{38f0d645-0f22-4928-a453-e8307a7a3b75}

Microsoft Visual Studio 2005

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The file {38f0d645-0f22-4928-a453-e8307a7a3b75}, “Visual Studio Macros” has been detected as malware by 35 anti-virus scanners.
Publisher:
Microsoft Corporation*  (Invalid match)

Product:
Microsoft® Visual Studio® 2005

Description:
Visual Studio Macros

Version:
8.0.50727.42 (RTM.050727-4200)

MD5:
25b5c130b65a18dfd24fb5e115673309

SHA-1:
ebd466c5bfbfe172f4c7e002c349f9f51f0949e2

SHA-256:
b9a54ef4f769068af029aa7941c464990c476911180c9f4ec3379ab3b51ff5b3

Scanner detections:
35 / 68

Status:
Malware

Analysis date:
4/27/2024 4:11:48 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1840342
856

Agnitum Outpost
Trojan.Inject
7.1.1

AhnLab V3 Security
Trojan/Win32.FakeMS
2014.09.12

Avira AntiVirus
TR/Agent.65536.709
7.11.171.172

avast!
Win32:Trojan-gen
2014.9-141002

AVG
Inject2
2015.0.3334

Baidu Antivirus
Trojan.Win32.Inject
4.0.3.14102

Bitdefender
Trojan.GenericKD.1840342
1.0.20.1375

Clam AntiVirus
Suspect.Trojan.Generic.TPF
0.98/21411

Comodo Security
TrojWare.Win32.TrojanDownloader.Small.~AQ
19481

Dr.Web
Trojan.DownLoad3.32784
9.0.1.0275

Emsisoft Anti-Malware
Backdoor.Win32.Agent
8.14.10.02.04

ESET NOD32
Win32/TrojanDownloader.Small.PSD
8.10401

Fortinet FortiGate
W32/Inject.RTDE!tr
10/2/2014

F-Prot
W32/Downldr2.IZQJ
v6.4.7.1.166

F-Secure
Trojan.GenericKD.1840342
11.2014-02-10_5

G Data
Trojan.GenericKD.1840342
14.10.24

IKARUS anti.virus
Trojan-Spy.Agent
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.183.13345

Kaspersky
Trojan.Win32.Inject
14.0.0.3164

Malwarebytes
Trojan.Patched
v2014.10.02.04

McAfee
RDN/Generic Downloader.x!kw
5600.6990

Microsoft Security Essentials
TrojanDownloader:Win32/Lerspeng.B
1.10904

MicroWorld eScan
Trojan.GenericKD.1840342
15.0.0.825

NANO AntiVirus
Trojan.Win32.DownLoad3.demkbr
0.28.2.61942

Norman
Troj_Generic.VQOBS
11.20141002

nProtect
Trojan.GenericKD.1840342
14.09.11.01

Panda Antivirus
Trj/Genetic.gen
14.10.02.04

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Quick Heal
TrojanDownloader.Lerspeng.r4
10.14.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.10.8.12

Sophos
Troj/Inject-BBS
4.98

Trend Micro House Call
TROJ_GEN.R0C2C0DI514
7.2.275

Trend Micro
TROJ_GEN.R0C2C0DI514
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic
33014

File size:
64 KB (65,536 bytes)

Product version:
8.0.50727.42

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
vsaenv.exe

File PE Metadata
Compilation timestamp:
7/25/2013 5:35:22 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:E07iT13vfdHldhwTkdZKNu3dJO7tZ9Cb8lHpwo9gLd:1i53vfdHldhwTIKNsTO70YlHBgLd

Entry address:
0x162B

Entry point:
8B, D2, 55, 8B, EC, 6A, FF, 68, 40, 25, 40, 00, 68, DC, 1D, 40, 00, 64, A1, 00, 00, 00, 00, E8, 38, 03, 00, 00, 85, C0, 74, 0D, 8B, 45, F4, 8B, 4D, 10, 89, 01, 33, C0, 40, C9, C3, 33, C0, C9, C3, 55, 8B, EC, 2D, 00, 00, 01, 00, EB, 0A, 41, 8B, 4D, 14, 89, 4D, E8, 8B, 4D, 10, 85, C0, 40, 6B, C0, 08, 74, 0A, 50, E8, 11, 02, 00, 00, 51, 6B, C0, 02, E8, 08, 02, 00, 00, 6B, C0, 03, 83, 65, FC, 00, 8D, 45, E0, 50, FF, 75, 0C, 68, 61, 10, 00, 00, FF, 75, 08, FF, 15, AC, B1, 40, 00, C9, C3, 55, 8B, EC, 83, E8, E0...
 
[+]

Code size:
4 KB (4,096 bytes)

Remove {38f0d645-0f22-4928-a453-e8307a7a3b75} - Powered by Reason Core Security