gwhpslj.exe

RealVNC Ltd

The executable gwhpslj.exe has been detected as malware by 16 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered by a time event.
Publisher:
RealVNC Ltd  (signed and verified)

Version:
1.0.0.0

MD5:
984b0bae008143fb90cf9adeacd99cac

SHA-1:
bfdf438e8302b0863a95613d77a114c8fb6513ee

SHA-256:
da33c54bd1a07d3245df44d6d0c4b882fad7fd822d276236c925b2469baac321

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
4/17/2024 11:20:49 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.lszci
8.3.3.4

avast!
Win32:Evo-gen [Susp]
2014.9-170308

AVG
MSIL11
2018.0.2445

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.1738

Dr.Web
Trojan.DownLoader17.15248
9.0.1.067

ESET NOD32
MSIL/Injector.ROM (variant)
11.15050

Fortinet FortiGate
W32/Omaneat.BTD!tr
3/8/2017

F-Prot
W32/MSIL_Injector.ID.gen
v6.4.7.1.166

IKARUS anti.virus
Trojan.Inject
0.2.1.2

K7 AntiVirus
Trojan
13.10.3.22644

Kaspersky
Trojan-Spy.MSIL.Omaneat
14.0.0.-1280

McAfee
Packed-KD!984B0BAE0081
5600.6101

Panda Antivirus
Trj/GdSda.A
17.03.08.10

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

Quick Heal
TrojanSpy.Omaneat
3.17.14.00

Sophos
Mal/Generic-S
4.98

File size:
762.3 KB (780,608 bytes)

Product version:
1.0.0.0

Original file name:
Izu.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\microsoft\windows\screentogif\gwhpslj.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/10/2012 1:00:00 AM

Valid to:
8/22/2015 12:59:59 AM

Subject:
CN=RealVNC Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=RealVNC Ltd, L=Cambridge, S=Cambridgeshire, C=GB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2838AA2AB3505BFABD474C9C373C4253

File PE Metadata
Compilation timestamp:
3/5/2017 8:58:39 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0xBB69E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9470

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
744 KB (761,856 bytes)

Scheduled Task
Task name:
Client Monitor

Trigger:
Time


Remove gwhpslj.exe - Powered by Reason Core Security