viewer.exe

The application viewer.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. Accoriding to the detections, this has been classified as a kyelogger which is capable of recoring a user's keystrokes.
MD5:
1a7a2bc3848d1d7a07ee484e098ba87f

SHA-1:
f9f8a0365f8434be279a6557f18deeadf94a18c6

SHA-256:
93bccdcef26989b777594384d0f6a18af0ded10d939a8d364de94f1c44616c83

Scanner detections:
18 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 11:45:44 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.KeyLogger
7.1.1

Avira AntiVirus
SPR/Ardamax.AB
7.11.109.96

AVG
Ardamax
2015.0.3253

Baidu Antivirus
HackTool.Win32.Monitor
4.0.3.141222

Comodo Security
UnclassifiedMalware
16861

Dr.Web
BackDoor.Xbot.1547
9.0.1.060

ESET NOD32
Win32/KeyLogger.Ardamax.NBG (variant)
8.8749

Fortinet FortiGate
Riskware/Ardamax
3/1/2014

IKARUS anti.virus
not-a-virus:Monitor.Win32.Ardamax
t3scan.2.0.127

Kaspersky
not-a-virus:Monitor.Win32.Ardamax
14.0.0.4237

McAfee
Artemis!1A7A2BC3848D
5600.7204

NANO AntiVirus
Trojan.Win32.KeyLogger.brupjz
0.26.0.55532

Panda Antivirus
Suspicious file
14.12.22.01

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.22.1

Rising Antivirus
Trojan.Win32.Generic.14AA1B9A
23.00.65.141220

Trend Micro House Call
TROJ_GEN.R0CBH01G313
7.2.60

Trend Micro
TROJ_GEN.R0CBC0OJO13
10.465.22

VIPRE Antivirus
Trojan.Win32.Generic
22702

File size:
791.5 KB (810,496 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\xzo\viewer.exe

File PE Metadata
Compilation timestamp:
6/30/2013 7:06:09 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:aNwQzWukloVVETscd3e58ni20Y9fEF43gTZzm8:aNwQzWLoV6TTfi20YhE+8

Entry address:
0x2A19A

Entry point:
E8, EE, 82, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, D8, A0, 48, 00, E8, C4, 14, 00, 00, 6A, 0E, E8, 7A, 1A, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 14, 95, 49, 00, BA, 10, 95, 49, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, EE, E4, FF, FF, 59, FF, 76, 04, E8, E5, E4, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, B3, 14, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, 45, 19, 00, 00, 59, C3, CC, CC, CC, CC, CC, CC...
 
[+]

Code size:
444.5 KB (455,168 bytes)

Remove viewer.exe - Powered by Reason Core Security