sharedreg.exe

Start Menu 8

IObit

The executable sharedreg.exe, “Start Menu 8 Setup ” has been detected as malware by 33 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from w060884.blob2.ge.tt and multiple other hosts.
Publisher:
IObit

Product:
Start Menu 8

Description:
Start Menu 8 Setup

Version:
1.0.0.0

MD5:
fc0e0947693d08324f0dc9e1577e7a00

SHA-1:
b1f47c533faec00644f94e7a2991bcc97a5b439b

SHA-256:
186213761b24f3a16e01ca0a558d1a3a835d2e19e03c0498d7e94c0dd53fa9b7

Scanner detections:
33 / 68

Status:
Malware

Analysis date:
4/19/2024 7:48:51 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.15680
1124

Agnitum Outpost
Backdoor.DarkKomet
7.1.1

AhnLab V3 Security
Backdoor/Win32.DarkKomet
2014.01.12

Avira AntiVirus
TR/Dropper.MSIL.Gen8
7.11.124.210

avast!
Win32:FakeAV-EMO [Trj]
2014.9-140106

AVG
MSIL
2015.0.3602

Baidu Antivirus
Backdoor.Win32.DarkKomet
4.0.3.1416

Bitdefender
Gen:Variant.Barys.15680
1.0.20.30

Bkav FE
W32.Clod639.Trojan
1.3.0.4613

Comodo Security
UnclassifiedMalware
17501

Dr.Web
BackDoor.Comet.152
9.0.1.06

Emsisoft Anti-Malware
Gen:Variant.Barys.15680
8.14.01.06.07

ESET NOD32
MSIL/Injector.BFZ (variant)
8.9279

Fortinet FortiGate
W32/DarkKomet.AIPF!tr.bdr
1/6/2014

F-Secure
Gen:Variant.Barys.15680
11.2014-06-01_2

G Data
Gen:Variant.Barys.15680
14.1.22

IKARUS anti.virus
Trojan.Msil
t3scan.2.2.29

K7 AntiVirus
Riskware
13.175.10814

Kaspersky
Backdoor.Win32.DarkKomet
14.0.0.4506

Malwarebytes
Trojan.FakeIO
v2014.01.06.07

McAfee
RDN/Generic BackDoor!vc
5600.7258

Microsoft Security Essentials
Backdoor:Win32/Fynloski.A
1.165.247.01

MicroWorld eScan
Gen:Variant.Barys.15680
15.0.0.18

NANO AntiVirus
Trojan.Win32.DarkKomet.cjefzo
0.28.0.57029

Norman
Troj_Generic.KYYIZ
11.20140106

Panda Antivirus
Generic Malware
14.01.06.07

Quick Heal
Backdoor.Fynloski
1.14.12.00

Sophos
Mal/Generic-S
4.96

Trend Micro House Call
TROJ_SPNR.03FC13
7.2.6

Trend Micro
TROJ_SPNR.03FC13
10.465.06

Vba32 AntiVirus
Backdoor.DarkKomet
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
25348

ViRobot
Backdoor.Win32.A.DarkKomet.518656.B
2011.4.7.4223

File size:
506.5 KB (518,656 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2012-2013

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\sharedreg.exe

File PE Metadata
Compilation timestamp:
4/5/2013 12:38:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:puwkjZkohdFZmqUNS6Svhwwh0WYumIXi53R3:ejThdpB6S2wOWeM2

Entry address:
0xABBB

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00, 05, 00, 03, 00, 00, 00, 38, 00, 00, 80, 0B, 00, 00, 00, 98, 00, 00, 80, 0E, 00, 00, 00, B0, 00, 00, 80, 10, 00, 00, 00, D0, 00, 00, 80, 18, 00, 00, 00, E8, 00, 00, 80, 00, 00, 00...
 
[+]

Entropy:
7.9181

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
35 KB (35,840 bytes)

The file sharedreg.exe has been seen being distributed by the following 3 URLs.

Remove sharedreg.exe - Powered by Reason Core Security