ygaiac3oeqwq.exe

Windows Defender User Interface

BreakPoint Software, Inc.

It runs as a scheduled task under the Windows Task Scheduler named setup triggered to execute each time a user logs in.
Publisher:
Microsoft Corporation  (signed by BreakPoint Software, Inc.)

Product:
Microsoft® Windows® Operating System

Description:
Windows Defender User Interface

Version:
4.9.10586.494

MD5:
99fe5c9a40cc97f52b7fbe199e6ae096

SHA-1:
3b1965e4d28ee3573a756ed6c9f06a3f04b82331

SHA-256:
0ed0453efe83ef6183a26a2c74da63b373d8875fcf08c326d7178151f79a4441

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
7/7/2025 10:29:31 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/Kryptik.GBY trojan
6.3

File size:
314.1 KB (321,664 bytes)

Product version:
4.9.10586.494

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
MSASCUI.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\ygaiac3oeqwq.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/17/2013 5:30:00 AM

Valid to:
10/18/2015 5:29:59 AM

Subject:
CN="BreakPoint Software, Inc.", OU=SECURE APPLICATION DEVELOPMENT, O="BreakPoint Software, Inc.", L=Wayland, S=Massachusetts, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0AC3CF34686D1BFF5FC6519BD737B0C5

File PE Metadata
Compilation timestamp:
8/21/2016 1:04:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:EJKiTyYeBMSLtA+JVSWGvuBQawKFybDQH5jDCGfk:AKiTUMSLG2GrawKFy3QdDCGfk

Entry address:
0x26B6E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9948

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
147 KB (150,528 bytes)

Scheduled Task
Task name:
setup

Path:
\Update\setup

Trigger:
Logon (Runs on logon)


Scan ygaiac3oeqwq.exe - Powered by Reason Core Security