VCDDaemon.exe

Virtual CloneDrive

Elaborate Bytes AG

The executable VCDDaemon.exe, “Virtual CloneDrive Daemon” has been detected as malware by 8 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘VirtualCloneDrive’.
Publisher:
Elaborate Bytes AG  (signed and verified)

Product:
Virtual CloneDrive

Description:
Virtual CloneDrive Daemon

Version:
5, 4, 0, 1

MD5:
a7a4469bb1ae4a383a1984dd84882547

SHA-1:
2284f28b3e508cd1638b10de866d98aa41abc74c

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/23/2024 11:46:17 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

avast!
Win32:Mabezat [Wrm]
160917-0

AVG
Win32/Mabezat
2013.0.4477

Clam AntiVirus
Win.Trojan.Mabezat-2
0.98/22214

Dr.Web
Win32.HLLW.Tazebama
9.0.1.05190

ESET NOD32
Win32/Mabezat.A virus
6.3.12010.0

F-Prot
W32/Mabezat.A-2
4.6.5.141

F-Secure
Win32.Worm.Mabezat.Gen
5.15.154

Kaspersky
Worm.Win32.Mabezat
15.0.2.529

File size:
209.8 KB (214,839 bytes)

Product version:
5, 4, 0, 0

Copyright:
Copyright © 2001 - 2008 Elaborate Bytes AG

Trademarks:
elby, CloneCD, CloneDVD and Elaborate Bytes are trademarks of Elaborate Bytes AG

Original file name:
VCDDaemon.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\elaborate bytes\virtualclonedrive\vcddaemon.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/7/2006 11:07:29 AM

Valid to:
12/7/2008 11:07:29 AM

Subject:
E=admin@elby.ch, CN=Elaborate Bytes AG, O=Elaborate Bytes AG, C=CH

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000010F5C98B8F5

File PE Metadata
Compilation timestamp:
6/29/2008 10:00:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:G06zaeq2J06pxGTwFg9PYBfIVkZueagpRl6mVP:GBz020GxFg9rVxaF6mZ

Entry address:
0x31EE

Entry point:
BB, 4C, 83, 20, 64, 93, E9, 20, 01, 00, 00, E5, 8B, EE, EA, 96, 1A, EE, EA, 36, 39, 6E, 6E, 6E, EE, 6E, 6E, B8, 6E, 6E, 6E, CD, 9F, A4, 9F, 9E, 9F, A7, A5, A4, 6E, 6E, 6E, E2, CF, E8, D3, D0, CF, DB, CF, 9C, D2, DA, DA, 6E, 6E, 6E, 6E, CA, 6E, 6E, 6E, B4, E0, D3, D3, BA, D7, D0, E0, CF, E0, E7, 6E, B1, E0, D3, CF, E2, D3, B2, D7, E0, D3, D1, E2, DD, E0, E7, AF, 6E, 6E, 6E, 6E, B5, D3, E2, C5, D7, DC, D2, DD, E5, E1, B2, D7, E0, D3, D1, E2, DD, E0, E7, AF, 6E, 6E, 6E, 6E, B5, D3, E2, BB, DD, D2, E3, DA, D3...
 
[+]

Code size:
24 KB (24,576 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VirtualCloneDrive

Command:
"C:\Program Files\elaborate bytes\virtualclonedrive\vcddaemon.exe" \s


Remove VCDDaemon.exe - Powered by Reason Core Security