p. fscapture 5.9 by yd.exe

The executable p. fscapture 5.9 by yd.exe has been detected as malware by 10 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler.
Remove p. fscapture 5.9 by yd.exe - Powered by Reason Core Security
MD5:
3628fec728184331e92f2b288c7b2959

SHA-1:
8380bf52b283fbd9fd705be5cfeedd5b59f9d052

SHA-256:
28b0dc88a1976f46e40cb743b508598e4ac01b64569334b63b0c7bec9c7ea244

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
12/4/2016 3:29:18 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/ADH.A.281
7.11.30.172

Antiy Labs AVL
Trojan[Backdoor]/Win32.IRCBot
1.0.0.1

Bkav FE
HW32.CDB
1.3.0.4959

Clam AntiVirus
Trojan.IRCBot-3683
0.98/19073

Commtouch SDK
W32/Trojan.HQSI-0977
5.4.1.7

F-Prot
W32/Trojan2.HDMJ
4.6.5.141

K7 AntiVirus
Trojan
13.1712358

K7 Gateway Antivirus
Trojan
13.1712358

Kingsoft AntiVirus
Win32.Malware.Generic.a.(kcloud)
331020.49267

nProtect
Trojan/W32.Agent.1814209
14.06.10.01

Remove p. fscapture 5.9 by yd.exe - Powered by Reason Core Security
File size:
1.7 MB (1,814,209 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/20/1992 2:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:BDHzLTZmGJeMYQWmh5jEinRAeplhSqApNEftPnvELCvBritE5iwO/Eqd75UYSYxD:BDHlNjEgtcqAHEfOGv8tE5S/EkjS28BY

Entry address:
0x1F26

Entry point:
9C, 60, 68, 53, 74, 41, 6C, 68, 54, 68, 49, 6E, E8, 00, 00, 00, 00, 58, BB, 37, 1F, 00, 00, 2B, C3, 50, 68, 00, 00, 40, 00, 68, 00, 2C, 00, 00, 68, 04, 01, 00, 00, E8, BA, FE, FF, FF, E9, 90, FF, FF, FF, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 83, C4, F4, FC, 53, 57, 56, 8B, 75, 08, 8B, 7D, 0C, C7, 45, FC, 08, 00, 00, 00, 33, DB, BA, 00, 00, 00, 80, 43, 33, C0, E8, 19, 01, 00, 00, 73, 0E, 8B, 4D, F8, E8, 27, 01, 00, 00, 02, 45, F7, AA, EB, E9, E8, 04, 01, 00, 00, 0F, 82, 96, 00, 00, 00, E8, F9, 00, 00, 00...
 
[+]

Entropy:
7.9181  (probably packed)

Code size:
7.5 KB (7,680 bytes)

Scheduled Task
Task name:
{A35A0777-3B62-4EB4-A97D-C78BF386DD16}

Trigger:
Registration (Runs on registration)


Remove p. fscapture 5.9 by yd.exe - Powered by Reason Core Security