winseptr.exe

winseptr

The executable winseptr.exe has been detected as malware by 29 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler named winspt triggered to execute each time a user logs in. The file has been seen being downloaded from feidowns.com.
Product:
winseptr

Version:
1.0.0.0

MD5:
be22495bb4faceb5b73fbea15ce58b94

SHA-1:
2b7a73bb617c3df043907186225a463674882ddc

SHA-256:
558303c6fe30ea324b5a04c2e396487606b1701fbbdc5aa5b53215fa7d284ae2

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
11/27/2024 8:50:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.540877
642

Agnitum Outpost
Trojan.PWS.Agent
7.1.1

AhnLab V3 Security
Trojan/Win32.Gen
2015.05.02

avast!
Win32:Agent-AWTD [Trj]
2014.9-150504

AVG
MSIL7
2016.0.3120

Baidu Antivirus
Trojan.Win32.InfoStealer
4.0.3.1554

Bitdefender
Gen:Variant.Kazy.540877
1.0.20.620

Comodo Security
UnclassifiedMalware
21959

Emsisoft Anti-Malware
Gen:Variant.Kazy.540877
8.15.05.04.09

ESET NOD32
MSIL/ExtenBro.AK (variant)
9.11562

Fortinet FortiGate
W32/Agent.AK!tr.pws
5/4/2015

F-Secure
Gen:Variant.Kazy.540877
11.2015-04-05_2

G Data
Gen:Variant.Kazy.540877
15.5.25

IKARUS anti.virus
Trojan.MSIL.ExtenBro
t3scan.1.8.9.0

Kaspersky
Trojan-PSW.Win32.Agent
14.0.0.2093

McAfee
RDN/Generic PWS.y!bdk
5600.6776

MicroWorld eScan
Gen:Variant.Kazy.540877
16.0.0.372

NANO AntiVirus
Trojan.Win32.Agent.dnnlfc
0.30.24.1357

Norman
Agent.BNCYI
11.20150504

Panda Antivirus
Trj/CI.A
15.05.04.09

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Quick Heal
TrojanPSW.Agent.r4
5.15.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.3ABF15
7.2.124

Trend Micro
TROJ_SPNR.3ABF15
10.465.04

Vba32 AntiVirus
TrojanPSW.Agent
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
39850

ViRobot
Trojan.Win32.A.PSW-Agent.602112.I[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Agent.Win32.508400
2.0.0.2163

File size:
588 KB (602,112 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
eklenti.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\winseptr.exe

File PE Metadata
Compilation timestamp:
1/22/2015 5:57:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Xcm8q72xUXce4frmAkxduicBKI+FQl/epc41h5uGXEXSecEiP/3IWVE/uxPciMC:Mm8q72xUXnu9+FQl/ZSnXu/G

Entry address:
0x90FDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 9B, D7, C0, 54, 00, 00, 00, 00, 02, 00, 00, 00, 1C, 01, 00, 00, 1C, 20, 09, 00, 1C, F4, 08, 00, 52, 53, 44, 53, 34, 2E, 08, 7D, BE, D0, 93, 4E, A8, D3, 2E, 30, 7B, 9A, 50, 47, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 63, 61, 73, 74, 69, 67, 65, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 65, 6B, 6C, 65, 6E, 74, 69, 5C, 65, 6B, 6C, 65, 6E, 74, 69, 5C, 6F...
 
[+]

Entropy:
6.1227

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
572 KB (585,728 bytes)

Scheduled Task
Task name:
winspt

Trigger:
Logon (Runs on logon)


The file winseptr.exe has been seen being distributed by the following URL.

Remove winseptr.exe - Powered by Reason Core Security