umarddyl.exe

The application umarddyl.exe has been detected as a potentially unwanted program by 13 anti-malware scanners.
MD5:
a3802c2dc4b887295c9cf273520d006b

SHA-1:
682fd156b7e035f1f51c9746877fd089efb38e41

SHA-256:
9fcde221c3c9f0b18d343285a0b8c84567f7f654321619d2b51e03e2f9e57b1f

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 8:00:34 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.ZooZoo.1
-40

avast!
Win32:Adware-CPD [Adw]
2014.9-170316

AVG
Generic6
2018.0.2438

Baidu Antivirus
Adware.Win32.PennyBee
4.0.3.17316

Bitdefender
Gen:Variant.Adware.ZooZoo.1
1.0.20.375

Emsisoft Anti-Malware
Gen:Variant.Adware.ZooZoo
8.17.03.16.09

ESET NOD32
Win32/Adware.PennyBee (variant)
11.11559

Fortinet FortiGate
Riskware/PennyBee
3/16/2017

F-Secure
Gen:Variant.Adware.ZooZoo
11.2017-16-03_5

G Data
Gen:Variant.Adware.ZooZoo
17.3.25

MicroWorld eScan
Gen:Variant.Adware.ZooZoo.1
18.0.0.225

Qihoo 360 Security
Win32/Virus.Adware.b43
1.0.0.1015

VIPRE Antivirus
Trojan.Win32.Generic
39828

File size:
439.5 KB (450,048 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\websmartapp\1.1.0.30\umarddyl.exe

File PE Metadata
Compilation timestamp:
4/26/2015 11:10:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x3CF5F

Entry point:
E8, 4F, F0, 00, 00, E9, 89, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, AC, 97, 46, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, AC, 97, 46, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F...
 
[+]

Entropy:
6.3292

Code size:
355.5 KB (364,032 bytes)

Remove umarddyl.exe - Powered by Reason Core Security