etranslator.exe

eTranslator

eTranslator Corp

This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘eTranslator Update’. The file has been seen being downloaded from sendme8.ru and multiple other hosts.
Publisher:
eTranslator Corp

Product:
eTranslator

Version:
1.2.0.0

MD5:
cccf820821a08f3ed9971da6b8ed39f0

SHA-1:
fb22360850579ce8716db74c246341b204c1c9d2

SHA-256:
a300322d63a05af05fcdb81461b007e9f54aa8ab9c0dab5f4211b7d3a175879c

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/25/2024 6:27:52 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Zadved.4
9.0.1.031

File size:
3.3 MB (3,429,095 bytes)

Product version:
1.2.0.0

Copyright:
eTranslator Corp

Trademarks:
eTranslator Corp

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\etranslator\etranslator.exe

File PE Metadata
Compilation timestamp:
1/29/2015 4:48:07 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:JQdYjJGZlSHdS8GurPUWKoiMhlHG/eaCMQuTPT3PVy9Km/BIpoaWf+X:JQdaJlPUWqMS/elW349KPpolq

Entry address:
0x240068

Entry point:
55, 8B, EC, 83, C4, EC, 33, C0, 89, 45, EC, B8, A0, 3E, 63, 00, E8, 9B, C9, DC, FF, 33, C0, 55, 68, DF, 00, 64, 00, 64, FF, 30, 64, 89, 20, E8, 78, 49, DC, FF, 85, C0, 75, 30, E8, 23, 76, FA, FF, 84, C0, 75, 20, 8D, 55, EC, 33, C0, E8, C1, 49, DC, FF, 8B, 45, EC, 33, D2, E8, AB, 76, FA, FF, A1, B4, C2, 64, 00, 8B, 00, E8, 17, 51, EE, FF, E8, 9A, 3D, FF, FF, EB, 05, E8, 03, 1D, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, 68, E6, 00, 64, 00, 8D, 45, EC, E8, 4A, 84, DC, FF, C3, E9, D4, 79, DC, FF, EB, F0, E8, 6D...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.2 MB (2,352,128 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
eTranslator Update

Command:
"C:\users\{user}\appdata\roaming\etranslator\etranslator.exe" -checkforupdates


The file etranslator.exe has been seen being distributed by the following 3 URLs.

http://sendme8.ru/.../84ccda952dc4c528c0eab7c4cacb7fb0.exe

Scan etranslator.exe - Powered by Reason Core Security