as.exe

qBank

The application as.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. This is a setup program which is used to install the application. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages. The file has been seen being downloaded from www.reqxmllo.com.
Publisher:
qBank

Product:
qBank

Version:
6.6.0.24

MD5:
1d20c35112a796a67cb4f746307b4e83

SHA-1:
874396aac42ba6f61583401fa688112d10b2e305

SHA-256:
a781eac0cd8a0675a0ea59fa76cb52072dea6996a406ea3e566e6cac02bbb776

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
11/27/2024 6:52:14 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.Gen7
8.3.2.4

ESET NOD32
Win32/ELEX.GG potentially unwanted application
7.0.302.0

IKARUS anti.virus
AdWare.WProtManager
t3scan.1.9.5.0

Panda Antivirus
Generic Suspicious
16.01.08.06

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen
1.0.0.1077

File size:
2.8 MB (2,906,221 bytes)

Product version:
6.6.0.24

Copyright:
Copyright (C) qBank.com 2010

Original file name:
qBank.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\Documents and Settings\{user}\Application data\8wdm8\aaaa\as.exe

File PE Metadata
Compilation timestamp:
1/8/2016 8:47:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:WDMt5D81xCvnskRrwcQd+CuUfPhv/ATRkV7fu058oJhp4XRBTc4PhGHShAgl:XnD8m6cLofPhv/AyVaMhWXRBA4pYAZl

Entry address:
0x161AB

Entry point:
E8, EC, A2, 00, 00, E9, 7B, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 60, 8B, 47, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, B8, 65, 47, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 60, 8B, 47, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F...
 
[+]

Entropy:
7.8641  (probably packed)

Code size:
386.5 KB (395,776 bytes)

The file as.exe has been seen being distributed by the following URL.

Remove as.exe - Powered by Reason Core Security