sys32.exe

Kemeda

The executable sys32.exe has been detected as malware by 19 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler named System triggered to execute each time a user logs in.
Publisher:
sorx  (signed by Kemeda)

Product:
sorx

Version:
25.4.13.666

MD5:
4fc634517160b52bd26d47c2eabed57b

SHA-1:
3ee93f6e2003cd46333f875e907f0c49b1131f66

SHA-256:
82a60f43d4c3d3f5e84bdb07d9888964ebf879cbbc6001380a6f1e91de0cd712

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
12/28/2024 3:56:04 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.221492
8.3.2.2

Arcabit
Trojan.Zusy.D2906F
1.0.0.590

avast!
Win32:Malware-gen
2014.9-151210

AVG
MSIL9
2016.0.2900

Baidu Antivirus
Trojan.Win32.SelfDel
4.0.3.151210

Bitdefender
Gen:Variant.Zusy.168047
1.0.20.1720

Dr.Web
Trojan.PWS.Siggen1.39314
9.0.1.0344

Emsisoft Anti-Malware
Gen:Variant.Zusy.168047
8.15.12.10.03

ESET NOD32
MSIL/Injector.MMH (variant)
9.12532

Fortinet FortiGate
MSIL/Injector.MMH!tr
12/10/2015

F-Secure
Gen:Variant.Zusy.168047
11.2015-10-12_5

G Data
Gen:Variant.Zusy.168047
15.12.25

Kaspersky
Trojan.Win32.SelfDel
14.0.0.994

McAfee
Artemis!4FC634517160
5600.6556

MicroWorld eScan
Gen:Variant.Zusy.168047
16.0.0.1032

Panda Antivirus
Trj/CI.A
15.12.10.03

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.151208

Sophos
Mal/Generic-S
4.98

File size:
446.5 KB (457,168 bytes)

Product version:
25.4.13.666

Copyright:
sorx

Trademarks:
sorx

Original file name:
sorx.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\sys32.exe

Digital Signature
Signed by:

Authority:
Kemeda

Valid from:
10/21/2015 2:07:25 PM

Valid to:
10/21/2016 2:07:25 PM

Subject:
CN=www.kemeda.pt, O=Kemeda, L=Lisboa, S=Lisboa, C=PK

Issuer:
CN=www.kemeda.pt, O=Kemeda, L=Lisboa, S=Lisboa, C=PK

Serial number:
008C6590B70633A028

File PE Metadata
Compilation timestamp:
10/30/2015 12:11:20 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
80.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:JNu8FJtCxdEQhI+n0uHUmdW+9y9d+AdyOvAwC2VHZIRhTsRVFVTDwi27336sB:jtJtCxbW+n0uHKxyEAwKrTsN5J273X

Entry address:
0x7092E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1167

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
442.5 KB (453,120 bytes)

Scheduled Task
Task name:
System

Path:
\Update\System

Trigger:
Logon (Runs on logon)


Remove sys32.exe - Powered by Reason Core Security