patch.exe

The executable patch.exe has been detected as malware by 28 anti-virus scanners.
MD5:
c86536e87ade0f528b30b69df9978437

SHA-1:
9bef94001b9614f660e25c026991a51bf950d5c2

SHA-256:
55c270ecad3acad6cc3d2161bb0259d59582c83bf838df8bc5c7c56100823b50

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/26/2024 5:09:08 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.12723
889

Agnitum Outpost
HackTool.Patcher
7.1.1

Avira AntiVirus
TR/Agent.117248.47
7.11.152.200

avast!
Win32:Trojan-gen
2014.9-140829

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.14829

Bitdefender
Gen:Variant.Strictor.12723
1.0.20.1205

Comodo Security
UnclassifiedMalware
18418

Emsisoft Anti-Malware
Gen:Variant.Strictor.12723
8.14.08.29.02

ESET NOD32
Win32/HackTool.Patcher (variant)
8.9885

Fortinet FortiGate
W32/QPatch.A!tr
8/29/2014

F-Prot
W32/Trojan2.NBAX
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.12723
11.2014-29-08_6

G Data
Gen:Variant.Strictor.12723
14.8.24

IKARUS anti.virus
Win32.Trojan
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.178.12278

Malwarebytes
PUP.Hacktool.Patcher
v2014.08.29.02

McAfee
Artemis!C86536E87ADE
5600.7023

MicroWorld eScan
Gen:Variant.Strictor.12723
15.0.0.723

Norman
keygen.X
11.20140829

Panda Antivirus
Trj/CI.A
14.08.29.02

Qihoo 360 Security
Win32/Trojan.d76
1.0.0.1015

Quick Heal
HackTool.Patcher.A
8.14.14.00

Sophos
Troj/QPatch-A
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-HackPatch
10392

Total Defense
Win32/Fosniw.ZAAB
37.0.10976

Trend Micro House Call
TROJ_GEN.R0CBC0FIT13
7.2.241

Trend Micro
TROJ_GEN.R0CBC0FIT13
10.465.29

VIPRE Antivirus
Trojan.Win32.Generic
29888

File size:
114.5 KB (117,248 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\tipard studio\tipard iphone transfer platinum\patch.exe

File PE Metadata
Compilation timestamp:
9/27/2008 6:06:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
3072:U4Td4IK0caGRSXOWzjD9vdvCCSnxHVTXi:Um4Z05LjD9v87x1T

Entry address:
0x78CB0

Entry point:
60, BE, 00, 00, 46, 00, 8D, BE, 00, 10, FA, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.7444

Packer / compiler:
UPX 2.90LZMA

Code size:
100 KB (102,400 bytes)

Remove patch.exe - Powered by Reason Core Security