casrv.exe

The application casrv.exe has been detected as a potentially unwanted program by 11 anti-malware scanners.
MD5:
d76691d2e04a3cfc182aece103fe4333

SHA-1:
d0d3a27a903cf8846b3446605d7ee5ac8fcdd221

SHA-256:
f2c9ee7ed3bd412f6be772c3a50c1a6076f398a00e990f0eaf25e34335630d3a

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 1:25:19 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1090414
655

AhnLab V3 Security
Adware/Win32.AdBar
2015.01.25

AVG
Generic6
2016.0.3133

Baidu Antivirus
Adware.Win32.ConvertAd
4.0.3.15112

Bitdefender
Application.Generic.1090414
1.0.20.555

F-Secure
Application.Generic.1090414
11.2015-21-04_3

G Data
Application.Generic.1090414
15.4.24

MicroWorld eScan
Application.Generic.1090414
16.0.0.333

NANO AntiVirus
Riskware.Win32.ClickMeIn.dlwzdd
0.30.0.64448

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.1.12.19

File size:
140 KB (143,360 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\casrv.exe

File PE Metadata
Compilation timestamp:
1/4/2015 6:46:06 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:JqRM8NbMXWsH88vEL9iLixn+K83pkhcg3EHQaIb:47BMGsH5e9isn+KthcgTaI

Entry address:
0xB1D1

Entry point:
E8, 76, 56, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 69, F5, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, 1D, 2E, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 88, 1A, 42, 00, 74, 12, 8B, 0D, 40, 18, 42, 00, 85, 48, 70, 75, 07, E8, 1B, 35, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 38, 1F, 42, 00, 74, 16, 8B, 46, 08, 8B, 0D, 40, 18, 42, 00...
 
[+]

Entropy:
6.4827

Code size:
102.5 KB (104,960 bytes)

Remove casrv.exe - Powered by Reason Core Security