fnplicensingservice.exe

FLEXnet Publisher (32 bit)

Acresso Software Inc.

The executable fnplicensingservice.exe, “Activation Licensing Service” has been detected as malware by 37 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “FLEXnet Licensing Service”. This virus which infects .exe files stops various security software and prevents some core Windows utilities from running. It also tries to download other files from a remote server, including other malware.
Publisher:
Acresso Software Inc.

Product:
FLEXnet Publisher (32 bit)

Description:
Activation Licensing Service

Version:
11.6.0.0 build 60117

MD5:
146d53409be8c69de8c92b551e8dedbc

SHA-1:
9c4895d9146fe0046a6b21144c6ad5de9260b8f0

SHA-256:
06a372138bec9fc83e3e6a7a2b8df4d4611936c4537e97ef495ffc23a3513ba5

Scanner detections:
37 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 7:58:43 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
5739717

Agnitum Outpost
Win32.Sality.BL
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2015.10.05

Avira AntiVirus
W32/Sality.AT
7.11.30.172

Arcabit
Win32.Sality.3
1.0.0.568

avast!
Win32:SaliCode
150913-1

AVG
Win32/Sality
2015.0.4355

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.15105

Bitdefender
Win32.Sality.3
1.0.20.1390

Bkav FE
W32.Sality.PE
1.3.0.7237

Comodo Security
Virus.Win32.Sality.gen
23355

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.14.151

G Data
Win32.Sality
15.10.25

IKARUS anti.virus
Virus.Sality
t3scan.1.9.5.0

K7 AntiVirus
Virus
13.210.17418

Kaspersky
Virus.Win32.Sality
15.0.0.543

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Virus:Win32/Sality.AT
1.1.12101.0

MicroWorld eScan
Win32.Sality.3
16.0.0.834

NANO AntiVirus
Virus.Win32.Sality.beygb
0.30.26.3725

Norman
Win32.Sality.3
04.08.2015 10:30:46

nProtect
Virus/W32.Sality.D
15.10.02.01

Panda Antivirus
W32/Sality.AA
15.10.05.12

Quick Heal
W32.Sality.U
10.15.14.00

Rising Antivirus
PE:Virus.Sality!1.A09C[F1]
23.00.65.151003

Sophos
Virus 'Mal/Sality-D'
5.19

Total Defense
Win32/Sality.AA
37.1.62.1

Trend Micro House Call
PE_SALITY.RL
7.2.278

Trend Micro
PE_SALITY.RL
10.465.05

Vba32 AntiVirus
Virus.Win32.Sality.bakc
3.12.26.4

VIPRE Antivirus
Threat.4721115
42326

ViRobot
Win32.Sality.Gen.A[h]
2014.3.20.0

Zillya! Antivirus
Virus.Sality.Win32.25
2.0.0.2427

File size:
708.3 KB (725,256 bytes)

Copyright:
Copyright (c) 2006-2008, Acresso Software Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe

File PE Metadata
Compilation timestamp:
4/11/2008 12:51:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.10

CTPH (ssdeep):
12288:p7NHvmMCN8IDfdtbA/uGNDzL11YsZNSU+G9EXN6EDfXKFqDf6BIW1:pRHvEGNDHLZNSE9jEDaGf6X

Entry address:
0x544F8

Entry point:
03, C7, 87, E8, 0F, BE, CE, 41, FF, CB, C6, C4, 28, 8D, 1D, D1, C4, AB, 74, 4F, 15, E2, 37, 49, 18, 02, C3, C6, C0, 32, F6, C7, DF, 01, C1, 68, AA, F2, 00, 00, F6, C5, 92, 0F, B7, ED, 5A, FE, C9, 69, DB, A8, D1, EE, E1, EB, 06, 81, FD, 2F, EB, 7A, A7, 2B, F2, 10, F9, F2, F6, C4, 94, 0F, AF, C2, 4A, 8D, 35, 81, BD, F5, 46, F2, 8A, C3, 81, D8, 8D, 3D, FA, 19, 8D, 35, C8, 48, 38, 0F, 73, 08, 69, D8, BA, 69, 12, AF, 84, C6, E8, 00, 00, 00, 00, 86, EC, 85, C1, 71, 0A, F7, C3, F8, 5D, EF, 75, F6, C4, A7, 4B, 81...
 
[+]

Entropy:
6.9298

Code size:
438 KB (448,512 bytes)

Service
Display name:
FLEXnet Licensing Service

Description:
This service performs licensing functions on behalf of FLEXnet enabled products.

Type:
Win32OwnProcess


Remove fnplicensingservice.exe - Powered by Reason Core Security