occxvwbq.exe

The executable occxvwbq.exe has been detected as malware by 22 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘rlbwlfdl’. According to AVG, this software downloads additional adware offers during setup.
Description:
Explorer

Version:
1.0

MD5:
b88597faf039d979a2d70ea351a837f1

SHA-1:
3e6744296925c85a20c2a9d2b5650b0a637b1670

SHA-256:
572f712c2b812414b9a1e92b870fb634da9111fcdaf8a02a872345b1de7fa763

Scanner detections:
22 / 68

Status:
Malware

Analysis date:
4/19/2024 10:35:59 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1807218
889

Avira AntiVirus
TR/Crypt.ZPACK.68698
7.11.167.130

avast!
Win32:Malware-gen
2014.9-140829

AVG
Downloader.Generic13
2015.0.3354

Baidu Antivirus
Trojan.Win32.Kuluoz
4.0.3.14911

Bitdefender
Trojan.GenericKD.1807218
1.0.20.1205

Emsisoft Anti-Malware
Trojan.GenericKD.1807218
8.14.08.29.02

ESET NOD32
Win32/TrojanDownloader.Zortob
8.10263

F-Secure
Trojan.GenericKD.1807218
11.2014-29-08_6

G Data
Trojan.GenericKD.1807218
14.8.24

IKARUS anti.virus
Trojan-Downloader.Win32.Kuluoz
t3scan.1.7.5.0

Kaspersky
Trojan.Win32.Yakes
14.0.0.3332

Malwarebytes
Trojan.Yakes
v2014.09.11.01

McAfee
Artemis!B88597FAF039
5600.7023

Microsoft Security Essentials
TrojanDownloader:Win32/Kuluoz.D
1.10802

MicroWorld eScan
Trojan.GenericKD.1807218
15.0.0.723

NANO AntiVirus
Trojan.Win32.Yakes.decwsf
0.28.2.61861

Qihoo 360 Security
Win32/Trojan.fc1
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.11.13

Sophos
Troj/Agent-AIIK
4.98

Trend Micro House Call
Suspicious_GEN.F47V0814
7.2.241

Vba32 AntiVirus
suspected of Cryptor.CDP
3.12.26.3

File size:
154 KB (157,696 bytes)

Product version:
1.0

Copyright:
No rights reserved.

Original file name:
MINIPAD.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\occxvwbq.exe

File PE Metadata
Compilation timestamp:
8/14/2014 10:12:34 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.71

CTPH (ssdeep):
3072:UT8qYYRReIBRI3LOO4CmRQz+A91AKCv4u1AKCv4Vj:Y8wReIBa3LOOihceKCvPeKCvA

Entry address:
0x1878

Entry point:
55, 89, E5, 83, EC, 24, C7, 45, E0, 00, 00, 00, 00, C7, 45, E4, 00, 00, 00, 00, 6A, 00, FF, 15, 4C, 16, 40, 00, 6A, 00, FF, 15, 68, 16, 40, 00, 8B, 45, FC, 81, 3D, F6, 10, 40, 00, 67, C0, 11, 00, 0F, 84, 8E, 02, 00, 00, 81, 3D, F6, 10, 40, 00, A9, AB, 51, 00, 0F, 84, 5B, 01, 00, 00, 6A, 00, 6A, 00, 6A, 00, 6A, 25, 50, FF, 15, 30, 12, 40, 00, 6A, 00, 6A, 00, 6A, 01, FF, 75, EC, FF, 15, 4C, 12, 40, 00, 6A, 01, FF, 75, EC, FF, 15, 6C, 12, 40, 00, 6A, 01, FF, 75, EC, FF, 15, 38, 12, 40, 00, 6A, 00, FF, 15, 28...
 
[+]

Entropy:
7.0316

Code size:
142.5 KB (145,920 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
rlbwlfdl

Command:
"C:\users\{user}\appdata\local\occxvwbq.exe"


Remove occxvwbq.exe - Powered by Reason Core Security