microsoft toolkit.exe

The application microsoft toolkit.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from forces.loadingdom.ru.
MD5:
ce24dee852271fe78bf38952e6f2afe0

SHA-1:
ba0a59c82d97ff3fc3697c16907b3e7edf55b281

SHA-256:
54cbbd2db1ea614104d0b5eacc8d390bfb8e31f3b6fc375bfac5d7b2478e3685

Scanner detections:
18 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 5:41:19 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Strictor.58597
927

Avira AntiVirus
TR/Crypt.Xpack.84789
7.11.163.108

avast!
Win32:LoadMoney-FA [PUP]
140617-1

AVG
Win32/Heur
2014.0.3986

Bitdefender
Gen:Variant.Adware.Strictor.58597
1.0.20.1015

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.58597
8.14.07.22.06

ESET NOD32
Win32/AdWare.LoadMoney.NC application
7.0.302.0

F-Secure
Gen:Variant.Adware.Strictor.58597
11.2014-22-07_3

G Data
Gen:Variant.Adware.Strictor.58597
14.7.24

IKARUS anti.virus
PUA.LoadMoney
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.181.12806

Malwarebytes
PUP.Optional.LoadMoney
v2014.07.22.06

MicroWorld eScan
Gen:Variant.Adware.Strictor.58597
15.0.0.609

NANO AntiVirus
Trojan.Win32.LMN.dchzsg
0.28.2.60990

Rising Antivirus
PE:Trojan.Win32.Generic.1702F13E!386068798
23.00.65.14720

Sophos
Troj/LdMon-G
4.98

Vba32 AntiVirus
BScope.Downware.LMN
3.12.26.3

VIPRE Antivirus
Threat.4080917
31208

File size:
434.5 KB (444,928 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\microsoft toolkit.exe

File PE Metadata
Compilation timestamp:
7/16/2014 9:42:43 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
0.21

CTPH (ssdeep):
6144:DJpHssjyX/0SE6ThEp7VnES0Zz+o4rgX3Dq1w4MXBoYpatG5tG8oTtG0tGzToe3T:VJssoPE6TauESq8pjqoJC2

Entry address:
0x70FE

Entry point:
13, 1C, 24, F5, 1B, 44, 24, FC, C1, E3, 17, C1, CD, 1F, C1, E8, 16, C1, EB, 17, C1, C0, 15, F7, D1, 90, C1, E5, 14, 39, F5, C1, E1, 0E, C1, D6, 10, 90, C1, E0, 0B, C1, E2, 19, C1, C2, 14, C1, E7, 19, 01, DB, C1, FE, 0A, 23, 5C, 24, 0C, FC, FC, 1B, 05, 40, A9, 44, 00, C1, FE, 0A, 85, 2D, C4, CB, 44, 00, 81, C3, EF, E9, 51, 9D, 11, FF, 2B, 5C, 24, 04, C1, D2, 02, C1, E2, 04, 90, 4B, D1, CB, 42, 87, F6, C1, CD, 02, BF, C3, 22, 60, C6, C1, C3, 1C, 4D, 03, 4C, 24, 0C, 90, 21, D6, 39, D3, 81, D6, 55, 02, AD, B7...
 
[+]

Code size:
383 KB (392,192 bytes)

The file microsoft toolkit.exe has been seen being distributed by the following URL.

Remove microsoft toolkit.exe - Powered by Reason Core Security