resildjglaifg.exe

The application resildjglaifg.exe has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from www.pluketech.com.
MD5:
5acfb651f7a499de0ca668aa5b89ee48

SHA-1:
38a8042373011d29a001e6026e42c67af9234659

SHA-256:
22ffa1013713123f822bfbbb0213f8e0adbea8c127dd1743b996e824ac505adc

Scanner detections:
14 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 6:44:28 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Application.Bundler.SW
308

AegisLab AV Signature
Uds.Dangerousobject.Multi!c
2.1.4+

AhnLab V3 Security
PUP/Win32.Bundler
2016.03.05

Arcabit
Application.Bundler.SW
1.0.0.656

avast!
Win32:Dropper-gen [Drp]
2014.9-160402

Bitdefender
Dropped:Application.Bundler.SW
1.0.20.465

Dr.Web
Trojan.DownLoader19.29089
9.0.1.093

F-Secure
Application.Bundler.SW
11.2016-02-04_7

G Data
Dropped:Application.Bundler.SW
16.4.25

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.424

McAfee
RDN/Generic.bfr
5600.6442

MicroWorld eScan
Dropped:Application.Bundler.SW
17.0.0.279

Qihoo 360 Security
Trojan.Generic
1.0.0.1120

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
327.6 KB (335,416 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:Gsdqxv6Ah6QvdxIbZ1G20pD7gz507jz2jK47e9ziwVu3za3Oc:O1znGQbgIz2jL7YVazab

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.7779

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file resildjglaifg.exe has been seen being distributed by the following URL.

Remove resildjglaifg.exe - Powered by Reason Core Security