Should I block it?
Yes, 98% block recommendation.
Possible reason:
Multiple malware detections
Relationships
sejal.exe
ysp by Microsoft
Version: | 1.00 |
MD5: | 8d467ad5feda6d2e8f042596cef69f03 |
SHA1: | 8f2061b92be579c43c76099bec48da28d8b2d643 |
SHA256: | 9443c99572e5f2624f27aa9dcdaf86bfd75691815512595a457c8236f6ae35e2 |
Warning 38 antivirus scanners has detected malware.
Overview
sejal.exe is malware that executes as a process with the local user's privileges. During installation, it (or a shortcut) is added to the user's startup folder which is designed to automatically launch when the user logs into Windows. This particular version is usually found on Microsoft Windows XP (5.1.2600.131072).
Details
File name: | sejal.exe |
Publisher: | Microsoft |
Product name: | ysp |
Description: | Photo |
Typical file path: | C:\Documents and Settings\user\Application data\sejal.exe |
Original name: | APS.exe |
File version: | 1.00 |
Size: | 1.24 MB (1,300,480 bytes) |
Build date: | 12/18/1998 1:23 AM |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | Yes |
Code language: | Microsoft Visual Basic |
.NET CLR: | No |
More details
Behaviors
User start menu folder
Shortcut pointer placed in '%appdata%\Microsoft\Windows\Start Menu'
Malware detections
Based on 40+ industry antivirus scanners, 38 of them detected the following malware.
Antivirus engine | Engine version | Detection |
Agnitum |
5.5.1.3 |
Trojan.Cossta!oH5t0Xgl1ZA |
AhnLab V3 Internet Security |
2013.03.12.03 |
Trojan/Win32.Cossta |
Avira AntiVir |
7.11.64.152 |
TR/Dropper.Gen |
Antiy Labs AVL |
2.0.3.7 |
Trojan/Win32.Cossta.gen |
avast! |
6.0.1289.0 |
Win32:Malware-gen |
AVG |
2014.0.3629 |
Generic25.EXH |
BitDefender |
7.2 |
Worm.Generic.370701 |
CAT Quick Heal |
10.13.12.00 |
Worm.Autorun.AE4 |
Comodo Internet Security |
15544 |
Worm.Win32.VB.mrb |
Dr.Web |
8.13.10.15 |
Trojan.DownLoader5.27927 |
Emsisoft Anti-Malware |
3.0.0.569 |
Worm.Generic.370701 (B) |
ESET NOD32 |
7.8107 |
a variant of Win32/AutoRun.VB.ATP |
Fortinet |
5.0.43.0 |
W32/AutoRun.RPV!worm |
F-Secure |
11.0.19020.35 |
Worm.Generic.370701 |
G Data |
13.10.22 |
Worm.Generic.370701 |
Ikarus |
T3.1.4.0.0 |
Worm.Win32.AutoRun |
K7 AntiVirus |
9.163.8344 |
Trojan |
Kaspersky |
9.0.0.837 |
Trojan.Win32.Cossta.shu |
Kingsoft |
2013.1.8.219 |
Win32.Troj.Cossta.s.(kcloud) |
Malwarebytes |
1.70.0.9 |
Backdoor.Agent |
McAfee |
5.400.1158 |
Generic PWS.aad |
McAfee Gateway Anti-Malware |
v2012.1-dat |
Generic PWS.aad |
Microsoft Security Essentials |
1.9203.0 |
Worm:Win32/Autorun.AEO |
eScan by MicroWorld |
12.0.250.0 |
Worm.Generic.370701 |
NANO AntiVirus |
0.22.8.51249 |
Trojan.Win32.Cossta.bjjpbe |
Norman |
7.00.22 |
AutoRun.BVJS |
nProtect |
2013-03-12.02 |
Worm.Generic.370701 |
Panda Antivirus |
10.0.3.5 |
Generic Trojan |
PC Tools |
9.0.0.2 |
Trojan.Gen |
Sophos |
4.86.0 |
Mal/Generic-S |
SUPERAntiSpyware |
5.6.0.1008 |
Trojan.Agent/Gen-Autorun |
Symantec |
20121.3.0.76 |
Trojan.Gen |
The Hacker |
None |
Trojan/AutoRun.VB.atp |
Total Defense |
37.0.10329 |
Win32/FakeFLDR_i |
Trend Micro |
9.740.0.1012 |
TROJ_GEN.RCBOCC9 |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_SPNR.05CA13 |
Vba32 AntiVirus |
3.12.20.2 |
Trojan.Cossta.shu |
VIPRE Antivirus |
15998 |
Trojan.Win32.Generic.pak!cobra |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.03870022% | |
Kernel CPU: | 0.01482748% | |
User CPU: | 0.02387274% | |
Kernel CPU time: | 4,359 ms/min | |
Context switches: | 751/sec | |
Memory |
Private memory: | 1.71 MB | |
Private (maximum): | 5.86 MB | |
Private (minimum): | 4.45 MB | |
Non-paged memory: | 1.71 MB | |
Virtual memory: | 42.99 MB | |
Virtual memory (peak): | 45.54 MB | |
Working set: | 5.85 MB | |
Working set (peak): | 5.88 MB | |
Resource allocations |
Threads: | 1 | |
Handles: | 351 | |
GUI GDI count: | 26 | |
GUI USER count: | 14 | |
Process properties
Distribution by Windows OS
OS version | distribution |
Microsoft Windows XP |
100.00% |
|
Distribution by PC manufacturer
PC Manufacturer | distribution |
Intel |
100.00% |
|