patch.exe

Mozilla Firefox

The application patch.exe has been detected as a potentially unwanted program by 27 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘4800314570ddeb183dcddef511a2d44b’.
Publisher:
Mozilla Firefox

Product:
Mozilla Firefox

Version:
48.78.56.54

MD5:
5de90e935e7d629e5a5f54ccba8c0ef5

SHA-1:
26a1e687806a1644b5fdb0891757f1ffbfa3968c

SHA-256:
4f71afedfcc158ba36d636ed168170c5a4c49573413645677b0e4909c9ef3889

Scanner detections:
27 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 2:40:02 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.406335
830

Agnitum Outpost
Trojan.DR.FrauDrop
7.1.1

Avira AntiVirus
TR/Dropper.MSIL.44780
7.11.176.180

avast!
MSIL:GenMalicious-R [Trj]
2014.9-141027

AVG
MSIL3
2015.0.3308

Baidu Antivirus
Trojan.Win32.FrauDrop
4.0.3.141027

Bitdefender
Gen:Variant.Kazy.406335
1.0.20.1500

Comodo Security
UnclassifiedMalware
19714

Emsisoft Anti-Malware
Gen:Variant.Kazy.406335
8.14.10.27.04

Fortinet FortiGate
MSIL/Injector.BRY!tr
10/27/2014

F-Prot
W32/Fathom.3-based
v6.4.7.1.166

F-Secure
Gen:Variant.Kazy.406335
11.2014-27-10_2

G Data
Gen:Variant.Kazy.406335
14.10.24

IKARUS anti.virus
Trojan-Dropper.Win32.FrauDrop
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.183.13584

Kaspersky
Trojan-Dropper.Win32.FrauDrop
14.0.0.3036

McAfee
RDN/Generic Dropper!up
5600.6964

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi
1.11005

MicroWorld eScan
Gen:Variant.Kazy.406335
15.0.0.900

NANO AntiVirus
Trojan.Win32.FrauDrop.dasuuu
0.28.2.62440

Norman
Troj_Generic.UHNCA
11.20141027

Panda Antivirus
Generic Malware
14.10.27.04

Qihoo 360 Security
Win32/Trojan.Dropper.8db
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.06GA14
7.2.300

Vba32 AntiVirus
TrojanDropper.FrauDrop.aezfu
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
33698

File size:
175.5 KB (179,712 bytes)

Product version:
48.78.56.54

Copyright:
Copyright © 2014 Mozilla Firefox

Trademarks:
Mozilla Firefox

Original file name:
PatchV5.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\patch.exe

File PE Metadata
Compilation timestamp:
6/7/2014 2:34:50 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:/TFJw5IbDKRek1bmVC53gq/VpEgWFRPbSTC5IS7hP8X8jAPIPB576gfthHeAHov8:HDKRek1bmVg7dpEgWFNu4t7N8X8jUsBW

Entry address:
0x2ABD9

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 14, 26, 00, 80, 10, 00, 00, 00, 64, 26, 00, 80, 18, 00, 00, 00, 58, 2A, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 02, 00, 00, 00, 48, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
163 KB (166,912 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
4800314570ddeb183dcddef511a2d44b

Command:
"C:\users\{user}\appdata\local\temp\patch.exe"..


Remove patch.exe - Powered by Reason Core Security