BingSvc.exe

Microsoft Bing Service

© 2015 Microsoft Corporation

The executable BingSvc.exe has been detected as malware by 3 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘BingSvc’.
Publisher:
© 2015 Microsoft Corporation

Product:
Microsoft Bing Service

Version:
1.0.6.0

MD5:
35c26d3fbcdd5f515748c453ee2522a4

SHA-1:
acd68c17011af72b6b83e38ff1a459292ec2192c

SHA-256:
9c2b725889721c8dfa1e630f220c2ea565c0a338aeff1312dba8cf3d8851bf19

Scanner detections:
3 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/29/2024 5:09:59 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.16.24

File size:
217.1 KB (222,287 bytes)

Product version:
1.0.6.0

Copyright:
© 2015 Microsoft Corporation. All rights reserved.

Original file name:
BingSvc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\bingsvc\bingsvc.exe

File PE Metadata
Compilation timestamp:
11/5/2015 3:37:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x71ED

Entry point:
E9, 16, 5A, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, FF, 75, 14, 6A, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 05, 00, 00, 00, 83, C4, 14, 5D, C3, 55, 8B, EC, 83, EC, 20, 53, 57, 33, DB, 6A, 07, 33, C0, 59, 8D, 7D, E4, 89, 5D, E0, F3, AB, 39, 45, 10, 75, 18, E8, 2F, 16, 00, 00, C7, 00, 16, 00, 00, 00, E8, B2, 2E, 00, 00, 83, C8, FF, E9, 9B, 00, 00, 00, 8B, 45, 0C, 56, 8B, 75, 08, 85, C0, 74, 19, 85, F6, 75, 15, E8, 08, 16, 00, 00, C7, 00, 16, 00, 00, 00, E8, 8B, 2E, 00, 00, 83, C8, FF, EB, 76, C7, 45, EC...
 
[+]

Entropy:
6.9316

Packer / compiler:
Xtreme-Protector v1.05

Code size:
78.5 KB (80,384 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BingSvc

Command:
C:\users\{user}\appdata\local\microsoft\bingsvc\bingsvc.exe


Remove BingSvc.exe - Powered by Reason Core Security