apctdefdl.exe

iYogi Inc.

The executable apctdefdl.exe has been detected as malware by 5 anti-virus scanners.
Publisher:
iYogi Inc.  (signed and verified)

MD5:
bbbef3a5d11e3318d0f3f7471f14d930

SHA-1:
dcf5868c35ed7694705742469e2d87a87c6c80f3

SHA-256:
4f4d6824dbe83f3d7fde4e2506c879696341191a6771ecd666bc4d3ab9e323df

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
11/25/2024 12:42:06 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.55024.1
7.11.183.182

Bkav FE
W32.GenericSulunchB.Trojan
1.3.0.4959

Clam AntiVirus
Trojan.Qhost-284
0.98/21411

Comodo Security
TrojWare.Win32.Refroso.bj
20024

Trend Micro House Call
HV_QHOST_CG09377D.RDXN
7.2.37

File size:
53.7 KB (55,024 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\apctdefdl.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/4/2009 8:00:00 PM

Valid to:
4/13/2012 7:59:59 PM

Subject:
CN=iYogi Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=iYogi Inc., L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5300351A9D31BA6C9A5ABF370077E8F8

File PE Metadata
Compilation timestamp:
4/5/2011 8:44:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
768:BdpnF5/ija+1I+NYVawgYvCAvEZQ25AX94JosOy5upx/0LTWHiqZl84woTMeA8xg:BdJyqnvE3tJSbF0LiHiaxoB3N

Entry address:
0x913C

Entry point:
55, 8B, EC, B9, 06, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, A0, 8F, 40, 00, E8, FB, BD, FF, FF, 33, C0, 55, 68, 00, 97, 40, 00, 64, FF, 30, 64, 89, 20, A1, 8C, A9, 40, 00, 33, D2, 89, 10, 8D, 45, EC, E8, C8, C1, FF, FF, 8B, 55, EC, B8, D4, F9, 40, 00, E8, FF, AE, FF, FF, 8D, 55, E8, A1, D4, F9, 40, 00, E8, C2, C0, FF, FF, 8B, 55, E8, B8, D4, F9, 40, 00, E8, E5, AE, FF, FF, C6, 05, D0, F9, 40, 00, 01, 6A, 0A, 68, 10, 97, 40, 00, A1, F0, D7, 40, 00, 50, E8, 08, BE, FF, FF, 8B, F8, 57, A1...
 
[+]

Entropy:
6.4234

Developed / compiled with:
Microsoft Visual C++

Code size:
34.5 KB (35,328 bytes)

Remove apctdefdl.exe - Powered by Reason Core Security