ea.exe

Kernel Veryfier

eSXi

The application ea.exe has been detected as a potentially unwanted program by 26 anti-malware scanners.
Publisher:
eSXi

Product:
Kernel Veryfier

Version:
2.4.4587.1000

MD5:
cf82ddeab3480a9dbfc4b77cfb5a2f3c

SHA-1:
2d722373f4fcd3c4e5e005627aeb70ae0d413166

SHA-256:
322954fc1635a46168d402c9108c9f0f50fc1f57aa6cd60f5b5fb32677389a4b

Scanner detections:
26 / 68

Status:
Potentially unwanted

Analysis date:
4/28/2024 6:13:38 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Krap.22016.LQ
2010.08.11

Avira AntiVirus
TR/ATRAPS.Gen2
8.2.4.34

avast!
Win32:Crypt-GHH
2014.9-170316

AVG
Cryptic
2018.0.2438

Bitdefender
Gen:Variant.Ursnif.8
1.0.20.375

Comodo Security
TrojWare.Win32.MalPack.AR2
5713

Dr.Web
Trojan.Botnetlog.13
9.0.1.075

Emsisoft Anti-Malware
Virus.Win32.Injector!IK
8.17.03.16.04

ESET NOD32
Win32/Kryptik.EDA (variant)
11.5357

F-Prot
W32/Harnig.A.gen
v6.4.6.1.107

F-Secure
Gen:Variant.Ursnif.8
11.2017-16-03_5

G Data
Gen:Variant.Ursnif
17.3.21

IKARUS anti.virus
Virus.Win32.Injector
t3scan.1.1.88.0

Kaspersky
Packed.Win32.Krap
14.0.0.-1316

McAfee
Artemis!CF82DDEAB348
5600.6094

Microsoft Security Essentials
TrojanDownloader:Win32/Harnig.gen!P
1.163.1557.0

Norman
W32/Obfuscated.WPH!genr
11.20170316

nProtect
Gen:Variant.Ursnif.8
10.08.11.02

Panda Antivirus
Adware/SecurityEssentials2010
17.03.16.04

Prevx
Medium Risk Malware
3.0

Quick Heal
Win32.Packed.Krap.ao.6
3.17.11.00

Sophos
Mal/FakeAV-BW
4.56

SUPERAntiSpyware
Trojan.Agent/Gen-Kryp[Varver]
8533

Trend Micro House Call
TROJ_BRDOLAB.SMF
7.2.75

Trend Micro
TROJ_BRDOLAB.SMF
10.465.16

Vba32 AntiVirus
BScope.Trojan.SB.0537
3.12.14.0

File size:
21.5 KB (22,016 bytes)

Product version:
2.4.4587.1000

Copyright:
eSXi (c)

Original file name:
KVFR.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\ea.exe

File PE Metadata
Compilation timestamp:
11/9/2007 10:25:20 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x40D0

Entry point:
55, 8B, EC, 81, EC, D4, 02, 00, 00, C7, 85, 40, FD, FF, FF, 00, 80, 1E, 00, 8D, 85, 40, FD, FF, FF, 31, F6, 50, 6A, 00, 6A, 00, FF, 15, 9C, 90, 40, 00, FF, 15, C8, 90, 40, 00, 2D, 21, 05, 00, 00, 01, C6, 8B, 85, 40, FD, FF, FF, 85, C0, 0F, 85, 8D, 02, 00, 00, B8, F5, FF, 00, 00, 01, F0, 89, 85, 40, FD, FF, FF, 89, 85, C4, FD, FF, FF, 89, D3, C7, 85, D0, FD, FF, FF, FB, 00, 00, 00, C7, 85, D1, FD, FF, FF, BF, 82, 78, FF, 6A, 01, 31, C0, 6A, 00, 31, DB, 53, 6A, 00, FF, 15, D8, 90, 40, 00, 5B, 4B, 01, D8, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
16.5 KB (16,896 bytes)

Remove ea.exe - Powered by Reason Core Security