pcfbsreport.exe

Baidu

Baidu, Inc.

The executable pcfbsreport.exe, “Baidu BlueScreen Reporter” has been detected as malware by 37 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
Publisher:
Baidu, Inc.

Product:
Baidu

Description:
Baidu BlueScreen Reporter

Version:
1,0,0,78

MD5:
1a9b63ca4868db8f99293bd89be7c8dc

SHA-1:
47b31e757288b8e8bfb3c6a6e57efbac4e761e6d

SHA-256:
761702f4aba7daba5a18e54fcd885ba4b4d81c0ef6f74ee85b7bdfa20c9061c3

Scanner detections:
37 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/16/2024 4:58:52 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
834

AegisLab AV Signature
W32.Sality
2.1.4+

Agnitum Outpost
Win32.Sality.FA.Gen
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2014.10.24

Avira AntiVirus
W32/Sality.AT
7.11.30.172

avast!
Win32:SaliCode
141023-1

AVG
Win32/Sality
2015.0.3312

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.141024

Bitdefender
Win32.Sality.3
1.0.20.1485

Bkav FE
W32.Sality.PE
1.3.0.4959

Dr.Web
Win32.Sector.22
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
14.10.24

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

Fortinet FortiGate
W95/SK.8699
10/24/2014

F-Prot
W32/Virut.AI!Generic
4.6.5.141

F-Secure
Win32.Sality.3
11.2014-24-10_6

G Data
Win32.Sality
14.10.24

IKARUS anti.virus
Trojan-Dropper.Agent
t3scan.1.7.8.0

K7 AntiVirus
Virus
13.185.13789

Kaspersky
Virus.Win32.Sality
15.0.0.494

McAfee
W32/Sality.gen.z
5600.6968

Microsoft Security Essentials
Threat.Undefined
1.187.339.0

MicroWorld eScan
Win32.Sality.3
15.0.0.891

NANO AntiVirus
Virus.Win32.Sality.bzkem
0.28.2.62841

Norman
Sality.ZHB
11.20141024

nProtect
Win32.Sality.3
14.10.23.01

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Quick Heal
W32.Sality.U
10.14.14.00

Rising Antivirus
PE:Win32.KUKU.GEN!1463551
23.00.65.141022

Sophos
Mal/Sality-D
4.98

Total Defense
Win32/Sality.AA
37.0.11245

Trend Micro House Call
PE_SALITY.ER
7.2.297

Trend Micro
PE_SALITY.ER
10.465.24

Vba32 AntiVirus
Virus.Win32.Sality.bakb
3.12.26.3

VIPRE Antivirus
Threat.4734158
33706

ViRobot
Win32.Sality.N
2011.4.7.4223

Zillya! Antivirus
Virus.Sality.Win32.20
2.0.0.1966

File size:
400.6 KB (410,264 bytes)

Product version:
1,0,0,78

Copyright:
Copyright (C) 2013 Baidu, Inc. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\baidu security\pc faster\4.0.0.0\pcfbsreport.exe

File PE Metadata
Compilation timestamp:
1/2/2014 8:36:22 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:qpRIaNMlmM4Wg+lohz+Gim6g/YX/jddihO6SVd8vdNBCFHVB3K:qsa2gMIAGiTg/YvFVdGy5X3K

Entry address:
0x27A66

Entry point:
0F, CA, 68, E7, DC, 87, 00, F6, C6, 33, 2C, 02, 0F, AF, ED, 81, D5, 5B, AA, 1D, 98, 8D, 01, 74, 02, 86, D2, 8D, 08, 8B, D8, 76, 05, 35, C2, 90, 5B, 87, 0F, AF, CE, 1D, 1F, 9F, 5B, C3, 86, E4, E8, 00, 00, 00, 00, F7, DD, 72, 06, C7, C2, 20, 57, 02, 76, 3B, CA, 75, 02, FF, C1, 3B, DF, 81, E0, F7, C8, DC, A5, 8A, E1, 2D, 23, 9A, 41, 79, BD, 1B, 00, 00, 00, 0F, BE, F7, 81, F5, 6F, 09, 00, 00, 81, C7, 65, B8, 72, 6F, C6, C1, B7, EB, 0A, 87, CA, 88, E5, 69, FE, 16, 9A, 22, 06, 81, ED, 43, F9, FF, FF, 0F, AF, F2...
 
[+]

Code size:
227 KB (232,448 bytes)

Windows Firewall Allowed Program
Name:
C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PcfBSReport.exe


Remove pcfbsreport.exe - Powered by Reason Core Security