{26602c53-5ba4-4d60-bc9e-02ab64d48091}

The file {26602c53-5ba4-4d60-bc9e-02ab64d48091} has been detected as malware by 29 anti-virus scanners.
Publisher:
Microsoft*  (Invalid match)

Product:
Microsoft

Version:
1.0.0.0

MD5:
617979206bd8c5f55dc02a1ecaae234b

SHA-1:
399211f8be81fb2f75f97317901d819e076dda08

SHA-256:
1e187fa644dc5aa7506e17f25d11870542080916db507611ea14bc2f9007dfde

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
4/27/2024 2:58:25 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Heur.MSIL.Krypt.2
856

Agnitum Outpost
Trojan.Blacks.Gen.LJ
7.1.1

Avira AntiVirus
TR/Dropper.MSIL.Gen
7.11.171.112

avast!
MSIL:Downloader-LX [Trj]
2014.9-141002

AVG
ILCrypt
2015.0.3334

Baidu Antivirus
Trojan.Win32.Foxhiex
4.0.3.14102

Bitdefender
Gen:Heur.MSIL.Krypt.2
1.0.20.1375

Comodo Security
TrojWare.Win32.Agent.TRE
19469

Dr.Web
BackDoor.Bladabindi.1702
9.0.1.0275

Emsisoft Anti-Malware
Gen:Heur.MSIL.Krypt
8.14.10.02.03

ESET NOD32
MSIL/Autorun.Agent.CA (variant)
8.10390

F-Secure
Gen:Heur.MSIL.Krypt.2
11.2014-02-10_5

G Data
Gen:Heur.MSIL.Krypt
14.10.24

IKARUS anti.virus
Worm.MSIL.Autorun
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13319

Kaspersky
Trojan.Win32.Foxhiex
14.0.0.3164

Malwarebytes
Trojan.Dropper
v2014.10.02.03

McAfee
RDN/Autorun.worm!dm
5600.6990

Microsoft Security Essentials
HackTool:Win32/BrowserPassview
1.10904

MicroWorld eScan
Gen:Heur.MSIL.Krypt.2
15.0.0.825

NANO AntiVirus
Trojan.Win32.Foxhiex.deoejy
0.28.2.61942

Panda Antivirus
Trj/Chgt.E
14.10.02.03

Qihoo 360 Security
Win32/Trojan.d60
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.173F8725!390039333
23.00.65.14930

Sophos
Mal/MSIL-BA
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-GameJack
10325

Trend Micro House Call
TROJ_GEN.R08NC0FI614
7.2.275

Trend Micro
TROJ_GEN.R08NC0FI614
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic
32960

File size:
485 KB (496,640 bytes)

Product version:
1.0.0.0

Copyright:
Microsoft

Trademarks:
Microsoft

Original file name:
svchost.exe

File PE Metadata
Compilation timestamp:
8/31/2014 7:00:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:M+P0Rhc9iHfc1MUNheqhhRtzCUxIPeLBV9:M+PLo/+rHFxCUxI6

Entry address:
0x7A9AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
482.5 KB (494,080 bytes)

Remove {26602c53-5ba4-4d60-bc9e-02ab64d48091} - Powered by Reason Core Security