windows.exe

Karim Lammali

The executable windows.exe has been detected as malware by 5 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Sidebar(x34) Build10’.
Publisher:
Microsoft Fonction Basic  (signed by Karim Lammali)

Product:
Microsoft Fonction Basic

Version:
8.5.74.7

MD5:
ca38c5066778f846df06ed1f77b8a221

SHA-1:
5750f55100587c84f79d3c4d553605cc857c298d

SHA-256:
33a66ecb290511645c83687218deef4f74f6fb75a55770074d020feaebffb786

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
12/11/2018 1:50:16 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
MSIL:Agent-DDY [Trj]
160215-2

Emsisoft Anti-Malware
Gen:Variant.MSILPerseus.1806
11.5.0.6191

F-Secure
Variant.MSILPerseus.1806
5.15.21

Microsoft Security Essentials
Threat.Undefined
1.215.312.0

Norman
Gen:Variant.MSILPerseus.1806
29.02.2016 05:46:54

File size:
400.9 KB (410,512 bytes)

Product version:
8.5.74.7

Copyright:
Microsoft Fonction Basic

Trademarks:
Microsoft Fonction Basic

Original file name:
34 Build 10.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\programme files(x34)build10\windows.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/18/2013 12:00:00 AM

Valid to:
5/21/2014 1:00:00 PM

Subject:
CN=Karim Lammali, O=Karim Lammali, L=Besançon, C=FR

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06477E3425F1448995CED539789E6842

File PE Metadata
Compilation timestamp:
3/13/2014 8:42:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:q3IO9dmEwMt2z9tyVpscTvIExcxajPlpUCsXn6+5ZycLkOGfdEYKRt1ejb0+6Tex:KIO9MEXtkonz2ycAtFno1/xBu

Entry address:
0x5F2DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
373 KB (381,952 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Sidebar(x34) Build10

Command:
C:\users\{user}\appdata\roaming\programme files(x34)build10\windows.exe


Remove windows.exe - Powered by Reason Core Security