bgqservice.exe

The executable bgqservice.exe has been detected as malware by 13 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
Version:
1.7.6001.18000 built by: WinDDK

MD5:
0c72a6cee18037aa9cf1a4f32263b6ab

SHA-1:
32cace16047de634fe39675053d145530a64c925

SHA-256:
c21cdde052488c3f4f62e45376ef809d91b009f929cbdf08155c1b7aabfadf3d

Scanner detections:
13 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
5/7/2024 7:19:39 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
5813571

avast!
Win32:Kukacka
160119-0

AVG
Win32/Sality
2015.0.4489

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Virut.AI!Generic
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Norman
Win32.Sality.3
11.01.2016 17:30:26

Sophos
Virus 'Mal/Sality-D'
5.22

VIPRE Antivirus
Threat.4721115
46908

File size:
139.5 KB (142,848 bytes)

Product version:
1.7.6001.18000

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mblaze ai\bgqservice.exe

File PE Metadata
Compilation timestamp:
1/10/2013 2:13:17 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:ZM4JZ45vH/sscpXru2gkRacX/WxFhgan+M/cSH/6KlZh7ztE9:H4JUFtfarFmobcO6Wv/tE

Entry address:
0x6B0A

Entry point:
60, 0F, B7, CA, 81, FE, E0, 3A, 00, 00, 72, 08, F7, C0, 3C, 75, 8B, 1F, 3B, EB, 1B, D6, FF, C3, 0F, AF, D8, F6, DE, 0F, A4, D6, 97, FE, C2, F6, C2, 9E, 2B, CF, 0F, A4, D0, E0, 0F, AC, FB, A9, 0F, C8, 8B, C8, 0F, AD, C1, FF, CD, 15, 20, 6E, 66, 96, 0F, BA, E9, D3, 0F, BA, F3, CE, 11, C5, 08, D6, 0B, C6, E8, 00, 00, 00, 00, 5F, D0, F9, F3, B4, 0A, C6, C3, E9, 0F, C1, D2, F6, C1, D9, 69, C7, B2, 89, 5C, CC, 81, C7, 72, 01, 01, 00, 0F, BD, F3, 81, EF, 2F, 06, 00, 00, 0F, BA, FB, D8, 0F, CB, C1, C6, CE, 85, C6...
 
[+]

Entropy:
7.4070

Code size:
60 KB (61,440 bytes)

Remove bgqservice.exe - Powered by Reason Core Security