yeisce.exe

The executable yeisce.exe has been detected as malware by 32 anti-virus scanners. It runs as a windows Service named “Pqrstu wetrtwer Ghijklmn Pqrs”.
MD5:
99304b1d8b940fa7ef10e38af44f09d9

SHA-1:
6db024495ab2bb10586f5a8611701510afc6775f

SHA-256:
fd006a878c852718f1d8be083f2d0525c1c5658061a1a04abcd6a37b42adeee1

Scanner detections:
32 / 68

Status:
Malware

Analysis date:
4/26/2024 4:58:17 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Generic.ServStart.A926EAD9
524

AhnLab V3 Security
Dropper/Win32.Dinwod
2015.08.14

Avira AntiVirus
TR/Staser.apzjs
8.3.1.6

Arcabit
Generic.ServStart.A926EAD9
1.0.0.425

avast!
Win32:Agent-AXZD [Trj]
2014.9-150830

AVG
Generic_r
2016.0.3002

Bitdefender
Generic.ServStart.A926EAD9
1.0.20.1210

Dr.Web
Trojan.PWS.Gamania.44384
9.0.1.0242

Emsisoft Anti-Malware
Generic.ServStart.A926EAD9
8.15.08.30.02

ESET NOD32
Win32/ServStart (variant)
9.12092

Fortinet FortiGate
W32/SDBot.BX!tr
8/30/2015

F-Prot
W32/Nitol.F.gen
v6.4.7.1.166

F-Secure
Generic.ServStart.A926EAD9
11.2015-30-08_1

G Data
Generic.ServStart.A926EAD9
15.8.25

IKARUS anti.virus
Trojan.Win32.ServStart
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.208.16887

Kaspersky
HEUR:Backdoor.Win32.Generic
14.0.0.1505

Malwarebytes
Trojan.FakeLPK
v2015.08.30.02

McAfee
BackDoor-FBOD!D323DC615EEC
5600.6658

Microsoft Security Essentials
DDoS:Win32/Nitol.A
1.1.11903.0

MicroWorld eScan
Generic.ServStart.A926EAD9
16.0.0.726

NANO AntiVirus
Trojan.Win32.Gamania.drvyfe
0.30.24.3079

nProtect
Generic.ServStart.A926EAD9
15.08.13.01

Panda Antivirus
Trj/Genetic.gen
15.08.30.02

Qihoo 360 Security
HEUR/QVM11.1.Malware.Gen
1.0.0.1015

Quick Heal
TrojanAPT.LecnaCShip.MUE.Z4
8.15.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
15.8.30.2

Rising Antivirus
PE:Backdoor.Overie!1.64BD
23.00.65.15828

Sophos
Mal/Behav-004
4.98

Trend Micro House Call
TROJ_NITOL.SMN1
7.2.242

Trend Micro
TROJ_NITOL.SMN1
10.465.30

VIPRE Antivirus
Trojan.Win32.Nitol.b
42868

File size:
21 KB (21,504 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\yeisce.exe

File PE Metadata
Compilation timestamp:
5/18/2015 9:20:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
384:KAnYGw8PYtOgjdkobbqbNQ5NYsQq0KZ6v6b2prnD5FQtPts+9Xyyt:KkTXwtOVOqba5SqL6LEP9b

Entry address:
0xD8C0

Entry point:
60, BE, 00, A0, 40, 00, 8D, BE, 00, 70, FF, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
7.1406

Packer / compiler:
UPX 2.90LZMA

Code size:
16 KB (16,384 bytes)

Service
Display name:
Pqrstu wetrtwer Ghijklmn Pqrs

Service name:
Pqrstu Wwerewre Ghi

Description:
Pqrstuvw werdfew Jklmnop Rstuvwxy Bcd

Type:
Win32OwnProcess, InteractiveProcess


Remove yeisce.exe - Powered by Reason Core Security