34c6bd.exe

The executable 34c6bd.exe has been detected as malware by 18 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘34C6BD’.
MD5:
7917e4f6992a3dad7b3029939eaeca50

SHA-1:
91db14d136e1b446235ee9a8a65173a38268d948

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
4/28/2024 6:57:33 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.Gen
7.9.1.122

Emsisoft A-Squared
Trojan.Win32.FlyStudio!IK
4.5.0.48

avast!
Win32:Malware-gen
2014.9-170314

Bitdefender
GenPack:Backdoor.Generic.183915
1.0.20.365

Dr.Web
Win32.HLLW.Autoruner.4360
9.0.1.073

F-Prot
W32/Nuj.A.gen
v6.4.5.1.85

F-Secure
GenPack:Backdoor.Generic.183915
11.2017-14-03_3

G Data
GenPack:Backdoor.Generic.183915
17.3.19

IKARUS anti.virus
Trojan.Win32.FlyStudio
t3scan.1.1.79.0

K7 AntiVirus
Trojan-Downloader.Win32.FlyStudio.fw
13.7.10.939

Kaspersky
Trojan-Downloader.Win32.FlyStudio
14.0.0.-1308

McAfee
W32/Autorun.worm.ev
5600.6095

Microsoft Security Essentials
Backdoor:Win32/FlyAgent.F
1.163.1557.0

Prevx
Medium Risk Malware
3.0

Rising Antivirus
Worm.Win32.Autorun.fbf
23.00.65.17312

Sophos
Mal/EncPk-GF
4.49

Trend Micro
WORM_FLYSTUD.SMC
10.465.14

Vba32 AntiVirus
Trojan-Dropper.Win32.Flystud.ko
3.12.12.1

File size:
1.4 MB (1,482,396 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\adbdb8\34c6bd.exe

File PE Metadata
Compilation timestamp:
12/25/1972 12:33:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
4.0

Entry address:
0x13EB

Entry point:
52, 53, 83, E3, 00, 57, 50, 56, 51, 0F, 84, F0, FE, FF, FF, 6C, D3, C6, 27, C9, 59, 5E, 58, 5F, 5B, 5A, F8, 0F, 83, 6F, FD, FF, FF, 0F, 63, BC, A4, 43, 83, EB, FC, E9, 9A, FE, FF, FF, 61, 14, 29, 42, 6B, 44, 29, 7D, 5E, 2B, A2, 34, 14, 68, 1C, C1, 65, 7B, 29, F5, DE, F0, A2, CB, 5D, 2B, A6, B0, E4, 52, 8A, 3D, DE, BA, 1F, 9D, 2F, 79, 9E, B1, 5F, 28, 12, C0, DD, 2A, F1, 01, 2B, 50, F2, B1, DA, 67, 21, 76, E3, C2, F6, 3C, CE, E9, 8C, B2, DA, A7, 9E, 25, 1F, F3, EE, B5, DD, 3A, 29, FA, E2, EA, 97, B2, 58, 9F...
 
[+]

Entropy:
7.7772  (probably packed)

Code size:
24 KB (24,576 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
34C6BD

Command:
C:\Windows\System32\adbdb8\34c6bd.exe


Remove 34c6bd.exe - Powered by Reason Core Security