cryea.dll

The module cryea.dll has been detected as a potentially unwanted program by 26 anti-malware scanners. This file is typically installed with the program Persian soft.
MD5:
50ee457dd3951fa72e0ad6374d7d8574

SHA-1:
5e5fb907a1578b632814fd55a9dbd12916ab5ac8

SHA-256:
bdf2892e171b536d3de984b711217c57944de44cebe903e0803c4d88f72a766c

Scanner detections:
26 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 10:41:23 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.9369683
943

AegisLab AV Signature
Troj.W32.Mepaow
2.1.4+

AhnLab V3 Security
Win-Trojan/Obfuscator.M.182784
2014.07.05

AVG
Generic33
2015.0.3421

Baidu Antivirus
Hacktool.Win32.Obfuscator
4.0.3.1477

Bitdefender
Trojan.Generic.9369683
1.0.20.940

Bkav FE
W32.Clodf6c.Trojan
1.3.0.4959

Comodo Security
ApplicUnwnt.Win32.HackTool.Crack.~A
18765

Dr.Web
Trojan.Siggen5.38819
9.0.1.0188

Emsisoft Anti-Malware
Trojan.Generic.9369683
8.14.07.07.06

F-Secure
Trojan.Generic.9369683
11.2014-07-07_2

G Data
Trojan.Generic.9369683
14.7.24

IKARUS anti.virus
possible-Threat.Crack.Crysis3
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.180.12626

McAfee
RDN/Generic.dx!cpf
5600.7077

Microsoft Security Essentials
VirTool:Win32/Obfuscator.XZ
1.10701

MicroWorld eScan
Trojan.Generic.9369683
15.0.0.564

NANO AntiVirus
Trojan.Win32.Siggen5.cukxbd
0.28.0.60577

Norman
Suspicious_Gen4.DDLWR
11.20140707

nProtect
Trojan/W32.Agent.182784.OJ
14.07.04.01

Panda Antivirus
Trj/Thed.W
14.07.07.06

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.03GD13
7.2.188

Trend Micro
TROJ_SPNR.03GD13
10.465.07

Vba32 AntiVirus
Trojan.PEF13C
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
30964

File size:
178.5 KB (182,784 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\sarir game\crysis 3\bin32\cryea.dll

File PE Metadata
Compilation timestamp:
2/23/2013 1:15:26 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:kbW/Z0N4AjtJB4TlpshZJQIXgfhwLzT25y16LfqR906wD5TFhhWz7uANzf:xZSjtJByLshZ6IXSh8aLY9T0WfhNzf

Entry address:
0x2980

Entry point:
B8, 01, 00, 00, 00, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 33, C9, 33, D2, 33, FF, 39, 4D, 0C, 76, 2F, 53, FE, C1, 0F, B6, C9, 8A, 1C, 31, 47, 8D, 04, 1A, 0F, B6, D0, 8A, 04, 32, 88, 04, 31, 02, C3, 0F, B6, C0, 88, 1C, 32, 0F, B6, 1C, 30, 8B, 45, 08, 30, 5C, 07, FF, 3B, 7D, 0C, 72, D3, 5B, 5F, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, E9, 11, 0D, 02, 00, 8A, 45, 00, 88, 3C, 24, 60, 0F, BA, E1, 0D, 9C, 83, ED, 02, FF, 74, 24, 04, F9, 00, 45, 04, 8D, 64, 24, 2C...
 
[+]

Entropy:
7.3125

Code size:
11 KB (11,264 bytes)

The file cryea.dll has been discovered within the following program.

Persian soft  by Persian soft
www.persiancompany.com
About 3% of users remove it
 
Powered by Should I Remove It?

The file cryea.dll has been seen being distributed by the following 4 URLs.

about:internet

Remove cryea.dll - Powered by Reason Core Security