updatewinexpand.exe

WinExpandSetup_newmgoon

CJMooter

The application updatewinexpand.exe has been detected as a potentially unwanted program by 24 anti-malware scanners.
Publisher:
CJMooter

Product:
WinExpandSetup_newmgoon

Version:
1.0.0.1

MD5:
869fce44b4705695e8d21995ddc5ae9e

SHA-1:
2bc08b777b8b794190b3837f6960d67ac5084bb4

SHA-256:
429269a16a5e8d350f3bffd02dd3d9ef05d7fdb26e28a3b029d1594a20f3b21e

Scanner detections:
24 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 6:34:20 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKDV.1361134
1017

AhnLab V3 Security
PUP/Win32.Winexpand
14.04.24

Avira AntiVirus
SPR/Tool.537088.10
7.11.144.8

avast!
Win32:Adware-gen [Adw]
2014.9-140424

AVG
Generic5
2015.0.3495

Baidu Antivirus
Adware.Win32.Kraddare
4.0.3.14424

Bitdefender
Trojan.GenericKDV.1361134
1.0.20.570

Bkav FE
W32.Clod230.Trojan
1.3.0.4959

Comodo Security
ApplicUnwnt
18115

Emsisoft Anti-Malware
Trojan.GenericKDV.1361134
8.14.04.24.03

ESET NOD32
Win32/Adware.Kraddare.HA (variant)
8.9690

F-Secure
Trojan.GenericKDV.1361134
11.2014-24-04_5

G Data
Trojan.GenericKDV.1361134
14.4.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.6.1.0

Malwarebytes
Adware.Korad
v2014.04.24.03

McAfee
RDN/Generic PUP.x!bcf
5600.7151

MicroWorld eScan
Trojan.GenericKDV.1361134
15.0.0.342

nProtect
Adware/W32.Agent.537088
14.04.17.03

Panda Antivirus
Trj/CI.A
14.04.24.03

Rising Antivirus
PE:Trojan.Win32.Generic.1494D2CF!345297615
23.00.65.14422

Trend Micro House Call
ADW_KRADDARE
7.2.114

Trend Micro
ADW_KRADDARE
10.465.24

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28320

File size:
524.5 KB (537,088 bytes)

Product version:
1.0.0.1

Copyright:
(c) CJMooter. All rights reserved.

Original file name:
WinExpandSetup_newmgoon.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\updatewinexpand.exe

File PE Metadata
Compilation timestamp:
4/28/2013 8:12:15 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:qSAbtIUHbwBzjvCHCitQyubIhKGr6b3DQUvlwQLmEKvECec1SHHl5sZgFmyFrMiS:qfmBOCi9ubqUsUd3TKv5ecMn7sc5f6

Entry address:
0x32631

Entry point:
E8, 14, 9E, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 8D, 9E, 00, 00, 83, C4, 14, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 2B, 45, 08, D1, F8, 48, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 55, 08, 53, 56, 57, 33, FF, 3B, D7, 74, 07, 8B, 5D, 0C, 3B, DF, 77, 1E, E8, 6F, 09, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 9E, 3B, 00, 00, 83, C4, 14, 8B, C6, 5F, 5E, 5B, 5D, C3, 8B, 75, 10, 3B, F7, 75, 07, 33, C0...
 
[+]

Entropy:
6.6315

Code size:
303.5 KB (310,784 bytes)

Remove updatewinexpand.exe - Powered by Reason Core Security