server.exe

SmartFTP Client

The executable server.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘6b0f453b62cb0bd5c6541da982a0e3e9’.
Publisher:
Tomb Raider: Anniversary  (signed by SmartFTP Client)

Product:
Tomb Raider: Anniversary

Version:
1.0.9

MD5:
e5c9ee9aac0cdf729efb0a57318a2592

SHA-1:
a60eea7143baf30e1caf4302d28c88b642e06ea1

SHA-256:
d3a09ac29c94418c4688182d7cd0a9fa6517497a92059ae953b8bc39795f5f99

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
1/13/2025 4:20:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Trojan.Server.Zusy (H)
17.2.25.3

File size:
71.9 KB (73,584 bytes)

Product version:
1.0.9

Copyright:
Copyright (C) 2007 Eidos Inc.

Trademarks:
Crystal Dynamics(R), the Crystal Dynamics(R) logo and the Eidos(R) logo are registered trademarks of the Eidos Group of Companies

Original file name:
Server2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\server.exe

Digital Signature
Signed by:

Authority:
SmartFTP Client

Valid from:
1/2/2014 10:56:32 AM

Valid to:
1/2/2114 10:56:32 AM

Subject:
CN=SmartFTP Client

Issuer:
CN=SmartFTP Client

Serial number:
6C7C1723381A15A44161851A894BF545

File PE Metadata
Compilation timestamp:
1/12/2017 2:32:19 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x1260E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
66 KB (67,584 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
6b0f453b62cb0bd5c6541da982a0e3e9

Command:
"C:\users\{user}\appdata\local\temp\server.exe"..


Remove server.exe - Powered by Reason Core Security