vylyu.exe

Paracoro

Bitsum Technologies

The executable vylyu.exe has been detected as malware by 12 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘{49005D69-12F8-C115-92B7-86636C88CF93}’.
Publisher:
Resoutiv inter  (signed by Bitsum Technologies)

Product:
Paracoro

Description:
Salinati lekki

Version:
1.02.0003

MD5:
f72b7af7f75910eaa0de50d04307ac03

SHA-1:
f65575d71624a610a31deb95e2d4c7065bfd6500

SHA-256:
14b536ec63c3aa28e559e50f3d0e7531703fb19e9828ac91eb15457d113d436a

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
4/24/2024 7:11:21 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Heur.Jatif.47
5813571

avast!
Win32:GenMalicious-U [Trj]
160119-0

AVG
Win32/VBCrypt
2015.0.4489

Emsisoft Anti-Malware
Gen:Heur.Jatif.47
10.0.0.5366

ESET NOD32
Win32/Injector.BIUJ trojan
7.0.302.0

F-Secure
Heur.Jatif.47
5.15.21

McAfee
Trojan.Generic-FAUW!F72B7AF7F759
18.0.204.0

Norman
Gen:Heur.Jatif.47
11.01.2016 17:30:26

Sophos
Virus 'Mal/VB-ANA'
5.22

VIPRE Antivirus
Threat.4150696
46826

File size:
230.5 KB (236,049 bytes)

Product version:
1.02.0003

Original file name:
Baylet.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\axivm\vylyu.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
10/1/2009 7:00:00 AM

Valid to:
10/2/2010 6:59:59 AM

Subject:
CN=Bitsum Technologies, O=Bitsum Technologies, STREET=1605 Allen Rd., L=Talbott, S=TN, PostalCode=37877, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00FC594B2E2C30E2B41F4CA24B350BCA89

File PE Metadata
Compilation timestamp:
7/24/2014 12:05:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:2MHlhC4TT0+z2OekGnKAZdoKU58d45s/qJHTvPW:NvC4hPRG7c5s/q9T3

Entry address:
0x142C

Entry point:
68, C4, 15, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 76, 7E, F3, D7, 4E, 6C, D3, 4A, 94, FD, 41, 77, 61, 6F, A3, 03, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 43, 58, 22, 0D, 0A, 42, 63, 61, 64, 69, 6C, 6C, 61, 63, 00, 6F, 72, 6D, 20, 6E, 6F, 6E, 00, 00, 00, 00, FF, CC, 31, 00, 04, 53, 2C, 75, E8, 09, 4A, 5D, 4B, B2, D6, 3D, D7, C2, AE, 3C, 36, 03, 64, 5A, EA, 30, 21, 1B, 4D, 91, AF, 6A, 67, 66, C9, E3, DE, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
216 KB (221,184 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
{49005D69-12F8-C115-92B7-86636C88CF93}

Command:
C:\users\{user}\appdata\roaming\axivm\vylyu.exe


Remove vylyu.exe - Powered by Reason Core Security