efp.exe

Easy FLV Player

YoutubeGet Developer Team

The executable efp.exe, “Easy FLV Player Setup ” has been detected as malware by 10 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. Infected by the Parite virus, a polymorphic file infecting virus that infects all portable EXE and SCR files found on local and shared network drives. The file has been seen being downloaded from www.youtubeget.com.
Publisher:
YoutubeGet Developer Team

Product:
Easy FLV Player

Description:
Easy FLV Player Setup

MD5:
85496ebd2ce95b1513ffd02a80fcd34f

SHA-1:
94886a2c653150b390787f7cdefe58459b25022b

SHA-256:
4b80f329e1653efc716812ea66d660f8065c99918f91f4922aa71da110575714

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/27/2024 1:32:50 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Parite
160518-2

AVG
Win32/Parite
2015.0.4568

Dr.Web
Win32.Parite.3
9.0.1.05190

Emsisoft Anti-Malware
Win32.Parite
9.0.0.4157

ESET NOD32
Win32/Parite.C virus
8.0.319.0

F-Prot
W32/Parite.C
4.6.5.141

Kaspersky
Virus.Win32.Parite
15.0.0.562

McAfee
Virus.W32/Pate.c
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.755.0

Norman
Win32.Parite.C
22.05.2016 07:18:28

File size:
569 KB (582,632 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\efp.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:l2UAtoRUMiDiKzBK5C3HgAAFtfDe821uDi62Vd1/wUXc7qrDyk:l2UYYH1XC3HxAFtrr21u+XddXUi

Entry address:
0x16000

Entry point:
4E, B8, C1, 71, 40, 02, 68, C1, 71, 40, 02, 5F, 68, 2A, 60, 41, 00, 5A, B9, C1, 71, 40, 02, BE, 9C, 05, 00, 00, FF, 34, 32, 41, 31, 04, 24, 8F, 04, 32, 4B, 4E, 83, EE, 03, 75, EF, 90, 29, 0C, 41, 02, C1, 71, 40, 02, C1, 71, 00, 02, 29, 91, 92, 02, CF, 5A, 46, 02, 29, 40, 46, 02, C1, C3, 42, 0A, 3E, 8E, BF, FD, 75, A1, 00, 02, A5, A3, 00, 02, BD, A3, 00, 02, C1, 71, 40, 02, C1, 71, 40, 02, C1, 71, 40, 02, 75, EB, 40, 02, A3, A3, 40, 02, BB, A3, 40, 02, C1, 71, 40, 02, C1, 71, 40, 02, C1, 71, 40, 02, C1, 71...
 
[+]

Code size:
36.5 KB (37,376 bytes)

The file efp.exe has been seen being distributed by the following URL.

Remove efp.exe - Powered by Reason Core Security