vista-mu.exe

Universal termsrv.dll Patch

deepxw Software

The application vista-mu.exe by deepxw Software has been detected as a potentially unwanted program by 5 anti-malware scanners.
Publisher:
deepxw  (signed by deepxw Software)

Product:
Universal termsrv.dll Patch

Version:
1.0.0.5

MD5:
e4c5b750e3f0acda5f176fc9b20c75d6

SHA-1:
b734359379d76b8ee9847d67fd75daf0b582c359

SHA-256:
06a77e6299c0e38c5bffdc5760b78d4e3fb5049d7849b50598bccef298af2d8b

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 2:03:34 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.DropperDapatoB11.Trojan
1.3.0.7133

Dr.Web
Program.TermSrvPatch
9.0.1.0292

IKARUS anti.virus
possible-Threat.Crack.TermServ
t3scan.1.9.5.0

NANO AntiVirus
Riskware.Win32.TermSrvPatch.bliqgg
0.30.24.3283

Trend Micro House Call
CRCK_PATCH
7.2.292

File size:
63.4 KB (64,872 bytes)

Product version:
1.0.0.5

Copyright:
Copyright (C) 2008-2009. All rights reserved.

Original file name:
UniversalTermsrvPatch.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\o\softwares\multi users software\ipc\vista\vista-mu.exe

Digital Signature
Signed by:

Authority:
deepxw Software

Valid from:
1/18/2008 8:00:00 AM

Valid to:
12/31/2011 8:00:00 AM

Subject:
CN=deepxw Software, E=deepxw, O=deepxw Software

Issuer:
CN=deepxw Software, E=deepxw, O=deepxw Software

Serial number:
18232ACE5210A6B04D8617A50040AF4C

File PE Metadata
Compilation timestamp:
4/16/2009 11:45:27 AM

OS version:
5.2

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
768:jE85L0/e4mYouQY9ot+3qennVG6ci4glF7buCq1FpwEDhEXpZwoHCspvaEhuBWdE:wHNF7buCq1FpZeeMppvfcSI9A5Nv3++C

Entry address:
0x80B7

Entry point:
6A, 70, 68, E8, 2F, 00, 01, E8, 55, 03, 00, 00, 8D, 45, 80, 50, FF, 15, DC, 10, 00, 01, 66, 81, 3D, 00, 00, 00, 01, 4D, 5A, 75, 27, A1, 3C, 00, 00, 01, 8D, 80, 00, 00, 00, 01, 81, 38, 50, 45, 00, 00, 75, 14, 0F, B7, 48, 18, 81, F9, 0B, 01, 00, 00, 74, 21, 81, F9, 0B, 02, 00, 00, 74, 06, 83, 65, E4, 00, EB, 27, 83, B8, 84, 00, 00, 00, 0E, 76, F1, 33, C9, 39, 88, F8, 00, 00, 00, EB, 0E, 83, 78, 74, 0E, 76, E1, 33, C9, 39, 88, E8, 00, 00, 00, 0F, 95, C1, 89, 4D, E4, 83, 65, FC, 00, 6A, 02, 5E, 56, FF, 15, B8...
 
[+]

Entropy:
5.7305

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
34.5 KB (35,328 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to broadband.actcorp.in  (202.83.24.138:80)

TCP (HTTP):
Connects to a23-212-109-146.deploy.static.akamaitechnologies.com  (23.212.109.146:80)

Remove vista-mu.exe - Powered by Reason Core Security