winfaith3.exe

WinWizard(3)

Buster Ind Com Imp e Exp de Acessorios P Autos Ltda

The executable winfaith3.exe has been detected as malware by 8 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Notepad’.
Publisher:

Product:
WinWizard(3)

Version:
50.0.8.0

MD5:
14d886e54fda31cbb58383071cc665d4

SHA-1:
33f495b09ae7171612d3671799ddfd268fde6d4b

SHA-256:
f9dd935fcc1ae4a6d8f97fa9e2332ca08eb798606cd011b0613afc003790f56d

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/23/2024 7:08:03 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Staser
2015.03.01

avast!
Win32:Malware-gen
2014.9-151230

ESET NOD32
Win32/Packed.PrivateEXEProtector.J suspicious (variant)
9.11248

G Data
Win32.Trojan.Agent.M013AR
15.12.25

McAfee
Artemis!14D886E54FDA
5600.6535

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.151228

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
37994

ViRobot
Trojan.Win32.S.Staser.11791216[h]
2014.3.20.0

File size:
11.2 MB (11,791,216 bytes)

Product version:
50.0.8.000

Copyright:
Copyright (C) Microsoft, Co. 2012

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\winfaith3.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
3/31/2013 9:00:00 PM

Valid to:
4/1/2014 8:59:59 PM

Subject:
CN=Buster Ind Com Imp e Exp de Acessorios P Autos Ltda, O=Buster Ind Com Imp e Exp de Acessorios P Autos Ltda, L=GOIANIA, S=GOIAS, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0637EE22B4697200C72E2B2A58DBAE34

File PE Metadata
Compilation timestamp:
1/22/2012 4:22:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.67

CTPH (ssdeep):
196608:BqmWj1R5nR7A8JD14yyXEJMTlbomB5FXeeVOK/o55H7OZPIgTWbhCklC:BqB1R5e8DCXlbo2FXroTbOtFiMMC

Entry address:
0x1000

Entry point:
EB, 08, DD, 3B, 00, 00, 00, 00, 00, 00, 73, 00, 68, B8, 3E, 88, 09, 50, 56, 5E, 53, 71, 00, 51, 90, 52, 90, 56, 90, 57, 7D, 00, 55, 81, CB, E9, 38, 00, 00, 40, BA, AA, 3A, 00, 00, 66, 98, 73, 00, 81, FB, 49, 2B, 00, 00, 81, E6, BB, 34, 00, 00, F8, 0F, 82, F7, 28, 00, 00, 81, C6, C5, 24, 00, 00, F8, 0F, 82, 53, 25, 00, 00, 2D, 3A, 27, 00, 00, F8, 0F, 82, E1, 2D, 00, 00, 89, D8, 31, C9, F3, AF, F7, C3, B8, 3E, 00, 00, 39, DE, 29, CB, F9, 0F, 83, 50, 2F, 00, 00, 81, F1, F7, 34, 00, 00, A9, 22, 0C, 00, 00, 01...
 
[+]

Code size:
21 MB (22,061,056 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Notepad

Command:
C:\windows\winfaith3.exe


Remove winfaith3.exe - Powered by Reason Core Security