fg742p.exe

Dynamic Internet Technology Inc.

This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘~babvwbt’. This executable runs as a local area network (LAN) Internet proxy server listening on port 8580. The file has been seen being downloaded from www.techspot.com and multiple other hosts.
Publisher:
Dynamic Internet Technology, Inc.  (signed by Dynamic Internet Technology Inc.)

Description:
Fast and Secure Gateway to Internet Freedom

Version:
7, 4, 2, 0

MD5:
df4b6036a089ac6fa2b0607c32c6ecfd

SHA-1:
23e14d1643ee2f471d8d62517516f1584985b4c5

SHA-256:
430933c383402152618a80e445d8ff48a13f29b487428a06abdc78d10f96a163

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 12:19:41 AM UTC  (today)

File size:
2 MB (2,115,360 bytes)

Product version:
0, 0, 0, 0

Copyright:
Copyright (C) 2003-2010

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\fg742p.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/15/2013 11:31:38 PM

Valid to:
8/27/2016 2:41:17 AM

Subject:
CN=Dynamic Internet Technology Inc., O=Dynamic Internet Technology Inc., L=Cary, S=NC, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F8866DEA7F7DB229FC28783E06844CDE

File PE Metadata
Compilation timestamp:
11/8/2013 11:32:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:qRGHGtXhYVTM6kRWUs9gMBr/85NdrmczSKXy86bKu2Hosx3:MhWTk7MrKHFiJbKuio+

Entry address:
0xA9FD3

Entry point:
52, BA, 64, 00, 00, 00, 85, D2, 74, 1D, B9, 00, 10, 00, 00, 85, C9, 74, 07, 01, C8, 01, D8, 49, EB, F5, 52, 54, 54, FF, 15, 33, 40, 5D, 00, 5A, 4A, EB, DF, 5A, E9, 00, B0, 48, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 06, 00, C8, 11, 00, 80, 48, 00, 00, 80, 03, 00, 00, 00, 78, 00, 00, 80, 04, 00, 00, 00, D8, 00, 00, 80, 05, 00, 00, 00, F0, 00, 00, 80, 06, 00, 00, 00, C0, 01, 00, 80, 0E, 00, 00, 00, 90, 02, 00, 80, 10, 00, 00, 00, B8, 02, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9492  (probably packed)

Code size:
1.1 MB (1,183,744 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:8580/

Local host port:
8580

Default credentials:
No


7 Startup Files (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
~babvwbt

Command:
C:\users\{user}\downloads\fg742p.exe

Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Oclaphpl

Command:
C:\users\{user}\downloads\programs\fg742p.exe

Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
~lfqtqyk

Command:
C:\users\{user}\desktop\fg742p.exe

Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
~rexzern

Command:
C:\data\fg742p.exe

Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Ywaqsajc

Command:
C:\users\{user}\downloads\92-8-28\filter\fg742p.exe

Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
~xdcrzxq

Command:
C:\users\{user}\desktop\programs\fg742p.exe


33 Windows Firewall Allowed Programs
Name:
C:\Documents and Settings\an\Desktop\Az\fg742p.exe

Name:
J:\program\fg742p.exe

Name:
F:\Freegate\fg742p.exe

Name:
F:\motfarege\software\fg742p.exe

Name:
D:\filterr\fg742p.exe

Name:
N:\freegate\fg742p.exe


The file fg742p.exe has been discovered within the following program.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
 
Powered by Should I Remove It?

The file fg742p.exe has been seen being distributed by the following 50 URLs.

http://www.techspot.com/downloads/downloadnow/.../?evp=6058390475ec30d4d688e4f4791b4a8e&file=1

http://www.techspot.com/downloads/downloadnow/.../?evp=6c8065dabaf305a1353b22f5790fdf53&file=1

https://d4c2us8g123wy.cloudfront.net/.../Freegate742.exe

http://s5.picofile.com/d/.../www_farshid2013_blogsky_com.exe

http://www.techspot.com/downloads/downloadnow/.../?evp=689d2c2725621b3ca235313f1a6f57a5&file=1

http://s5.picofile.com/d/.../fg742_www_yakamuz_ir_.exe

https://us-mg6.mail.yahoo.com/.../download?mid=2_0_0_3_15558_ALaki2IAACKdUrnUyfC9wBgFqBw&fid=Draft&pid=11&clean=0&appid=YahooMailNeo

https://mega.nz/temporary/.../kZ0SDBTJ

http://www.uplooder.net/.../dl.cgi?key=7e0b4f9dff08199d068ba2f34a1fd2b8

https://mg.mail.yahoo.com/.../download?m=YaDownload&mid=2_0_0_1_294501_AKVUfbwAABU9U95rNwAAAGvpc10&fid=Inbox&pid=2&clean=0&appid=YahooMailNeo

https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjJ-DF0fLhhg7KjBG3HNzpiwVk6MRXIBbyTVDFrY5L317MQJxgCqvH42SpLAbtjaqFcw/messages/@.id==AEnuw0MAAA8aVGb7wQabaPMjzAM/content/parts/@.id==2/raw?appid=YahooMailNeo&token=zitEzqOML3j84e6ealFTT5U7-km5qEQF52lp7AcCuBbdAKmC9RUwgIbJT3WFEktnqpmI6CWd7zCKVF8OHXsdJhflP-YvqMPCYv4BRcX1I1kGYHG5zZROOYeWZBW-NzAx&error=https://mg.mail.yahoo.com/.../iframemsg?id=37775b05-c3a6-2421-ed8d-87949381e154&ymreqid=e6dfa601-791a-58fe-0103-53004b010000

http://www.techspot.com/downloads/downloadnow/.../?evp=549a6039e123089f308d8b500f93f1e4&file=1

http://www.uplooder.net/.../dl.cgi?key=d6405786efa9d56ba68fcefff0f7f1b1

https://mg.mail.yahoo.com/.../download?m=YaDownload&mid=2_0_0_2_232094_AKx2imIAABKhU9SQ1QAAAHcJsYs&fid=Sent&pid=2&clean=0&appid=YahooMailNeo

http://s5.picofile.com/d/.../fg742p.exe

&onid=2085&oid=3001-2085_4-10415391&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=networking/network-tools&topicbrcrm=&pid=13484776&mfgid=6273410&merid=6273410&ctype=dm&cval=SPIGOTWIN&devicetype=desktop&pguid=6a53fb40044fe2280491bb0e&viewguid=XCPAJ-HFn2TvJilAV9K3bxX4PsfwCYp4uxMd&destUrl=http://software-files-a.cnet.com/s/software/13/48/47/.../fg742p.exe

Latest 30 of 64 download URLs

Scan fg742p.exe - Powered by Reason Core Security