{5a9121ef-b548-4ce9-af62-d485da9f89a0}.exe

Vkontakte DJ Installer

The application {5a9121ef-b548-4ce9-af62-d485da9f89a0}.exe has been detected as a potentially unwanted program by 15 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from setup.vkontakte.dj.
Product:
Vkontakte DJ Installer

Version:
1.9.1.30

MD5:
5b55da262e1c2d016f5628a796dd52c3

SHA-1:
d38e1d78089af1ae6f29381647dbcc8018b0064d

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 8:36:02 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1535113
346

Arcabit
Application.Generic.D176C89
1.0.0.629

Baidu Antivirus
PUA.MSIL.VKontakteDJ
4.0.3.16223

Bitdefender
Application.Generic.1535113
1.0.20.270

Dr.Web
Program.VKontakteDJ.9
9.0.1.054

ESET NOD32
MSIL/VKontakteDJ.A potentially unwanted (variant)
10.12738

Fortinet FortiGate
Riskware/VKontakteDJ
2/23/2016

F-Secure
Application.Generic.1535113
11.2016-23-02_3

G Data
Application.Generic.1535113
16.2.25

K7 AntiVirus
Adware
13.212.18131

Kaspersky
not-a-virus:Downloader.MSIL.VKontakteDJ
14.0.0.617

MicroWorld eScan
Application.Generic.1535113
17.0.0.162

Panda Antivirus
Generic Suspicious
16.02.23.03

Sophos
Vkontakte DJLoader (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic
45892

File size:
564 KB (577,536 bytes)

Product version:
1.9.1.30

Copyright:
Copyright © 2015

Original file name:
DjLoader.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\vkontaktedj\{5a9121ef-b548-4ce9-af62-d485da9f89a0}.exe

File PE Metadata
Compilation timestamp:
11/19/2015 4:00:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:FfBtFH4P7qsKQ0jnAt4BknkA3F2nFtsP5BtFW:FfJH4DBKQ0jnpBknk62FtshJW

Entry address:
0x6B1BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 70, 00, 00, 80, 10, 00, 00, 00, 88, 00, 00, 80, 18, 00, 00, 00, A0, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
420.5 KB (430,592 bytes)

The file {5a9121ef-b548-4ce9-af62-d485da9f89a0}.exe has been seen being distributed by the following URL.

Remove {5a9121ef-b548-4ce9-af62-d485da9f89a0}.exe - Powered by Reason Core Security