xuhuotr.exe

Marsukife Visatl 2010

The executable xuhuotr.exe has been detected as malware by 14 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
Product:
Marsukife® Visatl 2010

Version:
6.38.6132.31732

MD5:
7be349f932488fd5f2e8ed5cf9486f57

SHA-1:
9712b239d2384595da7f2866d76f3cc9f1585368

SHA-256:
00a0d0083defc865167bc43048dcfd2b542e62235a84c7e80690e519b5212369

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
4/24/2024 4:06:25 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.480787
835

Avira AntiVirus
TR/Crypt.ZPACK.Gen2
7.11.180.154

avast!
Win32:Dropper-gen [Drp]
141023-1

AVG
Win32/Cryptor
2014.0.4040

Bitdefender
Gen:Variant.Kazy.480787
1.0.20.1475

Bkav FE
HW32.Packed
1.3.0.4959

Emsisoft Anti-Malware
Gen:Variant.Kazy.480787
8.14.10.22.03

ESET NOD32
probably unknown NewHeur_PE virus
7.0.302.0

G Data
Gen:Variant.Kazy.480787
14.10.24

Malwarebytes
Trojan.FakeMS
v2014.10.22.03

McAfee
PWSZbot-FADO!7BE349F93248
5600.6969

MicroWorld eScan
Gen:Variant.Kazy.480787
15.0.0.885

Quick Heal
FraudTool.Security
10.14.14.00

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141020

File size:
286.2 KB (293,102 bytes)

Product version:
6.38.6132.31732

Original file name:
desinko.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\ibyvelik\xuhuotr.exe

File PE Metadata
Compilation timestamp:
5/29/2011 3:18:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:3VJKAe61qzBfSV5JpjkXp/aoNUGSkiz/DQMbA+OuQAXIkz8vu6G/:FIlSV5JFkXphNizMMbA+OviIkzsVG/

Entry address:
0xCD14

Entry point:
55, 8B, EC, 81, EC, 48, 03, 00, 00, B9, 51, 00, 00, 00, 89, 8D, 3C, FD, FF, FF, 53, EB, 40, 2B, C6, 3B, 85, 68, FD, FF, FF, 74, 36, 89, 8D, A0, FD, FF, FF, 3B, 85, DC, FE, FF, FF, 75, 28, 83, F0, 13, EB, 23, 2B, C6, BE, FC, 00, 00, 00, 89, B5, 04, FD, FF, FF, 3B, 8D, 04, FE, FF, FF, 74, 0E, 83, C0, 92, 83, F9, 8A, 75, 06, 89, 85, 94, FE, FF, FF, 56, 83, E8, C4, 89, 85, 3C, FD, FF, FF, 57, 8B, 3D, F8, 4E, 43, 00, 89, 85, 3C, FD, FF, FF, 89, BD, 3C, FD, FF, FF, 83, F8, AF, 75, 06, 89, BD, 0C, FE, FF, FF, 8D...
 
[+]

Entropy:
7.8835

Developed / compiled with:
Microsoft Visual C++

Code size:
100.5 KB (102,912 bytes)

Scheduled Task
Task name:
Security Center Update - 2606060516

Trigger:
Daily (Runs daily at 3:00 PM)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove xuhuotr.exe - Powered by Reason Core Security