drcheatslauncher.exe

The application drcheatslauncher.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dr-cheats.com.
MD5:
e63a75bc9bea5f378d7f7adbb5f9c357

SHA-1:
fa8439324001641a1393d8b13b7824b54660d4d0

SHA-256:
02c189ae03041864d2b668000f0727e2fb59f40200d86f305eb9388088c9013c

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 9:55:17 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.FU.kFW@a4@fDIpi
291

Agnitum Outpost
TrojanSpy.Agent
7.1.1

Avira AntiVirus
TR/Spy.Agent.3311616
8.3.2.4

Arcabit
Trojan.Heur.FU.EFE1CF
1.0.0.642

avast!
Win32:Malware-gen
2014.9-160419

AVG
Win32/Blacked
2017.0.2769

Bitdefender
Gen:Trojan.Heur.FU.kFW@a4@fDIpi
1.0.20.550

Bkav FE
HW32.Packed
1.3.0.7400

Clam AntiVirus
Win.Adware.Browsefox-12346
0.98/21511

Emsisoft Anti-Malware
Gen:Trojan.Heur.FU.kFW@a4@fDIpi
8.16.04.19.10

F-Secure
Gen:Trojan.Heur.FU.kFW@a4@fDIpi
11.2016-19-04_3

G Data
Gen:Trojan.Heur.FU.kFW@a4@fDIpi
16.4.25

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.338

McAfee
Artemis!E63A75BC9BEA
5600.6425

MicroWorld eScan
Gen:Trojan.Heur.FU.kFW@a4@fDIpi
17.0.0.330

Trend Micro
TROJ_GEN.R00IC0OJJ15
10.465.19

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
46576

Zillya! Antivirus
Trojan.Buzus.Win32.125203
2.0.0.2615

File size:
3.2 MB (3,311,616 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\drcheatslauncher.exe

File PE Metadata
Compilation timestamp:
10/3/2015 5:09:19 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:HsSGcT4MxVGb4gG69EHbLkCE0aTzLcIZW5:TGcRqbn9gbLAnzLc6e

Entry address:
0x31DE70

Entry point:
9C, 60, C7, 44, 24, 20, F1, 01, 8E, FF, 9C, 9C, 89, 74, 24, 04, 8D, 64, 24, 28, 0F, 80, BC, 7F, FF, FF, 68, 9A, EA, AE, CF, 9C, 8D, 64, 24, 04, E9, 2F, C2, 00, 00, E8, 9A, 19, FF, FF, 89, F4, 68, 40, 76, 59, AD, 8D, 64, 24, 04, E9, D6, 2D, FF, FF, 8D, 64, 24, 04, 0F, 84, CC, 2D, FF, FF, F8, E9, 98, D0, FF, FF, E8, FC, 15, FF, FF, 60, 8D, 64, 24, 28, 0F, 83, B6, 2D, FF, FF, 80, FB, 0E, 83, C1, 01, 51, 9C, E9, 8E, CD, FF, FF, 01, F8, E9, 92, 1B, 00, 00, B2, 52, 30, F5, C1, 54, 55, F2, BB, 27, 38, 14, CD, 43...
 
[+]

Entropy:
7.9217  (probably packed)

Code size:
135.5 KB (138,752 bytes)

The file drcheatslauncher.exe has been seen being distributed by the following URL.

Remove drcheatslauncher.exe - Powered by Reason Core Security