pcappstoresvc.exe

Baidu PC App Store

Baidu Inc.

The executable pcappstoresvc.exe, “Baidu PC App Store Service” has been detected as malware by 12 anti-virus scanners. It runs as a windows Service named “Baidu PC App Store Service 4.4.0.5890”.
Publisher:
Baidu Inc.

Product:
Baidu PC App Store

Description:
Baidu PC App Store Service

Version:
4,4,0,5890

MD5:
4ac8361eed292bc1a13c86a80ca594a2

SHA-1:
a4e581681592d32896dabeae56d84771c5520f1b

SHA-256:
a74bfad2f4992334f5db1300a142d4fd7ecd832d6fa8e3bc802fdec829ca3d93

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
4/26/2024 3:12:13 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Patched.Gen
7.11.30.172

avast!
Win32:Sality
141023-1

AVG
Win32/Sality
2015.0.3312

Bkav FE
W32.HfsAutoA
1.3.0.4959

Fortinet FortiGate
W95/SK.8699
10/24/2014

F-Prot
W32/Virut.AI!Generic
4.6.5.141

NANO AntiVirus
Virus.Win32.Virut-Gen.bwpxnc
0.28.2.62841

Qihoo 360 Security
Malware.QVM10.Gen
1.0.0.1015

Trend Micro House Call
PE_SALITY.ER
7.2.297

Trend Micro
PE_SALITY.ER
10.465.24

VIPRE Antivirus
Threat.4758034
33706

Zillya! Antivirus
Virus.Sality.Win32.20
2.0.0.1966

File size:
611.5 KB (626,208 bytes)

Product version:
4,4,0,5890

Copyright:
Copyright (C) 2012 Baidu, Inc. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\baidu security\pc app store\4.4.0.5890\pcappstoresvc.exe

File PE Metadata
Compilation timestamp:
5/27/2014 3:37:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
12288:Z8DYMSiOIq56FCe4N2aLtadAr8vmKPkYJfU669ND2A:Pi/CZN2aLtaInK8YJM62NH

Entry address:
0x328EC

Entry point:
E8, D2, A6, 00, 00, E9, A4, FE, FF, FF, 6A, 0C, 68, 00, 08, 47, 00, E8, D6, 24, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 28, ED, 47, 00, 77, 22, 6A, 04, E8, F9, 92, 00, 00, 59, 83, 65, FC, 00, 56, E8, 00, 9B, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, E2, 24, 00, 00, C3, 6A, 04, E8, F4, 91, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 78, 33, 46, 00, 83, 3D, 40, D8, 47, 00, 00, 75, 18, E8, 8F, 8E, 00...
 
[+]

Code size:
392 KB (401,408 bytes)

Service
Display name:
Baidu PC App Store Service 4.4.0.5890

Service name:
PCAppStoreSvc_{PCAppStore_4.4.0.5890}

Type:
Win32OwnProcess, InteractiveProcess


Remove pcappstoresvc.exe - Powered by Reason Core Security