limeprosetup.exe

Lime PRO

The executable limeprosetup.exe, “Lime PRO Setup ” has been detected as malware by 16 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from limewirefreedownload.org.
Publisher:
Lime PRO

Product:
Lime PRO

Description:
Lime PRO Setup

Version:
3.0.1.0

MD5:
84dd9d54a9d069061672bfaa9df90ba9

SHA-1:
1db709b70a1969a13ed736e192437a18319cca07

SHA-256:
98f209b07499d77add2bf81e772cec4f7e579562296ec6750737ede7119f805b

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
12/26/2024 1:23:29 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.6953206
194

Avira AntiVirus
TR/ATRAPS.Gen
7.11.210.134

avast!
Win32:Dropper-gen [Drp]
2014.9-160725

AVG
Generic27
2017.0.2672

Bitdefender
Trojan.Generic.6953206
1.0.20.1035

Bkav FE
HW32.Packed
1.3.0.6379

Emsisoft Anti-Malware
Trojan.Generic.6953206
8.16.07.25.02

ESET NOD32
Generik.HSAQSJJ (variant)
10.11184

F-Secure
Trojan.Generic.6953206
11.2016-25-07_2

G Data
Trojan.Generic.6953206
16.7.25

McAfee
Artemis!84DD9D54A9D0
5600.6328

MicroWorld eScan
Trojan.Generic.6953206
17.0.0.621

Qihoo 360 Security
Win32/Trojan.Dropper.ffe
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R0CBC0EGR14
7.2.207

Trend Micro
TROJ_GEN.R0CBC0EGR14
10.465.25

VIPRE Antivirus
Trojan.Win32.Generic
37618

File size:
3.4 MB (3,533,824 bytes)

Product version:
3.0.1.0

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\limeprosetup.exe

File PE Metadata
Compilation timestamp:
7/23/2011 1:06:12 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:H/cVIsnqy7oFlpDgAH5cHdeqHDvob6ht+BRE3v6SR:H/c/nusAZcHd5HDvouuLE/6SR

Entry address:
0x103E

Entry point:
55, 8B, EC, 83, E4, F8, 81, EC, EC, 03, 00, 00, 53, 56, 57, FF, 15, 40, 20, 40, 00, 50, 33, DB, 53, 6A, 10, FF, 15, 10, 20, 40, 00, 53, 89, 44, 24, 18, FF, 15, 38, 20, 40, 00, 8B, 35, 1C, 20, 40, 00, 53, 8B, F8, 6A, 40, 8D, 84, 24, B8, 00, 00, 00, 50, 57, FF, 74, 24, 24, FF, D6, 03, BC, 24, EC, 00, 00, 00, 53, 68, F8, 00, 00, 00, 8D, 84, 24, 00, 02, 00, 00, 50, 57, FF, 74, 24, 24, FF, D6, 33, C0, 81, C7, F8, 00, 00, 00, 89, 5C, 24, 1C, 66, 3B, 84, 24, FE, 01, 00, 00, 0F, 83, 3B, 02, 00, 00, 53, 6A, 28, 8D...
 
[+]

Entropy:
7.9879

Developed / compiled with:
Microsoft Visual C++

Code size:
1024 Bytes (1,024 bytes)

The file limeprosetup.exe has been seen being distributed by the following URL.

Remove limeprosetup.exe - Powered by Reason Core Security