7g7farmy3srr.exe

Corel Common Framework

OOO

The application 7g7farmy3srr.exe by OOO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Corel Corporation  (signed by OOO )

Product:
Corel Common Framework

Description:
DIM

Version:
7.5.0.375

MD5:
daf8a77fc3ace3addc92cee48f6dbe89

SHA-1:
fc2efbbc3ef59f96bdcbcd1d58e44769e1086723

SHA-256:
2f102f94b10f5761f85de6a8ae9a5ce6c4296fd7f6e70a21244f6d8c3acca36c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 1:42:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.2.21

File size:
560 KB (573,408 bytes)

Product version:
7.5.0.375

Copyright:
Copyright(c) 2007 Corel Corporation

Trademarks:
Copyright(c) 2007 Corel Corporation

Original file name:
DIMIntl.dll

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\7g7farmy3srr.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/28/2016 3:00:00 AM

Valid to:
9/29/2017 2:59:59 AM

Subject:
CN="OOO ""Stiks""", O="OOO ""Stiks""", STREET=d.7 ul.Glinki, L=Tyumen, S=Tyumen region, PostalCode=625015, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B526F3AAE3DA60C05A2E941DBACDBFF2

File PE Metadata
Compilation timestamp:
10/16/2016 10:29:00 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x81FB0

Entry point:
55, 8B, EC, 81, EC, A4, 02, 00, 00, 53, 56, 57, C6, 85, 67, FF, FF, FF, 1D, EB, 02, CD, 4F, EB, 02, 87, F7, 68, D3, 1F, 48, 00, C3, CD, 83, EB, 01, 55, 8B, C0, 68, E0, 1F, 48, 00, C3, 33, DD, 68, E7, 1F, 48, 00, C3, 56, EB, 02, 2B, E3, C1, E8, 00, 68, B1, 18, 00, 00, A1, D4, AA, 48, 00, 50, FF, 15, 6C, 38, 48, 00, 85, C0, 74, 0B, B9, 1C, 10, 00, 00, 85, C9, 74, 02, EB, F5, 8B, D2, 8B, 55, 08, 8B, D2, 89, 15, DC, AA, 48, 00, 89, 2D, BC, AA, 48, 00, C7, 85, 28, FF, FF, FF, 00, 00, 00, 00, BA, 69, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
518 KB (530,432 bytes)

Remove 7g7farmy3srr.exe - Powered by Reason Core Security