sndk&p.exe

The application sndk&p.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. This is a setup program which is used to install the application. This file is typically installed with the program Internet Download Manager by HostJSC. The file has been seen being downloaded from download2094.mediafire.com and multiple other hosts.
MD5:
3e9b7b76b154342811a8dcc2b507c1ce

SHA-1:
2828b9bd9e3d65e578b51b049a2bf5d4f2aef182

SHA-256:
16ff4927174e13d3bfa6da64956c8fb50a6087fba07b26234d0a4bfcdbaff729

Scanner detections:
21 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 11:55:37 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
HackTool.Keygen
7.1.1

AhnLab V3 Security
Trojan/Win32.Banbra
2013.12.26

Avira AntiVirus
SPR/Tool.Keygen.239
7.11.125.168

AVG
Crack
2014.0.3614

Comodo Security
ApplicUnsaf.Win32.HackTool.Keygen.~E
17630

F-Prot
W32/Backdoor2.HJND
v6.4.7.1.166

IKARUS anti.virus
possible-Threat.Keygen.IDM
t3scan.2.2.29

K7 AntiVirus
Backdoor
13.175.10881

Malwarebytes
Spyware.Password
v2013.12.25.04

McAfee
Generic PUP.z!fj
5600.7270

Microsoft Security Essentials
1.165.247.01

MicroWorld eScan
SPR/Tool.Keygen.239
14.0.0.1077

nProtect
Trojan-Spy/W32.Banker.289280.T
14.01.17.02

Quick Heal
(Suspicious) - DNAScan
12.13.12.00

Rising Antivirus
PE:Trojan.Win32.Generic.126EFF93!309264275
23.00.65.131223

Sophos
Generic PUA CI
4.96

SUPERAntiSpyware
Trojan.Agent/Gen-Keygen
10886

Trend Micro House Call
CRCK_SNDP
7.2.359

Trend Micro
CRCK_SNDP
10.465.25

VIPRE Antivirus
Trojan.Win32.Generic
25526

ViRobot
Trojan.Win32.A.ShipUp.289280
2011.4.7.4223

File size:
282.5 KB (289,280 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\new.pa.myegy.com\?????? ?????\?????? ??? ?????? ????\sndk&p.exe

File PE Metadata
Compilation timestamp:
10/27/2010 2:29:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
6144:VVDIykF3mQt0fZv9YC5fn+aCyIK3ccnMxj6YClOaH:VhedmUWY2W1K3DnsZCcO

Entry address:
0x1000

Entry point:
68, 01, 10, 46, 00, E8, 01, 00, 00, 00, C3, C3, 0A, A6, 98, E3, E3, BB, 44, A1, 03, 2A, 35, F5, E2, 10, E7, C3, 77, 44, 1F, F3, 8E, 40, 4D, DE, 0E, 79, 34, 50, 26, 28, 60, 7E, 77, 49, AD, 43, 9B, C8, B4, 63, 20, 81, 3A, C8, 83, BB, D9, 74, B4, 71, 85, FA, FA, E5, 55, 2C, B3, 3F, CC, EB, A8, 03, 84, 7F, 2C, CC, 05, 81, 9F, 5F, 52, F3, DB, BE, 1F, 35, ED, 10, 5E, BA, C8, 44, 31, 3D, 3B, 32, 97, 54, 1D, F3, 5A, 12, 27, C0, EB, B5, E4, 22, 65, 3F, 2C, F1, DE, A9, B7, 5C, 2A, 97, 1D, 70, CB, DC, AB, 0B, 5D, E2...
 
[+]

Entropy:
7.8101

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
13 KB (13,312 bytes)

The file sndk&p.exe has been discovered within the following program.

www.hostjsc.net
52% remove it
 
Powered by Should I Remove It?

The file sndk&p.exe has been seen being distributed by the following 2 URLs.

Remove sndk&p.exe - Powered by Reason Core Security