nsqe17d.tmpfs

The file nsqe17d.tmpfs has been detected as a potentially unwanted program by 19 anti-malware scanners. The file has been seen being downloaded from d3jydz90x0ejp8.cloudfront.net.
MD5:
d781629b36430b5b847eb830fee6061d

SHA-1:
c591476da6a9be9cad820fccb758bd599f095509

SHA-256:
89a89152dd5ebc30fb252e5bf75629a54b3320f6b02e7387beafee6c9a85bcbe

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 6:51:01 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1214204
558

Avira AntiVirus
ADWARE/AdService.122368.3
3.6.1.96

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150727

AVG
Generic_r
2016.0.3036

Baidu Antivirus
Adware.Win32.AdService
4.0.3.15727

Bitdefender
Application.Generic.1214204
1.0.20.1040

Comodo Security
ApplicUnwnt
21558

Dr.Web
Adware.ClickMeIn.459
9.0.1.0208

ESET NOD32
Win32/Adware.AdService.BI (variant)
9.11387

Fortinet FortiGate
Riskware/Agent
7/27/2015

F-Secure
Application.Generic.1214204
11.2015-27-07_2

G Data
Application.Generic.1214204
15.7.25

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.1673

MicroWorld eScan
Application.Generic.1214204
16.0.0.624

Panda Antivirus
Generic Suspicious
15.07.27.10

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Adware.AdService
16.1.3.23

Sophos
Generic PUA MF
4.98

Trend Micro House Call
TROJ_GEN.R047H07CQ15
7.2.208

File size:
119.5 KB (122,368 bytes)

Common path:
C:\users\{user}\appdata\roaming\3b11637c-1426865503-11db-8000-4e45435f4349\nsqe17d.tmpfs

File PE Metadata
Compilation timestamp:
3/20/2015 3:57:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:1rtrC6Bn14Ba/Mv2eKySHxTZJSkHWDHXRHgl0Xn3Bm9sIt1pVGS:1oc4Ba/m5MVJxWjhHXmyCVGS

Entry address:
0x77AB

Entry point:
E8, 17, 3B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, A4, DC, 41, 00, FF, 15, D0, 70, 41, 00, 85, C0, 75, 18, 56, E8, B3, 04, 00, 00, 8B, F0, FF, 15, 84, 70, 41, 00, 50, E8, 63, 04, 00, 00, 59, 89, 06, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, CC, 72, 41, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0...
 
[+]

Code size:
88 KB (90,112 bytes)

The file nsqe17d.tmpfs has been seen being distributed by the following URL.

Remove nsqe17d.tmpfs - Powered by Reason Core Security