efp.exe

Easy FLV Player

YoutubeGet Developer Team

The executable efp.exe, “Easy FLV Player Setup ” has been detected as malware by 10 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. Infected by the Parite virus, a polymorphic file infecting virus that infects all portable EXE and SCR files found on local and shared network drives. The file has been seen being downloaded from www.youtubeget.com.
Publisher:
YoutubeGet Developer Team

Product:
Easy FLV Player

Description:
Easy FLV Player Setup

MD5:
787575c22b89367d4e897ff214aad971

SHA-1:
16b8e598101fa3c0f72cee0410ada7bf4b907cec

SHA-256:
76140732ff7a0d8e7a9506352ba304eaa8541eb5fe40ff96cec8bdca1165312d

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/27/2024 1:43:55 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Parite
160503-1

AVG
Win32/Parite
2015.0.4591

Dr.Web
Win32.Parite.3
9.0.1.05190

Emsisoft Anti-Malware
Win32.Parite
11.5.0.6191

ESET NOD32
Win32/Parite.C virus
8.0.319.0

F-Prot
W32/Parite.C
4.6.5.141

Kaspersky
Virus.Win32.Parite
15.0.0.562

McAfee
Virus.W32/Pate.c
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.742.0

Norman
Win32.Parite.C
19.05.2016 01:04:49

File size:
569 KB (582,632 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\efp.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:b2UAtoRUMiDiKzBK5C3HgAAFtfDe82/IyY2wJOmE6ELVWvmd7s:b2UYYH1XC3HxAFtrr2/gNxE6kIvmd7s

Entry address:
0x16000

Entry point:
BB, 2A, 60, 41, 00, BF, D0, 71, 40, 02, BA, 9C, 05, 00, 00, 47, B8, D0, 71, 40, 02, FF, 34, 13, 83, E9, D0, 31, 04, 24, 68, D0, 71, 40, 02, 5E, 8F, 04, 13, 41, 83, EA, 04, 75, E8, 90, 38, 0C, 41, 02, D0, 71, 40, 02, D0, 71, 00, 02, 38, 91, 92, 02, DE, 5A, 46, 02, 38, 40, 46, 02, D0, C3, 42, 0A, 2F, 8E, BF, FD, 64, A1, 00, 02, B4, A3, 00, 02, AC, A3, 00, 02, D0, 71, 40, 02, D0, 71, 40, 02, D0, 71, 40, 02, 64, EB, 40, 02, B2, A3, 40, 02, AA, A3, 40, 02, D0, 71, 40, 02, D0, 71, 40, 02, D0, 71, 40, 02, D0, 71...
 
[+]

Code size:
36.5 KB (37,376 bytes)

The file efp.exe has been seen being distributed by the following URL.

Remove efp.exe - Powered by Reason Core Security