tloayikawi1c.exe

VMware Tools

Inergen

The executable tloayikawi1c.exe, “VMware HGFS Client” has been detected as malware by 1 anti-virus scanner.
Publisher:
VMware, Inc.  (signed by Inergen)

Product:
VMware Tools

Description:
VMware HGFS Client

Version:
9.6.2.31837

MD5:
f9bed5ec03819938f7cb2fa0fc1fb399

SHA-1:
06df7a10cfd662e55f3e7c749a31d5e926f502e1

SHA-256:
d50699dac5b244649990d3363a621a68b2a9c0d49a1b9c48d5ac5c8d1e50789c

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/29/2024 6:29:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.9.5

File size:
560 KB (573,480 bytes)

Product version:
9.6.2 build-1688356

Copyright:
Copyright © 1998-2014 VMware, Inc.

Original file name:
hgfsclient.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\tloayikawi1c.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/24/2016 9:00:00 PM

Valid to:
5/25/2017 8:59:59 PM

Subject:
CN=Inergen, O=Inergen, STREET="AVENUE VOLGOGRAD, House 93, Building 2, ROOM II ROOM 12,", L=Moscow, S=Moscow, PostalCode=109117, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C9BE03B759B3C958ED3BBFB001506309

File PE Metadata
Compilation timestamp:
6/19/2016 5:00:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, B8, 03, 00, 00, 68, 51, 06, 00, 00, 6A, 00, FF, 15, E0, A0, 48, 00, 50, FF, 15, E4, A0, 48, 00, 68, 4C, B0, 48, 00, 8B, 45, EC, 50, FF, 15, F4, A0, 48, 00, 68, 9D, 15, 00, 00, 8B, 0D, 14, B9, 48, 00, 51, FF, 15, F8, A0, 48, 00, 85, C0, 74, 07, 33, C0, E9, F6, 01, 00, 00, 8B, 55, F4, 81, EA, D3, 6B, AA, 04, 89, 55, EC, 8B, 45, F0, 8B, 4D, EC, D3, E0, 89, 45, F0, 8B, 4D, F4, 81, C1, 31, 1E, 83, 10, 89, 4D, F8, 68, 51, 06, 00, 00, 6A, 00, FF, 15, E0, A0, 48, 00, 50, FF, 15, E4, A0, 48, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
547.5 KB (560,640 bytes)

Remove tloayikawi1c.exe - Powered by Reason Core Security