notepadruntime.exe

QUANTO SOLUCOES E SISTEMA LTDA

The executable notepadruntime.exe has been detected as malware by 15 anti-virus scanners.
Publisher:
QUANTO SOLUCOES E SISTEMA LTDA  (signed and verified)

MD5:
51c132f17e76ce8624c7ca51def63e86

SHA-1:
2db709289e31865718f1dc54dc2a343e3ce07572

SHA-256:
90fa21931c6fd20de8b27f5067781975cb70b69e738e747a9200cee0944db664

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
4/18/2024 11:20:48 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.383414
-31

Arcabit
Trojan.Kazy.D5D9B6
1.0.0.774

avast!
Win32:Banker-KYB [Trj]
2014.9-170307

AVG
Win32/Blacked
2018.0.2447

Bitdefender
Gen:Variant.Kazy.383414
1.0.20.330

Bkav FE
HW32.Packed
1.3.0.8383

Emsisoft Anti-Malware
Gen:Variant.Kazy.383414
8.17.03.07.05

F-Secure
Gen:Variant.Kazy.383414
11.2017-07-03_3

G Data
Gen:Variant.Kazy.383414
17.3.25

McAfee
Artemis!51C132F17E76
5600.6103

Microsoft Security Essentials
TrojanSpy:Win32/Banker.XE
1.1.13103.0

MicroWorld eScan
Gen:Variant.Kazy.383414
18.0.0.198

Qihoo 360 Security
Win32/Trojan.41e
1.0.0.1120

Rising Antivirus
Malware.Generic!fYlPf7UAf3L@5 (thunder)
23.00.65.17305

VIPRE Antivirus
Trojan.Win32.Packer.EnigmaProtector1.1X-1.3X
52812

File size:
1.3 MB (1,387,360 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\22052014\notepadruntime.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/2/2014 9:00:00 PM

Valid to:
4/3/2015 8:59:59 PM

Subject:
CN=QUANTO SOLUCOES E SISTEMA LTDA, O=QUANTO SOLUCOES E SISTEMA LTDA, L=PRESIDENTE PRUDENTE, S=SAO PAULO, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
00B87EDE3281FFB1EE77DF86B54A8CB0

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x527A

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, AE, A5, 41, 00, 55, DC, 7B, 04, 4B, 5A, 6A, CB, 98, 10, 5A, DF, DE, A1, 25, E3, 80, 0D, 09, 5A, 5F, F4, 26, A3, 14, 38, F3, F1, 06, 5B, 72, 59, 46, 65, 20, 91, 9B, 4A, D6, 67, 10, 45, 4B, 79, 37, 67, 02, 67, 5B, 09, 19, B2, 9C, D0, 44, 2F, E5, B7, 6B, 28, 2E, 4E, 99, 96, 46, F2, 19, 6B, BA, A8, 34, 07, 8E, ED, D4, E4, 96, EC, B0, 40, FE, 35, FF, 1A, 22, 02, 32, DE, EF, F6, 8A, 96, 3D, BE, 6A, AE, 01, 5E, 4A, 3B...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
599 KB (613,376 bytes)

Remove notepadruntime.exe - Powered by Reason Core Security