ujmsfr52.yyq.exe

TODO:

TODO: <Company name>

The application ujmsfr52.yyq.exe has been detected as a potentially unwanted program by 9 anti-malware scanners.
Publisher:
TODO:

Product:
TODO: <Product name>

Version:
1.0.0.5

MD5:
2e185c6edca3bae181711016f99a756b

SHA-1:
772641ec6ef2ad50aa118befc2fdbfc471f585ba

SHA-256:
4f3f710727628dcdfd199d84b4138ac89871d439a5f866daec3382cfead8d756

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 9:27:14 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.Xpack.101850
7.11.180.204

AVG
Generic5
2015.0.3312

Baidu Antivirus
Adware.Win32.Cossder
4.0.3.141024

ESET NOD32
Win32/AdWare.MultiPlug.CZ (variant)
8.10606

IKARUS anti.virus
Trojan.Crypt.XPACK
t3scan.1.7.8.0

Kaspersky
not-a-virus:HEUR:WebToolbar.Win32.Cossder
14.0.0.3055

Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
1.0.0.1015

Sophos
Generic PUA HH
4.98

Vba32 AntiVirus
Malware-Cryptor.General.3
3.12.26.3

File size:
236.5 KB (242,176 bytes)

Product version:
1.0.0.5

Copyright:
Copyright (C) 2012-18

Original file name:
wegegiowgaf0976.exe

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\users\{user}\appdata\local\temp\ujmsfr52.yyq.exe

File PE Metadata
Compilation timestamp:
10/20/2014 9:01:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:1oINNaYoC9lbMSFQnWiV1AsUPs/04kyscxq2RPgDAY/xgH0njXAf4UXPrGYZO2Ur:fNNai9l4SFQWiM9Ob0ZRiC0Hfftt9i5

Entry address:
0x14F3

Entry point:
55, 8B, EC, 81, EC, 7C, 02, 00, 00, A1, 00, 30, 40, 00, 33, C5, 89, 45, FC, 53, 33, DB, 56, 57, C7, 85, 08, FF, FF, FF, F4, 15, 93, B0, C7, 85, 0C, FF, FF, FF, 99, DC, 99, 01, C7, 85, 10, FF, FF, FF, CE, 72, 15, A2, C7, 85, 14, FF, FF, FF, 16, D9, 51, A8, C7, 85, 18, FF, FF, FF, 10, 8C, 80, FF, C7, 85, 1C, FF, FF, FF, 76, B8, F3, C1, C7, 85, 20, FF, FF, FF, B0, 06, 6A, 90, C7, 85, 24, FF, FF, FF, CC, 97, 10, 25, C7, 85, 28, FF, FF, FF, E1, 62, AF, 80, C7, 85, 2C, FF, FF, FF, A4, 1A, 86, D0, C7, 85, 30, FF...
 
[+]

Entropy:
5.7053

Developed / compiled with:
Microsoft Visual C++

Code size:
123 KB (125,952 bytes)

Remove ujmsfr52.yyq.exe - Powered by Reason Core Security