xctrujso.exe

The executable xctrujso.exe has been detected as malware by 25 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘brlabatn’. According to AVG, this software downloads additional adware offers during setup.
Description:
example.exe

Version:
1.0

MD5:
a6697ad2dbcd35a2ca10788c017680aa

SHA-1:
a6bfd521c82e3bedbe57d98d222b1dbf79b4adf8

SHA-256:
8046b14809710cea9e54cde69012078b2415539c2cfedb23f56d117a28ae3e68

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
4/16/2024 8:56:19 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1819874
889

Avira AntiVirus
TR/Dldr.Kuluoz.D.323
7.11.169.78

avast!
Win32:Malware-gen
2014.9-140829

AVG
Downloader.Generic13
2015.0.3367

Baidu Antivirus
Trojan.Win32.Yakes
4.0.3.14829

Bitdefender
Trojan.GenericKD.1819874
1.0.20.1205

Emsisoft Anti-Malware
Trojan.GenericKD.1819874
8.14.08.29.02

ESET NOD32
Win32/Kryptik.CJPS (variant)
8.10316

F-Secure
Trojan.GenericKD.1819874
11.2014-29-08_6

G Data
Trojan.GenericKD.1819874
14.8.24

IKARUS anti.virus
Trojan-Downloader.Win32.Kuluoz
t3scan.1.7.5.0

Kaspersky
Trojan.Win32.Yakes
14.0.0.3332

Malwarebytes
Trojan.Yakes
v2014.08.29.02

McAfee
Artemis!A6697AD2DBCD
5600.7023

Microsoft Security Essentials
TrojanDownloader:Win32/Kuluoz.D
1.10904

MicroWorld eScan
Trojan.GenericKD.1819874
15.0.0.723

NANO AntiVirus
Trojan.Win32.Yakes.decwsf
0.28.2.61861

nProtect
Trojan.GenericKD.1819874
14.08.25.01

Panda Antivirus
Trj/Chgt.D
14.08.29.02

Qihoo 360 Security
Win32/Trojan.fc1
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.11.13

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_FRS.0NA000HP14
7.2.241

Trend Micro
TROJ_FRS.0NA000HP14
10.465.29

Vba32 AntiVirus
suspected of Cryptor.CDP
3.12.26.3

File size:
125 KB (128,000 bytes)

Product version:
1.0

Copyright:
No rights reserved.

Original file name:
MINIPAD.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\xctrujso.exe

File PE Metadata
Compilation timestamp:
8/23/2014 6:20:14 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.71

CTPH (ssdeep):
3072:QBNqYYXcwhAK8s6gKES9dolVZpkmtA5XAEALY:YNJqAJgKESUlBG5XAE

Entry address:
0x1870

Entry point:
55, 89, E5, 83, EC, 24, C7, 45, E0, 00, 00, 00, 00, C7, 45, E4, 00, 00, 00, 00, 6A, 00, FF, 15, 44, 16, 40, 00, 6A, 00, FF, 15, 60, 16, 40, 00, 8B, 45, FC, 81, 3D, F6, 10, 40, 00, 67, C0, 11, 00, 0F, 84, 53, 02, 00, 00, 81, 3D, F6, 10, 40, 00, A9, AB, 51, 00, 0F, 84, 62, 01, 00, 00, 6A, 00, 6A, 00, 6A, 00, 6A, 25, 50, FF, 15, 28, 12, 40, 00, 6A, 01, FF, 75, EC, FF, 15, 30, 12, 40, 00, 6A, 01, FF, 75, EC, FF, 15, 30, 12, 40, 00, 6A, 01, FF, 75, EC, FF, 15, 30, 12, 40, 00, 6A, 01, FF, 75, EC, FF, 15, 30, 12...
 
[+]

Entropy:
7.0743

Code size:
114 KB (116,736 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
brlabatn

Command:
"C:\users\{user}\appdata\local\xctrujso.exe"


Remove xctrujso.exe - Powered by Reason Core Security