hxdsvc.exe

hxdsvc

NetZone Info-Tech Co., Ltd., Shanghai

The application hxdsvc.exe by NetZone Info-Tech Co.,, Shanghai has been detected as a potentially unwanted program by 8 anti-malware scanners. It runs as a windows Service named “NetZone Hxd Client Service”.
Publisher:
Netzonesoft Corp.  (signed by NetZone Info-Tech Co., Ltd., Shanghai)

Product:
hxdsvc

Version:
3.0.2900

MD5:
1f4efd4d4ad869cb46102a917cff4821

SHA-1:
d913447bb5db6462b6c0906bb785216cf5ec447e

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 1:46:42 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Banker.Banker.ssgg
7.11.134.184

AVG
PSW.Banker6
2016.0.2995

Comodo Security
UnclassifiedMalware
17885

IKARUS anti.virus
Trojan-PWS.Banker6
t3scan.2.2.29

Reason Heuristics
PUP.Optional.NetZoneInfoTechCoShanghai.Service
15.9.5.16

SUPERAntiSpyware
Trojan.Agent/Gen-Banker
9648

Vba32 AntiVirus
suspected of Unknown.Win32Virus
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
27078

File size:
585.3 KB (599,312 bytes)

Product version:
3.0.2900

Copyright:
Copyright (C) Netzonesoft Corp. 2008-2009

Original file name:
hxdsvc

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\hxdsvc.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/26/2011 8:00:00 AM

Valid to:
8/5/2012 7:59:59 AM

Subject:
CN="NetZone Info-Tech Co., Ltd., Shanghai", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="NetZone Info-Tech Co., Ltd., Shanghai", L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
00F1D32C1B972DF4D97FEF5EE83B90E5

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:LSL/pMt7WmS3nLQzse+uY8wLC6OXc3B00F1j5SYYC:uO7WZLve1mLChc3BRF1D

Entry address:
0x76C94

Entry point:
55, 8B, EC, 83, C4, F0, B8, C4, 67, 47, 00, E8, E4, F8, F8, FF, E8, DF, C4, FF, FF, E8, 66, D6, F8, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5345

Developed / compiled with:
Microsoft Visual C++

Code size:
471.5 KB (482,816 bytes)

Service
Display name:
NetZone Hxd Client Service

Service name:
nzHxDSvc

Description:
Hxd Client Service

Type:
Win32OwnProcess, InteractiveProcess

Group:
hxdsvc

Depends on:
MSiSCSI


Remove hxdsvc.exe - Powered by Reason Core Security