4, 10, 30, 0

Copyright:
Conical (c)

Trademarks:
TM2-15

Original file name:
lltmoping.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\microsoft toolkit.exe

File PE Metadata
Compilation timestamp:
3/24/2015 5:57:58 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:WdSsBR1aUeveIMwQaCkqXkbsJPJcwA5F+hOcIUNgx:WX3aUqhiksJPJvA5F+hOcITx

Entry address:
0x5C22

Entry point:
E8, 24, 26, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 48, E6, 40, 00, E8, 9C, 0F, 00, 00, 6A, 0E, E8, 9E, 04, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, B8, 51, 9D, 01, BA, B4, 51, 9D, 01, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, EF, FC, FF, FF, 59, FF, 76, 04, E8, E6, FC, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 8B, 0F, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, 69, 03, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 5D...
 
[+]

Entropy:
4.9670

Code size:
42 KB (43,008 bytes)

The file microsoft toolkit.exe has been seen being distributed by the following URL.

Remove microsoft toolkit.exe - Powered by Reason Core Security