shortcut.exe

Injekt LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The application shortcut.exe by Injekt has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Injekt LLC  (signed and verified)

MD5:
b2ff1225ebb6a710c84a1803e2946471

SHA-1:
71d4e9e88bab8d91d68cadae2aca017ec74a6b50

SHA-256:
6f16f6439c198aecad83363447951eb282219199de37ff8ce80d8264ea195cdd

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/25/2024 2:39:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt.I
14.9.19.12

File size:
221.8 KB (227,168 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\temp\{random}.tmp\sb\shortcut.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/22/2014 8:00:00 PM

Valid to:
6/22/2015 7:59:59 PM

Subject:
CN=Injekt LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Injekt LLC, L=Carlsbad, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
22388FB3C3238D36E8B8ABBBE3903F04

File PE Metadata
Compilation timestamp:
4/25/2014 1:38:45 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:HtQXKxTNw3CbhXpj/zIkM+MA5X5f0yBv5fMfxc3oc38c7s:NRxhd/0lU/Mxc4cMc7s

Entry address:
0xC9CA

Entry point:
E8, 04, 52, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 78, 34, 42, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 58, 22, 42, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 78, 34, 42, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00...
 
[+]

Entropy:
5.9476

Code size:
93.5 KB (95,744 bytes)

Remove shortcut.exe - Powered by Reason Core Security