wadfngrv.exe

Spy Voice Recorder

LouYue Software Development Co.,Ltd.

The application wadfngrv.exe by LouYue Software Development Co.,Ltd has been detected as a potentially unwanted program by 13 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘VIC’.
Publisher:
Keylogger Spy Monitor,Inc.  (signed by LouYue Software Development Co.,Ltd.)

Product:
Spy Voice Recorder

Version:
3.02.0004

MD5:
6e8bcca2c24cc2ff12b20361cda59edb

SHA-1:
325885584bff46a28ea8d6da0b649ad52a09bcd6

SHA-256:
f4ec5c0dbc764f54855439fcc05029586573fb19ae4ba29b517cb88d617d2d05

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 5:43:50 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Spyware.SpyVoiceRecorder.A
257

Arcabit
Application.Spyware.SpyVoiceRecorder.A
1.0.0.680

Bitdefender
Application.Spyware.SpyVoiceRecorder.A
1.0.20.715

Comodo Security
UnclassifiedMalware
25007

F-Secure
Application.Spyware.SpyVoiceRecorder
11.2016-22-05_1

G Data
Application.Spyware.SpyVoiceRecorder
16.5.25

IKARUS anti.virus
Application.Spyware.SpyVoiceRecorder
t3scan.2.0.9.0

Malwarebytes
PUP.Optional.KeyLogger
v2016.05.22.06

McAfee
Spyware-SpyMonitor
5600.6391

Microsoft Security Essentials
MonitoringTool:Win32/Spyvoice
1.1.12706.0

MicroWorld eScan
Application.Spyware.SpyVoiceRecorder.A
17.0.0.429

Qihoo 360 Security
Win32/Trojan.Adware.37e
1.0.0.1120

VIPRE Antivirus
Hidden Recorder
49342

File size:
355 KB (363,520 bytes)

Product version:
3.02.0004

Original file name:
wadfngrv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\lycd\wadfngrv.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/12/2011 2:00:00 AM

Valid to:
4/12/2012 1:59:59 AM

Subject:
CN="LouYue Software Development Co.,Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LouYue Software Development Co.,Ltd.", L=LouDi, S=HuNan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4196F92430255474574D2184B3168698

File PE Metadata
Compilation timestamp:
11/12/2009 3:08:23 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:imzjkmruZEqs/RA9x/7WwNM0ekdti5CDArAxMDw7LZEl/+UziX6S+xt71sC6rn:iOjiN/9x/7ncrAxYljiCtxx6T

Entry address:
0x2DB8

Entry point:
68, 44, 73, 40, 00, E8, EE, FF, FF, FF, 00, 00, 60, 00, 00, 00, 30, 00, 00, 00, 58, 00, 00, 00, 40, 00, 00, 00, D0, 10, 34, B2, DC, 15, 82, 4B, 9F, 71, 3F, 75, BD, 43, 9A, 59, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 77, 61, 64, 66, 6E, 67, 72, 76, 00, 30, 34, 36, 7D, 23, 32, 2E, 53, 70, 79, 20, 56, 6F, 69, 63, 65, 20, 52, 65, 63, 6F, 72, 64, 65, 72, 00, 65, 6D, 33, 32, 5C, 00, 74, 64, 6F, 6C, 65, 32, 2E, D8, 00, 00, 00, A8, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 0F, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
332 KB (339,968 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VIC

Command:
C:\Program Files\lycd\wadfngrv.exe


Remove wadfngrv.exe - Powered by Reason Core Security