updater.exe

Kemeda

The executable updater.exe has been detected as malware by 21 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler named Updater triggered to execute each time a user logs in.
Publisher:
Kemeda  (signed and verified)

Version:
12.38.25.9

MD5:
36bcd4c10c9d4ef371f6aa009af547b9

SHA-1:
35f9a19c3a776005769b40730ef2ab510679bb20

SHA-256:
fc11b0a176528d2d1407ce5c6eed2a3d05b25ead9a886fd59a327785abe3adb2

Scanner detections:
21 / 68

Status:
Malware

Analysis date:
12/28/2024 4:40:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2877983
437

Avira AntiVirus
TR/Dropper.MSIL.226113
8.3.2.2

Arcabit
Trojan.Generic.D2BEA1F
1.0.0.597

avast!
Win32:Evo-gen [Susp]
2014.9-151124

AVG
MSIL9
2016.0.2915

Baidu Antivirus
Trojan.MSIL.Injector
4.0.3.151124

Bitdefender
Trojan.GenericKD.2877983
1.0.20.1640

Dr.Web
Trojan.DownLoader17.15248
9.0.1.0328

Emsisoft Anti-Malware
Trojan.GenericKD.2877983
8.15.11.24.01

ESET NOD32
MSIL/Injector.MTF (variant)
9.12587

Fortinet FortiGate
MSIL/Injector.MTF!tr
11/24/2015

F-Secure
Trojan.GenericKD.2877983
11.2015-24-11_3

G Data
Trojan.GenericKD.2877983
15.11.25

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.17897

Kaspersky
Trojan.MSIL.Inject
14.0.0.1072

McAfee
Artemis!36BCD4C10C9D
5600.6571

MicroWorld eScan
Trojan.GenericKD.2877983
16.0.0.984

Panda Antivirus
Trj/GdSda.A
15.11.24.01

Qihoo 360 Security
QVM03.0.Malware.Gen
1.0.0.1077

Sophos
Mal/Generic-S
4.98

File size:
1.1 MB (1,185,256 bytes)

Product version:
12.38.25.9

Original file name:
kcl.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\updater.exe

Digital Signature
Signed by:

Authority:
Kemeda

Valid from:
10/21/2015 11:07:25 PM

Valid to:
10/21/2016 11:07:25 PM

Subject:
CN=www.kemeda.pt, O=Kemeda, L=Lisboa, S=Lisboa, C=PK

Issuer:
CN=www.kemeda.pt, O=Kemeda, L=Lisboa, S=Lisboa, C=PK

Serial number:
008C6590B70633A028

File PE Metadata
Compilation timestamp:
11/16/2015 3:46:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
80.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:kCJCiwNa6xPbyfRMFSfu/8gjCW3xsgpfEKmjAXAePo6slKA/W0pW:k0NwY6RlWuUgBmgpsKtXAzq

Entry address:
0xC7DDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 70, 00, 00, 80, 10, 00, 00, 00, 88, 00, 00, 80, 18, 00, 00, 00, A0, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00, 06, 00, 00, 00, 00, 00, B8, 00, 00, 80, 01, 00, 00, 00, D0, 00, 00, 80, 02, 00, 00, 00, E8, 00, 00, 80, 03, 00, 00, 00, 00, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
791.5 KB (810,496 bytes)

Scheduled Task
Task name:
Updater

Path:
\Update\Updater

Trigger:
Logon (Runs on logon)


Remove updater.exe - Powered by Reason Core Security