auds.exe

广西千炎网络科技有限公司

The application auds.exe by 广西千炎网络科技有限公司 has been detected as a potentially unwanted program by 3 anti-malware scanners.
Publisher:
广西千炎网络科技有限公司  (signed and verified)

Version:
1.0.0.1

MD5:
00c580cca765fe9f85cd0c85ac93b2b5

SHA-1:
ee58428a9c8b1c9fe4238be880e43f25aa3e905c

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
1/15/2025 1:12:11 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160807-0

Dr.Web
Adware.Wuji.17
9.0.1.05190

ESET NOD32
Win32/WuJi.M potentially unwanted application
6.3

File size:
203.6 KB (208,512 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2015

File type:
Executable application (Win32 EXE)

Language:
Chinese

Common path:
C:\Program Files\t_201601110922\201601110922\auds.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/17/2015 12:00:00 AM

Valid to:
11/16/2016 11:59:59 PM

Subject:
CN=广西千炎网络科技有限公司, OU=技术, O=广西千炎网络科技有限公司, L=南宁, S=广西, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1ECA4D827EC25FB144574CEF9DE92C0E

File PE Metadata
Compilation timestamp:
1/9/2016 9:00:45 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:fpClR/E+oxV9ENg+HUfOiVlZPOAGj5WocOuZITBhrVO70RAX/fm:y/AINtapGAGj5z9uZarVO700fm

Entry address:
0x142BE

Entry point:
E8, 70, 05, 00, 00, E9, 6B, FD, FF, FF, FF, 25, 0C, E1, 41, 00, FF, 25, 10, E1, 41, 00, 6A, 14, 68, 18, 29, 42, 00, E8, A0, 02, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, AE, 05, 00, 00, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 96, 02, 00, 00, C2, 10, 00, 6A, 0C, 68, 38, 29, 42, 00, E8, 42, 02, 00, 00...
 
[+]

Code size:
116 KB (118,784 bytes)

Windows Firewall Allowed Program
Name:
C:\Program Files\t_201601110922\201601110922\auds.exe


Remove auds.exe - Powered by Reason Core Security