pps-qq-19.exe

The executable pps-qq-19.exe has been detected as malware by 14 anti-virus scanners.
MD5:
54738bc3554a2929b23e9c0fa7272f8c

SHA-1:
b12fcaf22d51728fa2fe1e8655deee24ead3c957

SHA-256:
e94bb7e300203266b5f1d691aa4f3c396d48bd76044a800aeaf11b9dd29d8fa8

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
4/25/2024 12:03:46 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.58657
5696344

Arcabit
Trojan.Kazy.DBD135
1.0.0.624

avast!
Win32:Malware-gen
151004-0

AVG
Win32/Heur
2015.0.4460

Bitdefender
Gen:Variant.Kazy.774453
1.0.20.1655

Bkav FE
HW32.Packed
1.3.0.7383

Emsisoft Anti-Malware
Gen:Variant.Kazy.774453
8.15.11.27.05

ESET NOD32
Win32/Kryptik.EGFS trojan
7.0.302.0

F-Secure
Gen:Variant.Symmi.58657
5.15.21

G Data
Gen:Variant.Symmi.58657
15.11.25

Microsoft Security Essentials
Threat.Undefined
1.211.1032.0

MicroWorld eScan
Gen:Variant.Symmi.58657
16.0.0.993

Norman
Gen:Variant.Kazy.774453
07.10.2015 03:16:12

Qihoo 360 Security
QVM20.1.Malware.Gen
1.0.0.1077

File size:
1.4 MB (1,466,368 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\pps-qq-19.exe

File PE Metadata
Compilation timestamp:
6/30/2012 3:21:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:jUt3s5emdZFdMkRrGN4R+Qpa1GzW/WfTgdnGHT4yRacJo29viBq6N1:gt3Wem7IkUYRpawqWfcwHTDa2KZN

Entry address:
0xF15A

Entry point:
83, EC, 04, 89, 2C, 24, 89, E5, 83, EC, 60, EB, 01, C3, 8D, 35, FF, 7F, 15, 01, 46, 56, FF, 15, B0, 10, 00, 01, 83, F8, 00, 74, 01, C3, 66, 81, FC, 00, FC, 0F, 82, 05, FF, FF, FF, 8D, 1D, FF, 7F, 15, 01, 43, 6A, 00, 6A, 00, 53, C6, 03, 79, 8D, 05, 33, E0, 15, 01, 40, 50, 8D, 05, B8, 10, 00, 01, FF, 10, 8A, 3D, 25, 81, 15, 01, 8D, 05, BC, 10, 00, 01, FF, 10, 85, C0, 0F, 85, D0, FE, FF, FF, 8D, 05, 33, E0, 15, 01, 40, 50, 8D, 05, B8, 10, 00, 01, FF, 10, 8D, 15, FF, 7F, 15, 01, 42, C6, 02, 64, 6A, 00, 6A, 00...
 
[+]

Entropy:
7.7502  (probably packed)

Code size:
1.3 MB (1,404,928 bytes)

Remove pps-qq-19.exe - Powered by Reason Core Security