ksmoney.exe

Astonsoft DeepBurner

MALITEK

The application ksmoney.exe by MALITEK has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Astonsoft  (signed by MALITEK)

Product:
Astonsoft DeepBurner

Version:
1.9.0.228

MD5:
bffa1ee70adc00d6a8a047617b7b670f

SHA-1:
1011ad0e48c69cad88b4fae1f0b74f51fa45f6e9

SHA-256:
90d1d0f5914857603f2c2ff23194824c1ae30bfec0fdf503176873c777868a35

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/2/2024 5:25:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallMonster (M)
17.3.4.0

File size:
2.7 MB (2,856,888 bytes)

Product version:
1.8

Copyright:
Astonsoft (c) 2002 - 2006

Original file name:
DeepBurner.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ksmoney.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/12/2016 4:00:00 AM

Valid to:
3/13/2017 3:59:59 AM

Subject:
CN=MALITEK, O=MALITEK, STREET="Gazovikov, 30, 160", L=Tyumen, S=RU, PostalCode=625022, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EE626B9BCE0A4EB8C590A5CF0E187D8D

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

Entry address:
0x76D000

Entry point:
FC, 50, B8, A4, CF, B6, 00, 83, C0, 70, 50, C3, C2, 08, 00, B9, 20, 10, 00, 00, B8, 01, 00, 00, 00, 8B, 90, 98, A3, B6, 00, 0F, B6, 12, 80, EA, B1, 83, EA, 07, 0B, D2, 75, 20, FF, 15, 4B, C2, B6, 00, FF, 15, 4B, C2, B6, 00, 0F, AA, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, E9, F5, 06, 00, 00, DA, 81, E9, DB, E3, AC, 00, E9, A3, 06, 00, 00, 98, 15, 97, 51, EB, 14, 6F, DC, B8, 9D, EB, 03, 9C, EB, 01, C3, 81, 6C, 24, 04, 28, 10, A4, A0, EB, EF, 68, 7B, E7, 5A, A1, EB, EB, EE, 2D...
 
[+]

Code size:
648.5 KB (664,064 bytes)

Remove ksmoney.exe - Powered by Reason Core Security