keygen.exe

The application keygen.exe has been detected as a potentially unwanted program by 23 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from s6042.chomikuj.pl and multiple other hosts.
MD5:
f3552fe22b3d200387ea1decd15d5c6f

SHA-1:
b93ed1c06e175ff27c567be381380d5db79367dd

SHA-256:
b7661ac172a71b88e782c0ac936c7197e83b4a429d90b5f4445a80afca4cffb5

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
2/26/2025 6:00:34 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.6833980
567

Agnitum Outpost
Trojan.Offend
7.1.1

Avira AntiVirus
TR/Offend.6833980
3.6.1.96

AVG
Generic9_c
2016.0.3045

Bitdefender
Trojan.Generic.6833980
1.0.20.990

Emsisoft Anti-Malware
Trojan.Generic.6833980
8.15.07.17.08

F-Secure
Trojan.Generic.6833980
11.2015-17-07_6

G Data
Trojan.Generic.6833980
15.7.25

IKARUS anti.virus
not-a-virus.Keygen.PCTools
t3scan.1.8.9.0

Malwarebytes
RiskWare.Tool.CK
v2015.07.17.08

McAfee
Generic.dx!F3552FE22B3D
5600.6701

Microsoft Security Essentials
1.1.11602.0

MicroWorld eScan
Trojan.Generic.6833980
16.0.0.594

NANO AntiVirus
Trojan.Win32.Offend.ineje
0.30.24.1357

Norman
Suspicious_Gen2.SMSTW
11.20150717

nProtect
Trojan.Generic.6833980
15.05.08.01

Rising Antivirus
PE:Trojan.Win32.Generic.134235E8!323106280
23.00.65.15715

Sophos
Keygen
4.98

SUPERAntiSpyware
Trojan.Agent/Generic
9747

Trend Micro House Call
CRCK_KEYGEN
7.2.198

Trend Micro
CRCK_KEYGEN
10.465.17

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
40126

ViRobot
Trojan.Win32.S.Agent.55808.EP[h]
2014.3.20.0

File size:
54.5 KB (55,808 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pc.tools.registry.mechanic.v11.0.0.277.multilingual.winall.incl.keygen.and.patch-brd\keygen\keygen.exe

File PE Metadata
Compilation timestamp:
4/12/2011 11:07:41 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:kLjZdl2NiuK2Boks2NisW8uEEixZuCcgEgSX:kZ2rK2lQsW8uEjcTgS

Entry address:
0x412F0

Entry point:
60, BE, 00, 50, 43, 00, 8D, BE, 00, C0, FC, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
52 KB (53,248 bytes)

The file keygen.exe has been seen being distributed by the following 2 URLs.

http://s6042.chomikuj.pl/File.aspx?e=tQarEXQOE2WhHV2uVH-9eHZezavfLHcjkNyEVjBABJIeU2CCaFlKYq8jApUICKX3skjtd8JI13aqbUhihXg-mmoi8gYt6UwSqzKwU6q39R4RSO7qIfLwkMvGhSCGhn5S_bTyCz21n3YCViPdCE-Bmw&pv=2

Remove keygen.exe - Powered by Reason Core Security