41b288a-2ba76625

Norton HSPlayer

VIRUSBLOKADA LTD.

The file 41b288a-2ba76625, “Norton Premium Services & One Click Support Player” has been detected as malware by 24 anti-virus scanners.
Publisher:
Piranha Bytes  (signed by VIRUSBLOKADA LTD.)

Product:
Norton HSPlayer

Description:
Norton Premium Services & One Click Support Player

Version:
5.8.4.5

MD5:
8f0c962495e2b96d7452ad57c15bad2a

SHA-1:
e6e7fa34d92e309a645b685ca1a6bb942580c5d0

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/25/2024 11:43:09 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.FakeAv
2011.11.10

Avira AntiVirus
TR/EyeStye.N.2288
7.11.17.126

avast!
Win32:Malware-gen
2014.9-170130

AVG
PSW.Generic9
2018.0.2482

Bitdefender
Trojan.Generic.6674516
1.0.20.150

Clam AntiVirus
Trojan.Spy.Zbot-441
0.98/18155

Dr.Web
Trojan.PWS.SpySweep.46
9.0.1.030

Emsisoft Anti-Malware
Trojan.Win32.Spyeye!IK
8.17.01.30.04

ESET NOD32
Win32/Spy.SpyEye.CA
11.6619

Fortinet FortiGate
W32/Malware_fam.NB
1/30/2017

F-Secure
Trojan.Generic.6674516
11.2017-30-01_2

G Data
Trojan.Generic.6674516
17.1.22

IKARUS anti.virus
Trojan.Win32.Spyeye
t3scan.1.1.109.0

K7 AntiVirus
Riskware
13.115433

Kaspersky
Trojan.Win32.FakeAv
14.0.0.-1093

McAfee
Generic FakeAlert!tr
5600.6138

Microsoft Security Essentials
Trojan:Win32/EyeStye.N
1.163.1557.0

Norman
W32/Suspicious_Gen2.RWHNP
11.20170130

nProtect
Gen:Variant.Kazy.40559
11.11.10.01

Panda Antivirus
Trj/CI.A
17.01.30.04

Rising Antivirus
Trojan.Win32.Generic.129A6292
23.00.65.17128

SUPERAntiSpyware
Trojan.Agent/Gen-Zbot
8622

Vba32 AntiVirus
Trojan.FakeAv.iibu
3.12.16.4

VIPRE Antivirus
Trojan.Win32.Generic
11014

File size:
181.4 KB (185,720 bytes)

Product version:
3.9.1.7

Copyright:
Copyright © 2010 Symantec Corporation. All rights reserved.

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Application data\sun\java\deployment\cache\6.0\10\41b288a-2ba76625

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/28/2010 10:00:00 PM

Valid to:
1/30/2012 9:59:59 PM

Subject:
CN=VIRUSBLOKADA LTD., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=VIRUSBLOKADA LTD., L=Minsk, S=none, C=BY

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2BEF4F72149367BCC7775D0000909C1D

File PE Metadata
Compilation timestamp:
7/2/1998 5:44:15 AM

OS version:
3.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
4.2

Entry address:
0x2510

Entry point:
55, 8B, EC, 83, EC, 44, 50, 56, 57, 6A, 00, 6A, 00, 6A, 00, 6A, 00, 6A, 00, FF, 15, 68, 72, 40, 00, A3, 01, 91, 40, 00, 6A, 03, BE, 84, 71, 40, 00, FF, 16, A3, BC, 9A, 40, 00, BE, 5A, 06, 00, 00, 81, EE, B6, 0C, 00, 00, 89, 75, D8, BE, A6, 01, 00, 00, C1, CE, 1B, 03, 35, 65, 97, 40, 00, 89, 35, 7D, 97, 40, 00, C7, 05, 1F, 91, 40, 00, F9, 05, 00, 00, FF, 35, 1F, 91, 40, 00, 5A, 89, 55, E4, C7, 05, 29, 9B, 40, 00, CA, 05, 00, 00, 8B, 3D, 29, 9B, 40, 00, 09, FF, 74, 06, 89, 3D, 2C, 98, 40, 00, 8B, 15, 2C, 98...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
21.5 KB (22,016 bytes)

Remove 41b288a-2ba76625 - Powered by Reason Core Security