neocodec.exe

The executable neocodec.exe has been detected as malware by 13 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
MD5:
715c32d520f2c82f3a808e2757bcce66

SHA-1:
34d9b17bfa8ce16ecaca3d2ea0f2b54801aceabb

SHA-256:
a1fcdb66d2e572ec1e3897c124c9704b84ebb017d36286b1ba0cddc23a0ded5a

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/25/2024 7:03:39 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Rogue.KD.696613
7.11.121.182

avast!
Win32:Trojan-gen
2014.9-140423

Bkav FE
W32.Clodda8.Trojan
1.3.0.4613

Comodo Security
TrojWare.Win32.UMal.~A
17490

IKARUS anti.virus
Win32.Trojan
t3scan.2.2.29

K7 AntiVirus
Riskware
13.174.10609

McAfee
Artemis!715C32D520F2
5600.7151

MicroWorld eScan
Trojan.Generic.KD.696613
15.0.0.339

Norman
Troj_Generic.DNAJZ
11.20140423

Panda Antivirus
Generic Malware
14.04.23.10

Rising Antivirus
PE:Trojan.Win32.Generic.12F22FE0!317861856
23.00.65.14421

VIPRE Antivirus
Trojan.Win32.Generic
24692

ViRobot
Backdoor.Win32.A.Ceckno.1297920
2011.4.7.4223

File size:
1.2 MB (1,297,920 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\neocodec\neocodec.exe

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:QaIWubs9Uiz7gnGrKsDB9tloB3XPFK/zHQbmZSH/mEuvl:Q34Uq/Kez2GzwaIhuv

Entry address:
0x10FE30

Entry point:
55, 8B, EC, 83, C4, E8, 53, 33, C0, 89, 45, EC, 89, 45, E8, B8, F0, F7, 50, 00, E8, BF, 6C, EF, FF, 33, C0, 55, 68, E4, FE, 50, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, A1, D8, 8A, 51, 00, 8B, 00, E8, 1E, C7, FB, FF, 8B, 45, E8, 8D, 55, EC, E8, FB, BC, EF, FF, 8B, 45, EC, E8, 5F, 4E, EF, FF, 50, 6A, FF, 6A, 00, E8, 39, 6F, EF, FF, 8B, D8, E8, AA, 70, EF, FF, 3D, B7, 00, 00, 00, 75, 08, 53, E8, 55, 72, EF, FF, EB, 30, A1, D8, 8A, 51, 00, 8B, 00, E8, 37, C0, FB, FF, 8B, 0D, A0, 84, 51, 00, A1, D8, 8A, 51, 00...
 
[+]

Entropy:
6.6202

Developed / compiled with:
Microsoft Visual C++

Code size:
1.1 MB (1,110,016 bytes)

Scheduled Task
Task name:
neocodec.exe

Trigger:
Logon (Runs on logon)


Remove neocodec.exe - Powered by Reason Core Security