patch.exe

The executable patch.exe has been detected as malware by 31 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from s10298.chomikuj.pl.
MD5:
20b432810baa58e2e696a397764eb796

SHA-1:
d4a4b9d61e364d7d58be87e0ccbc43e90d44d740

SHA-256:
b593f8527f81abeb68011d8b65724cef863b72eb88e2cdba4b8e7c99720373ae

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
12/26/2024 4:57:36 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.7607654
394

Agnitum Outpost
HackTool.Patcher
7.1.1

AhnLab V3 Security
Win-Trojan/Xema.variant
2015.11.26

Arcabit
Trojan.Generic.D741566
1.0.0.624

AVG
PSW.Generic6
2017.0.2872

Bitdefender
Trojan.Generic.7607654
1.0.20.35

Clam AntiVirus
Win.Trojan.Hacktool-1440
0.98/21511

Comodo Security
UnclassifiedMalware
23656

Emsisoft Anti-Malware
Trojan.Generic.7607654
8.16.01.07.12

ESET NOD32
Win32/HackTool.Patcher.A potentially unsafe (variant)
10.12624

Fortinet FortiGate
W32/AdbPat.A!tr
1/7/2016

F-Secure
Trojan.Generic.7607654
11.2016-07-01_5

G Data
Trojan.Generic.7607654
16.1.25

IKARUS anti.virus
Virus.HackTool.Win32.VB
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.17972

Malwarebytes
HackTool.Agent
v2016.01.07.12

McAfee
PWS-Mmorpg.gen
5600.6528

Microsoft Security Essentials
1.1.12300.0

MicroWorld eScan
Trojan.Generic.7607654
17.0.0.21

NANO AntiVirus
Trojan.Win32.Bumat.dofqty
0.30.26.4751

nProtect
Trojan/W32.Agent.135168.BS
15.11.25.01

Panda Antivirus
Trj/CI.A
16.01.07.12

Qihoo 360 Security
HEUR/Malware.QVM17.Gen
1.0.0.1077

Quick Heal
HackTool.Patcher.A
1.16.14.00

Sophos
Generic Patcher (PUA)
4.98

Total Defense
Win32/Tnega.AGNL
37.1.62.1

Trend Micro House Call
TROJ_SPNR.38IE14
7.2.7

Trend Micro
TROJ_SPNR.38IE14
10.465.07

VIPRE Antivirus
Trojan.Win32.Patcher.a
45424

ViRobot
Trojan.Win32.S.Agent.135168.UU[h]
2014.3.20.0

Zillya! Antivirus
Tool.Patcher.Win32.2317
2.0.0.2527

File size:
132 KB (135,168 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\adobe\adobe audition 3.0\patch.exe

File PE Metadata
Compilation timestamp:
3/3/2008 7:08:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
3072:hjjo1nGtLyKGS9Whv9vxXlAQYxprn/TaH7r+0UNoqZKUl6j:+ZKGlvto1n/wUNowKUl6

Entry address:
0x2FBE

Entry point:
B8, 10, E8, 4C, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, CC, A1, 52, 0B, F1, 58, AB, 45, 65, 40, 13, FE, B5, 75, FA, 5B, 51, 9E, 47, 4A, 67, 26, DB, 03, 7F, 53, 1F, F1, C7, 08, 92, 9E, A6, BD, F5, A8, 9B, 50, 04, F3, F9, B5, AE, 3E, EF, B9, 46, 1B, 7E, 79, CE, 1A, 6A, 55, 46, 42, 8A, 24, 22, 8B, 34, 09, 3C, B4, 06, 8F, A5, F4, 36, 7F, 2D, 8A, CE, F7, FC, 72, 04, BF, E2, 60, 66, 89, 1C, 96, 9C, C9, 39, E5, EE, 41, 3C, 03, 44...
 
[+]

Packer / compiler:
PECompact v2

Code size:
14 KB (14,336 bytes)

The file patch.exe has been seen being distributed by the following URL.

Remove patch.exe - Powered by Reason Core Security