fdsv.exe

Smallfrogs

The executable fdsv.exe, “FileDigitalSignVerify Application” has been detected as malware by 11 anti-virus scanners.
Publisher:
Smallfrogs Studio  (signed by Smallfrogs)

Description:
FileDigitalSignVerify Application

Version:
1, 2, 0, 22

MD5:
da3a21ecabce5c424ae9b6f44e3db1f4

SHA-1:
1d4608bb71ca331009f914ebe765ad7cfa01ae13

SHA-256:
dd874cfb3eea2077dd289fe6b6bf094327470ee7b5176e810e47ff6302ce1582

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
4/26/2024 8:49:20 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Mabezat [Wrm]
150717-0

AVG
Win32/Mabezat
2015.0.4355

Dr.Web
Win32.HLLW.Tazebama
9.0.1.05190

Emsisoft Anti-Malware
Win32.Worm.Mabezat.Gen
11.5.0.6191

ESET NOD32
Win32/Mabezat.A virus
8.0.319.0

F-Prot
W32/Mabezat.A-2
4.6.5.141

F-Secure
Win32.Worm.Mabezat.Gen
5.15.96

Kaspersky
Worm.Win32.Mabezat
15.0.0.562

McAfee
Virus.W32/Mabezat.a
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.217.1541.0

Norman
Win32.Worm.Mabezat.Gen
02.04.2016 17:35:19

File size:
240.3 KB (246,031 bytes)

Product version:
1, 2, 0, 22

Copyright:
Copyright (C) 2007-2008 Smallfrogs. All rights reserved.

Original file name:
FileDigitalSignVerify.EXE

File type:
Executable application (Win32 EXE)

Language:
Chinese

Common path:
C:\windows\fdsv.exe

Digital Signature
Signed by:

Authority:
Smallfrogs Studio

Valid from:
12/22/2007 8:15:19 PM

Valid to:
12/22/2027 8:15:18 PM

Subject:
CN=Smallfrogs

Issuer:
E=SUPPORT@KZTECHS.COM, CN=KZTechs.COM, O=Smallfrogs Studio, C=CN

Serial number:
722ABCAFFAF382B24590F0FE0981637E

File PE Metadata
Compilation timestamp:
2/28/2008 6:07:10 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
3072:dOLbkcfLJqHVtFIhrt8RKEBC/MJM3Ov4kM0qrGtkn054aDPjReCHmv:MLbkh3DBCk+3A4+qiXRY

Entry address:
0x3A85

Entry point:
BB, 83, 98, 65, 79, 93, E9, 20, 01, 00, 00, B6, 5C, BF, BB, 67, EB, BF, BB, DF, 9C, 40, 3F, 3F, BF, 3F, 3F, EE, 3F, 3F, 3F, 9E, 70, 75, 70, 6F, 70, 78, 76, 75, 3F, 3F, 3F, B3, A0, B9, A4, A1, A0, AC, A0, 6D, A3, AB, AB, 3F, 3F, 3F, 3F, 9B, 3F, 3F, 3F, 85, B1, A4, A4, 8B, A8, A1, B1, A0, B1, B8, 3F, 82, B1, A4, A0, B3, A4, 83, A8, B1, A4, A2, B3, AE, B1, B8, 80, 3F, 3F, 3F, 3F, 86, A4, B3, 96, A8, AD, A3, AE, B6, B2, 83, A8, B1, A4, A2, B3, AE, B1, B8, 80, 3F, 3F, 3F, 3F, 86, A4, B3, 8C, AE, A3, B4, AB, A4...
 
[+]

Entropy:
7.0227

Code size:
52 KB (53,248 bytes)

Remove fdsv.exe - Powered by Reason Core Security