malware102

CrystalDiskInfo

Meicun Ge

The file malware102 has been detected as malware by 14 anti-virus scanners.
Publisher:
Crystal Dew World  (signed by Meicun Ge)

Product:
CrystalDiskInfo

Version:
6.2.0.2014

MD5:
a97e6b7de260c809b6d8006ec651f100

SHA-1:
055303c245f97517c00aaed85f803645e7d9dcee

SHA-256:
499482215cf80fcbba693e314d4b382829fdca9cd1abc102e2c4a1548fdbb720

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
12/4/2024 5:48:21 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Mikey.18695
573

Arcabit
Trojan.Mikey.D4907
1.0.0.425

AVG
Generic_r
2016.0.3051

Bitdefender
Gen:Variant.Mikey.18695
1.0.20.960

Emsisoft Anti-Malware
Gen:Variant.Mikey.18695
8.15.07.11.07

ESET NOD32
Win32/Agent.RHL (variant)
9.11925

Fortinet FortiGate
W32/Agent.ARC!tr
7/11/2015

G Data
Gen:Variant.Mikey.18695
15.7.25

IKARUS anti.virus
Trojan.Win32.Agent
t3scan.1.9.5.0

Microsoft Security Essentials
Trojan:Win32/Hitbrovi!dha
1.1.11804.0

MicroWorld eScan
Gen:Variant.Mikey.18695
16.0.0.576

Panda Antivirus
Trj/Genetic.gen
15.07.11.07

Sophos
Mal/Agent-ARC
4.98

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
41920

File size:
369.7 KB (378,584 bytes)

Product version:
6.2.0.2014

Copyright:
Copyright (C) 2008-2014 hiyohiyo. All rights reserved.

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
9/8/2014 9:49:43 AM

Valid to:
9/8/2015 9:49:43 AM

Subject:
E=meicunge@gmail.com, CN="Open Source Developer, meicun ge", O=Meicun Ge, C=CN

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
4FC13D6220C629043A26F81B1CAD72D8

File PE Metadata
Compilation timestamp:
12/12/2014 1:39:19 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:/kZUWdHP1/DXW7nSoGFLzPz5DotEI/5l5kgkN3qAARa7js3XmWF462OhXDprgzq0:8Z/HP1/Dm7TGxdDWhRUgkV7KaBWrFzpW

Entry address:
0x75A90

Entry point:
68, 67, F7, 75, B0, 66, C7, 04, 24, DF, 67, 9C, C7, 44, 24, 04, DC, 7F, B3, 6F, 68, 73, B8, A6, AB, 60, C7, 44, 24, 24, 62, 92, 1F, B8, 9C, 8D, 64, 24, 28, E9, C1, B1, 04, 00, 63, 1A, F3, 47, 28, 9E, E1, C7, 89, 8A, 77, 9B, 78, 92, F0, 99, 76, A6, 51, B1, D5, AA, 85, BA, 43, 97, 7C, A0, D0, 93, B8, BB, 84, BD, BE, 9D, 64, 06, 9C, 17, 87, B2, 20, 8D, E8, 19, 33, F8, 2B, D6, C5, D6, 30, F3, E7, 64, A3, 57, 5E, 18, FC, 45, 44, 03, 72, D3, CA, 4B, E4, 3D, D9, A3, 67, 3C, E5, AF, DB, FA, 0F, E9, CB, 3F, 20, 6A...
 
[+]

Entropy:
7.8931  (probably packed)

Code size:
187 KB (191,488 bytes)

Remove malware102 - Powered by Reason Core Security