updateflashplayer_f03beb18.exe

Masnesaft Visual Studio 2010

Masnesaft Corporation

The application updateflashplayer_f03beb18.exe, “Masnesaft Visual Studie 2010” has been detected as a potentially unwanted program by 34 anti-malware scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. It is also typically executed from the user's temporary directory.
Publisher:
Masnesaft Corporation

Product:
Masnesaft® Visual Studio® 2010

Description:
Masnesaft Visual Studie 2010

Version:
1.9.43074.5121 built by: SP1Rel

MD5:
f59f472a780d4895251b8fb3303085a7

SHA-1:
63078a60148f9b4595dca122f98980dcf0a74184

SHA-256:
2752a1b4390e0f9b989b09ba535dd606ab150c40e29c073f5320eec861452c5f

Scanner detections:
34 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 3:50:57 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.409901
918

Agnitum Outpost
Trojan.Kryptik
7.1.1

AhnLab V3 Security
Trojan/Win32.Katusha
2014.08.01

Avira AntiVirus
TR/Crypt.Xpack.87109
7.11.164.214

avast!
Win32:Zbot-UGS [Trj]
2014.9-140731

AVG
Crypt3
2015.0.3396

Baidu Antivirus
Trojan.Win32.Katusha
4.0.3.14731

Bitdefender
Gen:Variant.Kazy.408868
1.0.20.1060

Bkav FE
HW32.CDB
1.3.0.4959

Clam AntiVirus
Win.Trojan.Agent-752429
0.98/21411

Comodo Security
TrojWare.Win32.Kryptik.CHIQ
19042

Dr.Web
Trojan.Siggen6.15132
9.0.1.0212

Emsisoft Anti-Malware
Trojan.GenericKD.1757275
8.14.07.31.02

ESET NOD32
Win32/Kryptik.CGTO (variant)
8.10186

Fortinet FortiGate
W32/Katusha.CGKA!tr
7/31/2014

F-Secure
Gen:Variant.Kazy.408868
11.2014-31-07_5

G Data
Gen:Variant.Kazy.408868
14.7.24

IKARUS anti.virus
Packed.Win32.Katusha
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.182.12911

Kaspersky
Packed.Win32.Katusha
14.0.0.3477

Malwarebytes
Spyware.Zbot.MSXGen
v2014.07.31.02

McAfee
PWSZbot-FBTA!E7746FE5637D
5600.7052

Microsoft Security Essentials
PWS:Win32/Zbot
1.10802

MicroWorld eScan
Gen:Variant.Kazy.408868
15.0.0.636

NANO AntiVirus
Trojan.Win32.Katusha.dchieb
0.28.2.61148

Panda Antivirus
Trj/Genetic.gen
14.07.31.02

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14729

Sophos
Troj/Zbot-HGR
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-FalComp
10368

Total Defense
Win32/Zbot.KfLBQP
37.0.11092

Trend Micro House Call
TSPY_ZBOT.SMRAP
7.2.212

Trend Micro
TSPY_ZBOT.SMRAP
10.465.31

VIPRE Antivirus
Trojan.Win32.Generic
31800

File size:
355.5 KB (364,065 bytes)

Product version:
1.9.43074.5121

Copyright:
© Masnesaft Corporation. All rights reserved.

Original file name:
devenv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\updateflashplayer_f03beb18.exe

File PE Metadata
Compilation timestamp:
1/29/2011 9:49:20 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:EwCfc4sNa6+uE/GW7DXXW4s9SKxI6OqJiOTNrE9MUotRvm:HC0b+uuVPXGTZeqJNrIMUilm

Entry address:
0xC588

Entry point:
55, 8B, EC, 81, EC, 8C, 01, 00, 00, EB, 4E, EB, 4C, 8B, C7, 89, 5D, A4, EB, 45, 03, D3, 89, 9D, 60, FF, FF, FF, EB, 3B, 03, DB, 8B, CA, EB, 35, B9, 00, 45, 05, A1, 03, CF, 3B, 8D, 7C, FE, FF, FF, 75, 26, 83, C1, FD, 8B, 35, 80, C0, 43, 00, 89, 8D, D8, FE, FF, FF, 89, 9D, D8, FE, FF, FF, 3B, 3D, 34, C0, 43, 00, 75, 09, 33, C1, 8B, FB, EB, 03, 89, 75, B4, 53, 8B, 1D, 68, C0, 43, 00, 89, 9D, AC, FE, FF, FF, 56, 83, F3, E7, 8B, F3, 89, B5, AC, FE, FF, FF, 57, 33, F3, 89, B5, AC, FE, FF, FF, 8B, B5, AC, FE, FF...
 
[+]

Entropy:
7.9393

Developed / compiled with:
Microsoft Visual C++

Code size:
153.5 KB (157,184 bytes)

Remove updateflashplayer_f03beb18.exe - Powered by Reason Core Security