compiler-3.exe

Lavasoft Limited

The executable compiler-3.exe has been detected as malware by 4 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘compiler-22’.
Publisher:
Lavasoft Limited  (signed and verified)

MD5:
bfc26203a42649fecce370972e6fe4f6

SHA-1:
5e211691cafcb52285f9788bf0d6845bccb63094

SHA-256:
cdb2db957c3c30d576d78d8925c200046c038e6e49e7df2052200bbbd3e0cfdd

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
11/26/2024 1:36:16 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160917-0

Dr.Web
Trojan.Nymaim.36
9.0.1.05190

ESET NOD32
Win32/Kryptik.FELR trojan
6.3.12010.0

F-Secure
Variant.Razy.89521
5.15.154

File size:
429.1 KB (439,416 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\compiler-57\compiler-3.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/28/2011 1:00:00 AM

Valid to:
1/28/2013 12:59:59 AM

Subject:
CN=Lavasoft Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lavasoft Limited, L=Sliema, S=SLM, C=MT

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7CEC887E3A0E10A63F47C72B25751AB9

File PE Metadata
Compilation timestamp:
1/29/2010 10:00:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
4.199

Entry address:
0x1000

Entry point:
6A, 00, FF, 15, 12, A8, 40, 00, 8B, F8, FF, 15, 06, A8, 40, 00, 50, 6A, 0B, 33, C0, 50, 6A, 02, 6A, 00, 6A, 00, FF, 15, 52, A9, 40, 00, 57, 50, 83, F8, FF, 0F, 85, 3A, 04, 01, 00, 8B, EC, 81, EC, 14, 0E, 00, 00, B8, 57, 4D, 41, 00, 50, FF, 15, 36, A9, 40, 00, 8B, 3D, 3C, 49, 41, 00, 89, 3D, 4F, 4C, 41, 00, 83, 2D, 4F, 4C, 41, 00, 11, 0F, 84, 25, 23, 00, 00, BE, 0A, 00, 00, 00, 89, B5, B4, FA, FF, FF, 8B, 3D, 4F, 4C, 41, 00, 89, 3D, 16, 43, 41, 00, 81, 3D, 16, 43, 41, 00, EF, FF, FF, FF, 0F, 85, F3, DE, FF...
 
[+]

Packer / compiler:
FASM v1.3x

Code size:
24.5 KB (25,088 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
compiler-22

Command:
C:\ProgramData\compiler-57\compiler-3.exe -92


Remove compiler-3.exe - Powered by Reason Core Security