updater_task.dll

The library updater_task.dll has been detected as malware by 23 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler named updater triggered daily at a specified time.
MD5:
bc91ffe3452406b97fd91a7eb13bcc2c

SHA-1:
6c84aa8d9808af4f999695f2990088eb5c82b846

SHA-256:
dfe52cc35240ea523750187034e32b27004b9d900847d294595757b792f12734

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
5/4/2024 6:45:55 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1643808
838

Avira AntiVirus
TR/Sefnit.CB.6
7.11.151.88

avast!
Win32:Sefnit-IM [Trj]
2014.9-141019

AVG
Generic36
2015.0.3316

Bitdefender
Trojan.GenericKD.1643808
1.0.20.1460

Emsisoft Anti-Malware
Trojan.GenericKD.1643808
8.14.10.19.10

Fortinet FortiGate
W32/Sefnit.FAY!tr
10/19/2014

F-Secure
Trojan.GenericKD.1643808
11.2014-19-10_1

G Data
Trojan.GenericKD.1643808
14.10.24

IKARUS anti.virus
Trojan.Win32.Sefnit
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.178.12184

Kaspersky
Backdoor.Win32.Mevade
14.0.0.3075

McAfee
Sefnit-FAY!BC91FFE34524
5600.6972

Microsoft Security Essentials
Trojan:Win32/Sefnit.CB
1.10600

MicroWorld eScan
Trojan.GenericKD.1643808
15.0.0.876

Norman
Suspicious_Gen4.GFPCM
11.20141019

nProtect
Trojan.GenericKD.1643808
14.05.23.01

Panda Antivirus
Trj/Genetic.gen
14.10.19.10

Sophos
Mal/Sefnit-E
4.98

Trend Micro House Call
TROJ_GEN.R0CBC0DDT14
7.2.292

Trend Micro
TROJ_GEN.R0CBC0DDT14
10.465.19

Vba32 AntiVirus
Backdoor.Mevade
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
29542

File size:
1.5 MB (1,573,888 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\roaming\updater\updater_task.dll

File PE Metadata
Compilation timestamp:
3/28/2014 1:08:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
49152:7KDpUet+mpH5ygVeryohwl0dGHp/vXJlxGb:ndmx5ygVMBhw3

Entry address:
0x1B10E

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 2B, 58, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 51, 51, 8D, 45, F8, 50, FF, 15, 68, 30, 11, 10, 8B, 45, F8, 8B, 4D, FC, 6A, 00, 05, 00, 80, C1, 2A, 68, 80, 96, 98, 00, 81, D1, 21, 4E, 62, FE, 51, 50, E8, 8F, 58, 00, 00, 83, FA, 07, 7C, 0E, 7F, 07, 3D, FF, 6F, 40, 93, 76, 05, 83, C8, FF, 8B, D0, 8B, 4D, 08, 85, C9, 74, 05, 89, 01, 89, 51, 04, C9, C3, 8B, FF, 55, 8B, EC, E8, FB, 23, 00, 00, 8B, 4D...
 
[+]

Code size:
1.1 MB (1,120,768 bytes)

Scheduled Task
Task name:
updater

Trigger:
Daily (Runs daily at 10:24)


Remove updater_task.dll - Powered by Reason Core Security