2sbug.exe

XerosSecurityProtection

Max Programming, S.L.

The executable 2sbug.exe has been detected as malware by 29 anti-virus scanners.
Publisher:
Max Programming, S.L.  (signed and verified)

Product:
XerosSecurityProtection

Version:
1.00

MD5:
f1b4a90955078130bf0ee676b1866151

SHA-1:
ba5a5358436eb2b4b6a69a21ae6682f16fa904d5

SHA-256:
fd167c769c395fd1022e6dcb78ef2d1d6e198f215e5b7939d38742c364ce1383

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
4/25/2024 8:37:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.15587875
362

Avira AntiVirus
TR/Special.428216
8.3.2.4

Arcabit
Trojan.Generic.DEDDA23
1.0.0.646

avast!
Win32:Malware-gen
2014.9-160208

AVG
MSIL9
2017.0.2840

Bitdefender
Trojan.Generic.15587875
1.0.20.195

Bkav FE
HW32.Packed
1.3.0.7400

Comodo Security
UnclassifiedMalware
24003

Dr.Web
Trojan.DownLoader18.42877
9.0.1.039

Emsisoft Anti-Malware
Trojan.Generic.15587875
8.16.02.08.11

ESET NOD32
MSIL/Agent.ABP
10.12913

Fortinet FortiGate
W32/Agent.ABLZF!tr
2/8/2016

F-Secure
Trojan.Generic.15587875
11.2016-08-02_2

G Data
Trojan.Generic.15587875
16.2.25

IKARUS anti.virus
Trojan.MSIL.Agent
t3scan.2.0.3.0

K7 AntiVirus
Trojan
13.212.18514

Kaspersky
Trojan.MSIL.Agent
14.0.0.693

McAfee
RDN/Generic PWS.y
5600.6496

Microsoft Security Essentials
TrojanSpy:MSIL/Omaneat.B
1.1.12400.0

MicroWorld eScan
Trojan.Generic.15587875
17.0.0.117

NANO AntiVirus
Trojan.Win32.DownLoader18.dzoapp
1.0.14.5380

nProtect
Trojan.Generic.15587875
16.01.22.01

Panda Antivirus
Trj/CI.A
16.02.08.11

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16206

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R00UC0DA916
10.465.08

Vba32 AntiVirus
TScope.Trojan.VB
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
46708

File size:
418.2 KB (428,216 bytes)

Product version:
1.00

Original file name:
fsgrdgrtg.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\users\{user}\appdata\local\temp\2sbug.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/20/2012 2:00:00 AM

Valid to:
2/20/2017 1:59:59 AM

Subject:
CN="Max Programming, S.L.", O="Max Programming, S.L.", STREET="C/La Mar, 4", L=Denia, S=Alicante, PostalCode=03700, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FAFEFEA51201FA249373E0FA2EAED4C9

File PE Metadata
Compilation timestamp:
1/3/2016 10:39:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:NwCocecSI9zWZg0+pTk4cTmBAytNHpQLbMFeyb89r9O4qA3T6:yCo5gzWZT+p44eQt9YbPt6+6

Entry address:
0x1814

Entry point:
68, 10, 1A, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, E0, 5D, DA, 4D, 39, A2, 4D, 4A, A0, 92, A9, 29, D6, 07, E6, 93, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 75, 74, 65, 20, 56, 42, 58, 65, 72, 6F, 73, 53, 65, 63, 75, 72, 69, 74, 79, 50, 72, 6F, 74, 65, 63, 74, 69, 6F, 6E, 00, 00, 00, 00, 00, 01, 00, 01, 00, A0, 29, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 24, 2A, 40, 00, 98, 20, 41, 00, 00, 00, 00, 00, B0, 71, 35, 00...
 
[+]

Entropy:
6.7718

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
400 KB (409,600 bytes)

Remove 2sbug.exe - Powered by Reason Core Security