installqrpviewer.exe

QRP Viewer

Responsive Software Limited

The executable installqrpviewer.exe, “Quick Report Viewer ” has been detected as malware by 5 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from localhost and multiple other hosts.
Publisher:
Responsive Software Limited

Product:
QRP Viewer

Description:
Quick Report Viewer

Version:
1.3.0.0

MD5:
b8ef3807de332f58200dfed7e4085101

SHA-1:
68b9a15a2aa4a877f30b1eb543adf81b09a32c03

SHA-256:
96d2e8339da2c377fdf2a7d639bcec0e7863049398895ba5882a53085c16d807

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
2/25/2025 5:32:51 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dldr.Delf.bbab.1
7.11.122.246

AVG
Downloader.Generic12
2015.0.3491

IKARUS anti.virus
Trojan-Downloader.Delf
t3scan.2.2.29

Norman
Delf.LGDO
11.20140428

Rising Antivirus
PE:Trojan.Win32.Generic.12DBE1E9!316400105
23.00.65.14426

File size:
3.6 MB (3,810,771 bytes)

Product version:
1.3.0.0

Copyright:
Copyright (c) 2006 Responsive Software Limited

Original file name:
stub32i.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\installqrpviewer.exe

File PE Metadata
Compilation timestamp:
9/6/2001 2:02:57 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:5VvZE7l3Ist1mEPh+Hs14NvyGJsSHel6L:vvZEdntlh+H84NqGJsKJ

Entry address:
0x8947

Entry point:
55, 8B, EC, 6A, FF, 68, 18, 33, 41, 00, 68, 80, BA, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, E8, 31, 41, 00, 33, D2, 8A, D4, 89, 15, 5C, 63, 41, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 58, 63, 41, 00, C1, E1, 08, 03, CA, 89, 0D, 54, 63, 41, 00, C1, E8, 10, A3, 50, 63, 41, 00, 33, F6, 56, E8, E0, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 11, 2F, 00, 00, FF, 15, EC, 31, 41, 00, A3, 24, 8A, 41, 00, E8...
 
[+]

Entropy:
7.9895

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
72 KB (73,728 bytes)

The file installqrpviewer.exe has been seen being distributed by the following 2 URLs.

http://localhost:37848/continue?TiCredToken=3000&Source=WTP&URL=http://.../InstallQRPViewer.exe&Permanent=1

Remove installqrpviewer.exe - Powered by Reason Core Security