chit dlya igry.exe

Windows Media Player Folder Sharing Executable

Strong Media

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable chit dlya igry.exe, “Windows Media Player Folder Sharing Executable” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Strong Media)

Product:
Microsoft® Windows® Operating System

Description:
Windows Media Player Folder Sharing Executable

Version:
11.0.5721.5262 (WMP_11.090130-1421)

MD5:
d9ef8d3f5154f73b1f2e68ca7cd16f2b

SHA-1:
0b85f697d5e02d239c8410931cc85819f97af887

SHA-256:
c62c0dac54a7ab6fc54ac0c1234c50b024771443e17dada8f8389807bbf84842

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/29/2024 8:35:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.29.23

File size:
936.5 KB (958,952 bytes)

Product version:
11.0.5721.5262

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
wmpshare.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\chit dlya igry.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/14/2016 3:00:00 AM

Valid to:
6/15/2017 2:59:59 AM

Subject:
CN=Strong Media, O=Strong Media, STREET="Sokolniki Square, 4 A", L=Moscow, S=Moscow, PostalCode=107113, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DE80B6BBB2E40F5F7B3C2F4B76F141D9

File PE Metadata
Compilation timestamp:
7/15/2016 3:09:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1030

Entry point:
55, 8B, EC, 81, EC, 40, 04, 00, 00, 8B, 45, F8, 03, 45, F8, 89, 45, F0, 8B, 4D, F4, 2B, 4D, F0, 89, 4D, F0, 8B, 55, DC, 0F, AF, 55, E0, 89, 55, F4, 8B, 45, E4, C1, E0, 04, 89, 45, F4, 8B, 55, F4, 8B, 4D, F4, D3, E2, 89, 55, E4, 68, 4C, 80, 4D, 00, FF, 15, 20, C0, 4B, 00, 68, 58, 80, 4D, 00, FF, 15, 1C, C0, 4B, 00, 8B, 45, EC, 69, C0, 6F, 6D, 3E, 12, 89, 45, F8, 8B, 4D, F0, 51, 8B, 55, F0, 52, FF, 15, 0C, C0, 4B, 00, 68, 70, 80, 4D, 00, FF, 15, 20, C0, 4B, 00, 68, 93, 15, 00, 00, A1, 34, 43, 4E, 00, 50, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
744.5 KB (762,368 bytes)

Remove chit dlya igry.exe - Powered by Reason Core Security