microduo_windows7_start_v2009.exe

微剋多資訊

The executable microduo_windows7_start_v2009.exe, “Windows 7 啟用程序 2009 Installation ” has been detected as malware by 7 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source.
Publisher:
微剋多資訊

Description:
Windows 7 啟用程序 2009 Installation

Version:
2009

MD5:
c0058e781cbd2aec683b4408406b9e7e

SHA-1:
8b66cb4e291b479b605fdffaa992f8b00c0a7da4

SHA-256:
c423cd2a16485e75131c52391ffbe29d30c63ff5693b5d50e34a2c25d3e86d36

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/30/2024 6:34:15 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft A-Squared
Gen.Trojan!IK
4.5.0.24

IKARUS anti.virus
Gen.Trojan
t3scan.1.1.72.0

K7 AntiVirus
Trojan.Win32.Malware.1
13.7.10.843

McAfee
Suspect-29!C0058E781CBD
5600.6097

Norman
W32/Delf.DRLY
11.20170313

Panda Antivirus
Suspicious file
17.03.13.04

ViRobot
Trojan.Win32.Agent.2558416
2009.9.12.1932

File size:
273.4 KB (279,924 bytes)

Copyright:
微剋多資訊

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\microduo_windows7_start_v2009.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x17DE0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 18, 7D, 41, 00, E8, F0, AA, FE, FF, B8, 40, 7E, 41, 00, E8, F6, 17, FF, FF, 8B, 15, AC, 86, 41, 00, 89, 02, 8B, 15, AC, 86, 41, 00, 8B, 12, A1, B0, 86, 41, 00, E8, 80, D5, FF, FF, 8B, 15, AC, 86, 41, 00, 8B, 12, A1, 50, 86, 41, 00, E8, 3A, 71, FF, FF, A1, AC, 86, 41, 00, E8, E8, 09, FF, FF, E8, 0B, 9B, FE, FF, 00, 00, 00, FF, FF, FF, FF, 01, 00, 00, 00, 2A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5937

Developed / compiled with:
Microsoft Visual C++

Code size:
92 KB (94,208 bytes)

Remove microduo_windows7_start_v2009.exe - Powered by Reason Core Security