welcome.exe

FlashJester Jugglor Engine

3rd Eye Solutions

The executable welcome.exe, “FlashJester Jugglor Engine ” has been detected as malware by 23 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from drive.google.com.
Publisher:
3rd Eye Solutions

Product:
FlashJester Jugglor Engine

Description:
FlashJester Jugglor Engine

Version:
2.1.0.0

MD5:
007888ed288a40519236ab566eaaf8af

SHA-1:
a7a879e71b2683745f09b0db1f2a4243a3cfd73f

SHA-256:
a64269f806d5a1b819cad9fddb9474e331c380e0b688f20b5c96e12eb4661f3f

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
12/21/2025 3:20:35 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Pincav.5757052
2014.10.11

Baidu Antivirus
Trojan.Win32.Pincav
4.0.3.14123

Bkav FE
W32.Clod34f.Trojan
1.3.0.4959

Comodo Security
Heur.Suspicious
17906

Dr.Web
Trojan.Inject1.5050
9.0.1.084

Fortinet FortiGate
W32/Pincav.GRS!tr
12/3/2014

F-Prot
W32/MalwareF.DXDS
v6.4.7.1.166

IKARUS anti.virus
Trojan-Dropper.Win32.Injector
t3scan.1.7.8.0

Kaspersky
Trojan-Dropper.Win32.Injector
14.0.0.2851

McAfee
Artemis!007888ED288A
5600.7181

NANO AntiVirus
Trojan.Win32.Pincav.qxpyg
0.28.2.62483

Norman
Malware.ZDKS
11.20140325

Quick Heal
Trojan.Pincav.g3
12.14.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.3.17

Rising Antivirus
PE:Trojan.Win32.Generic.12A8115C!313004380
23.00.65.141201

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.0BL611
7.2.337

Trend Micro
TROJ_SPNR.0BL611
10.465.03

Vba32 AntiVirus
Trojan.Pincav
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
27228

ViRobot
Trojan.Win32.A.Pincav.1382504[UPX]
2011.4.7.4223

XVirus List
Win32.Detected
2.11.20

Zillya! Antivirus
Trojan.Pincav.Win32.7962
2.0.0.1949

File size:
2.2 MB (2,287,204 bytes)

Product version:
2.1.0.0

Copyright:
© Copyright FlashJester Jugglor 1998-2004 by 3rd Eye Solutions Ltd

Original file name:
welcome.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:oStI9R8Fs8F+iYC/ULvEepyC/8BFnvHZMghLRLkKeX6t78xyNL:oS48Fv+iB/+yZiORPeX6hNL

Entry address:
0x9DEA0

Entry point:
60, BE, 00, 80, 46, 00, 8D, BE, 00, 90, F9, FF, C7, 87, B0, 74, 07, 00, 45, 06, 8B, 1D, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
220 KB (225,280 bytes)

The file welcome.exe has been seen being distributed by the following URL.

https://drive.google.com/a/.../uc?id=0B5mthA_F7BhWaTRRbXVJZG9FVWM&export=download

Remove welcome.exe - Powered by Reason Core Security