qiqoy.exe

Marsukife Visatl 2010

The executable qiqoy.exe has been detected as malware by 24 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
Product:
Marsukife® Visatl 2010

Version:
13.8.55766.65327

MD5:
d60db242f1d552f2987771fff9f8460c

SHA-1:
39ed316ea205447a7c5e07a3bc7105cc648ab8c3

SHA-256:
158d5c09386d8ceb3415037decbdd7e9aabcf9dbf4ea01819fc1183f901634b5

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/20/2024 2:34:57 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12008271
835

AhnLab V3 Security
Trojan/Win32.Agent
2014.10.23

Avira AntiVirus
TR/Crypt.ZPACK.Gen2
7.11.180.154

avast!
Win32:Malware-gen
141003-0

AVG
Win32/Cryptor
2014.0.4040

Baidu Antivirus
Trojan.Win32.Kryptik
4.0.3.14112

Bitdefender
Trojan.Generic.12008271
1.0.20.1475

Bkav FE
HW32.Packed
1.3.0.4959

Emsisoft Anti-Malware
Trojan.Generic.12008271
8.14.10.22.03

ESET NOD32
Win32/Kryptik.COAW (variant)
8.10604

Fortinet FortiGate
W32/Kryptik.CJJL!tr
10/22/2014

F-Secure
Trojan.Generic.12008271
11.2014-22-10_4

G Data
Trojan.Generic.12008271
14.10.24

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3062

Malwarebytes
Trojan.FakeMS
v2014.10.22.03

McAfee
PWSZbot-FADO!D60DB242F1D5
5600.6969

MicroWorld eScan
Trojan.Generic.12008271
15.0.0.885

Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
1.0.0.1015

Quick Heal
FraudTool.Security
10.14.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.2.11

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141020

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R08NC0PJM14
7.2.306

Trend Micro
TROJ_GEN.R08NC0PJM14
10.465.02

File size:
280.1 KB (286,791 bytes)

Product version:
13.8.55766.65327

Original file name:
desinko.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\ykisboc\qiqoy.exe

File PE Metadata
Compilation timestamp:
6/26/2012 4:04:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:AQ/pKeJT+BbJA6OlOKjh/wgxgoitOGi7WDoj1M1s:7/pKGT6A6OlVNxgqG0NZ8s

Entry address:
0xCD14

Entry point:
55, 8B, EC, 81, EC, B4, 01, 00, 00, B8, F9, 7C, 00, 00, EB, 11, BB, 9D, 00, 00, 00, 81, F3, 00, 22, 42, 10, 89, 9D, 6C, FE, FF, FF, 53, 83, EB, D2, BA, DD, B1, 00, 00, EB, 06, 89, 9D, EC, FE, FF, FF, 56, B8, E8, 00, 00, 00, 89, 85, E8, FE, FF, FF, 57, 8B, 9D, E8, FE, FF, FF, 83, C3, C4, 83, FB, B5, 0F, 85, C9, 00, 00, 00, B9, 9D, C7, 00, 00, 83, C3, C0, 89, 8D, E8, FE, FF, FF, E9, B6, 00, 00, 00, 83, F6, A4, 3B, B5, A4, FE, FF, FF, 0F, 84, A7, 00, 00, 00, 33, F3, BA, A8, 00, 00, 00, 89, 45, D8, 89, 55, D8...
 
[+]

Entropy:
7.9245

Developed / compiled with:
Microsoft Visual C++

Code size:
94.5 KB (96,768 bytes)

Scheduled Task
Task name:
Security Center Update - 2152276243

Trigger:
Daily (Runs daily at 3:00 PM)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove qiqoy.exe - Powered by Reason Core Security