oiukjjlh.exe

Zemi Interactive Co., Ltd.

The executable oiukjjlh.exe has been detected as malware by 27 anti-virus scanners.
Publisher:
Zemi Interactive Co., Ltd.  (signed and verified)

MD5:
aaee989b391dea8163ce5a0d6f55b317

SHA-1:
67a71b471908c6881b09d6da4b5f7f5419145b43

SHA-256:
4e6b30db935e41231a108cba1c5d4cacde03cf262e9e85d24387950ae5a369c6

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/25/2024 4:54:56 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.15322472
212

AhnLab V3 Security
Malware/Win32.Generic
2016.04.21

Avira AntiVirus
TR/Agent.132048
8.3.3.4

Arcabit
Trojan.Generic.DE9CD68
1.0.0.672

AVG
Agent5
2017.0.2690

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.1677

Bitdefender
Trojan.Generic.15322472
1.0.20.945

Emsisoft Anti-Malware
Trojan.Generic.15322472
8.16.07.07.08

ESET NOD32
Win32/Agent.XLX (variant)
10.13365

Fortinet FortiGate
W32/Agent.XLX!tr
7/7/2016

F-Secure
Trojan.Generic.15322472
11.2016-07-07_5

G Data
Trojan.Generic.15322472
16.7.25

IKARUS anti.virus
Trojan.Win32.Agent
t3scan.2.0.9.0

K7 AntiVirus
Trojan
13.222.19366

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-57

McAfee
Artemis!AAEE989B391D
5600.6346

Microsoft Security Essentials
Trojan:Win32/Knokunocci.A
1.1.12603.0

MicroWorld eScan
Trojan.Generic.15322472
17.0.0.567

NANO AntiVirus
Trojan.Win32.Agent.dxvixs
1.0.30.8000

nProtect
Trojan.Generic.15322472
16.04.20.01

Panda Antivirus
Trj/Genetic.gen
16.07.07.08

Quick Heal
Trojan.Knokunocci.r5
7.16.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R028C0DJB15
10.465.07

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
48774

ViRobot
Trojan.Win32.Z.Agent.132048[h]
2014.3.20.0

File size:
129 KB (132,048 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\oiukjjlh.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/9/2013 8:00:00 AM

Valid to:
8/9/2014 7:59:59 AM

Subject:
CN="Zemi Interactive Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Zemi Interactive Co., Ltd.", L=SeoChoGu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4505E9AC8D288D763A1088ED1E2C8A60

File PE Metadata
Compilation timestamp:
9/18/2015 9:51:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:F4hPPTyE5VdiFqwx7G4UZpYie1Xz54YNWkBM+C+5Ok4bdpKH:cdiFqwA4e+BUoqyOk45p

Entry address:
0x3719

Entry point:
E8, 6A, 3D, 00, 00, E9, 89, FE, FF, FF, C7, 01, D8, D1, 40, 00, E9, B2, 3E, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, D8, D1, 40, 00, E8, 9F, 3E, 00, 00, F6, 45, 08, 01, 74, 07, 56, E8, 37, FD, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, AD, 3E, 00, 00, C7, 06, D8, D1, 40, 00, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 56, 3F, 00, 00, 59, 85, C0, 74, 0F, FF, 75, 08, E8, A6, 3E, 00, 00, 59, 85, C0, 74, E6, C9, C3, F6...
 
[+]

Entropy:
5.6901

Code size:
44.5 KB (45,568 bytes)

Remove oiukjjlh.exe - Powered by Reason Core Security