executer.exe

Hongkong zoekyu Technology Limited

The application executer.exe by Hongkong zoekyu Technology Limited has been detected as a potentially unwanted program by 4 anti-malware scanners.
Publisher:
Hongkong zoekyu Technology Limited  (signed and verified)

MD5:
586e9d7450bdae7f4cc058fe5b5235ac

SHA-1:
ba04c91042de8579c54080a6fc8b36ac44e7243e

SHA-256:
5f48b560df2bd9a925a5fa186002c012359fff35b2a7ed79112ac2a9b427983b

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
2/24/2025 11:34:13 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Dr.Web
Adware.Mutabaha.1194
9.0.1.05190

ESET NOD32
Win32/ELEX.HD potentially unwanted application
8.0.319.0

Microsoft Security Essentials
Threat.Undefined
1.223.968.0

Reason Heuristics
Adware.Yessearches.Hongkong.Meta (M)
16.6.7.21

File size:
1.6 MB (1,626,712 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\yessearches-bnd\executer.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/31/2015 5:52:51 AM

Valid to:
8/31/2016 5:52:51 AM

Subject:
CN=Hongkong zoekyu Technology Limited, O=Hongkong zoekyu Technology Limited, L=香港, S=香港, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A7482C0A326B72D75AEE1323E44001AB

File PE Metadata
Compilation timestamp:
12/30/2015 5:37:33 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:p30ptI53j6GiiItdZksirvZ3HZBunwZC:OtIgGID/UHjunwZ

Entry address:
0x34C1C

Entry point:
E8, 61, 77, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 80, 92, 46, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, 2D, 5F, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 8D, 85, E4, FC, FF, FF, 6A, 4C, 6A, 00, 50, E8, 30, 25, 00, 00, 8D, 85, E0, FC, FF, FF, 83, C4, 0C, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC...
 
[+]

Entropy:
2.6653

Code size:
325 KB (332,800 bytes)

Remove executer.exe - Powered by Reason Core Security