supercopier.exe

Grosoft

The executable supercopier.exe has been detected as malware by 30 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ultracopier’.
Product:
Grosoft®

Version:
4.9

MD5:
8744e8506969efc11c3912c182cb6001

SHA-1:
91ca865133d2232c2151c4f32f4cb4370b796548

SHA-256:
0b6f94b67d6294f4bcc7b1152b71e3b6a0e33e51aab8fea63d3aeb98c0a92848

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/28/2024 9:52:16 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Dropper/Agent.806912.B
2011.03.13

Avira AntiVirus
TR/Bagle.94667
7.11.4.177

avast!
Win32:Trojan-gen
2014.9-170313

AVG
Win32/Themida
2018.0.2441

Bitdefender
Trojan.Generic.1882136
1.0.20.360

Clam AntiVirus
PUA.Packed.Themida-2
0.98/17411

Comodo Security
Packed.Win32..Black.~A
7960

Dr.Web
Trojan.Packed.650
9.0.1.072

Emsisoft Anti-Malware
Trojan-Downloader.Win32.Bagle!IK
8.17.03.13.10

ESET NOD32
Win32/Bagle.QT
11.5948

Fortinet FortiGate
W32/Bagle.ANQ!tr.dldr
3/13/2017

F-Prot
W32/Bagle.D.gen
v6.4.6.2.117

F-Secure
Trojan:W32/Agent.JLU
11.2017-13-03_2

G Data
Trojan.Generic.1882136
17.3.21

IKARUS anti.virus
Trojan-Downloader.Win32.Bagle
t3scan.1.1.97.0

K7 AntiVirus
Trojan-Downloader
13.93.4087

Kaspersky
Packed.Win32.Black
14.0.0.-1302

McAfee
Generic.dx
5600.6097

Microsoft Security Essentials
TrojanDownloader:Win32/Bagle.YY
1.163.1557.0

Norman
W32/Mitglied.BKC
11.20170313

nProtect
Trojan-Downloader/W32.Bagle.806912.D
11.02.10.01

Panda Antivirus
Trj/Thed.A
17.03.13.10

Prevx
High Risk Worm
3.0

Quick Heal
TrojanDownloader.Bagle.anq
3.17.11.00

Sophos
Mal/Behav-374
4.63

Trend Micro House Call
TROJ_Generic.DIT
7.2.72

Trend Micro
TROJ_Generic.DIT
10.465.13

Vba32 AntiVirus
Trojan-Downloader.Win32.Bagle.anq
3.12.14.3

VIPRE Antivirus
Trojan.Win32.Generic
8687

ViRobot
Trojan.Win32.Downloader-Bagle.806912.G
2011.3.12.4354

File size:
788 KB (806,912 bytes)

Product version:
4.9

Copyright:
Copyright Grosoft®

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\supercopier4\supercopier.exe

File PE Metadata
Compilation timestamp:
2/10/2009 10:15:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x86014

Entry point:
B8, 00, 00, 00, 00, 60, 0B, C0, 74, 68, E8, 00, 00, 00, 00, 58, 05, 53, 00, 00, 00, 80, 38, E9, 75, 13, 61, EB, 45, DB, 2D, 37, 60, 48, 00, FF, FF, FF, FF, FF, FF, FF, FF, 3D, 40, E8, 00, 00, 00, 00, 58, 25, 00, F0, FF, FF, 33, FF, 66, BB, 19, 5A, 66, 83, C3, 34, 66, 39, 18, 75, 12, 0F, B7, 50, 3C, 03, D0, BB, E9, 44, 00, 00, 83, C3, 67, 39, 1A, 74, 07, 2D, 00, 10, 00, 00, EB, DA, 8B, F8, B8, CF, BD, 10, 00, 03, C7, B9, 6D, 62, 08, 00, 03, CF, EB, 0A, B8, CF, BD, 50, 00, B9, 6D, 62, 48, 00, 50, 51, E8, 87...
 
[+]

Entropy:
7.8945

Packer / compiler:
Themida/WinLicense V1.8.0.2 +

Code size:
264 KB (270,336 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ultracopier

Command:
"C:\Program Files\supercopier4\supercopier.exe""


Remove supercopier.exe - Powered by Reason Core Security