prvtzd_dup.exe

The application prvtzd_dup.exe has been detected as a potentially unwanted program by 22 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. Also know as BrowserDefender, this bundled service will prevent various web browser toolbars and extensions from running as well as block changes to the search page and provider. The file has been seen being downloaded from i1.magnipic.info and multiple other hosts a known adware distribution point operated by WEB PICK - INTERNET HOLDINGS LTD.
MD5:
00f2c3ab92ee1cb7d59d0bc7f9e31641

SHA-1:
cd1d150bb93ea4b83e86d6cfe3682c60ce9b4361

SHA-256:
de19819e773d8a2eabff42af07447ab70ed301f8442e71abd5efff351f2e5eff

Scanner detections:
22 / 68

Status:
Potentially unwanted

Explanation:
This service will prevent resources from modifying the web browser's home and search pages as well as the search provider set by the product, an affiliate search engine partner.

Analysis date:
12/26/2024 1:51:08 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Backdoor.Hupigon
7.1.1

avast!
NSIS:SProtector-A [PUP]
2014.9-131224

AVG
BackDoor.Hupigon6
2014.0.3615

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.131224

Bitdefender
Adware.Generic.513696
1.0.20.1790

Bkav FE
W32.Clod5bf.Trojan
1.3.0.4562

Comodo Security
UnclassifiedMalware
17305

Dr.Web
Adware.BGuard.11
9.0.1.0358

Emsisoft Anti-Malware
Adware.Generic.513696
8.13.12.24.02

ESET NOD32
Win32/SProtector
7.9073

F-Secure
Gen:Variant.Adware.BHO.Bprotector.1
11.2013-24-12_3

G Data
Adware.Generic.513696
13.12.22

IKARUS anti.virus
Backdoor.Win32.Hupigon
t3scan.2.2.29

K7 AntiVirus
Riskware
13.174.10263

McAfee
Artemis!00F2C3AB92EE
5600.7271

MicroWorld eScan
Adware.Generic.513696
14.0.0.1074

NANO AntiVirus
Trojan.Win32.Hupigon.bofczx
0.28.0.56316

Norman
Suspicious_Gen4.DQWWF
11.20131224

Rising Antivirus
Trojan.Win32.Generic.146E0050
23.00.65.131222

Vba32 AntiVirus
Backdoor.Hupigon
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
23556

ViRobot
Backdoor.Win32.A.Hupigon.1584068
2011.4.7.4223

File size:
1.5 MB (1,584,068 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\prvtzd_dup.exe

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:sumWM9ZDmrOzZMVowcbkv4KSvfENXvX/5fXf0KVWM9ZDmrOzZMVows:IirlVoMv4KSv8V/FXxFirlVof

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9924

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file prvtzd_dup.exe has been seen being distributed by the following 2 URLs.

Remove prvtzd_dup.exe - Powered by Reason Core Security