qhs.exe

The application qhs.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. Accoriding to the detections, this has been classified as a kyelogger which is capable of recoring a user's keystrokes.
MD5:
e9e639bb4c7c113d3142887257853565

SHA-1:
fd3507b436585eeb4b5c43693b08bf6dde0a34d9

SHA-256:
4937fbbfddf1a5fc48406968b63665d94f6b7a664485bd74a512948da5e275c2

Scanner detections:
20 / 68

Status:
Potentially unwanted

Explanation:
The software cotains keystroke monitoring/logging capablities which may or may not be installed without the user's knowledge.

Analysis date:
4/25/2024 4:46:36 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Keylogger.Ardamax.6
885

Agnitum Outpost
Riskware.Monitor
7.1.1

Avira AntiVirus
SPR/Tool.Monitor.Gen
7.11.145.6

avast!
Win32:Ardamax-RE [PUP]
2014.9-140902

AVG
Ardamax
2015.0.3363

Baidu Antivirus
Trojan.Win32.Ardamax
4.0.3.1492

Bitdefender
Gen:Variant.Application.Keylogger.Ardamax.6
1.0.20.1225

Dr.Web
Trojan.KeyLogger.22499
9.0.1.0245

Emsisoft Anti-Malware
Gen:Variant.Application.Keylogger.Ardamax
8.14.09.02.05

ESET NOD32
Win32/KeyLogger.Ardamax.NBP (variant)
8.9713

F-Secure
Gen:Variant.Application.Keylogger
11.2014-02-09_3

G Data
Gen:Variant.Application.Keylogger.Ardamax
14.9.24

Kaspersky
not-a-virus:Monitor.Win32.Ardamax
14.0.0.3311

MicroWorld eScan
Gen:Variant.Application.Keylogger.Ardamax.6
15.0.0.735

NANO AntiVirus
Trojan.Win32.KeyLogger.cubrgw
0.28.0.59492

Panda Antivirus
Trj/Genetic.gen
14.09.02.05

SUPERAntiSpyware
Trojan.Agent/Gen-Graftor
10384

Trend Micro House Call
TSPY_ARDAMAX.BMC
7.2.245

Trend Micro
TSPY_ARDAMAX.BMC
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic
28548

File size:
2.4 MB (2,499,584 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\wcpslg\qhs.exe

File PE Metadata
Compilation timestamp:
4/12/2014 5:32:05 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:pL01p9lEkWCIxrqLeaI1Xw4FMRHK6ZMWsmf9ppn0OWcCBqkggg0VvJ1paoj19:pCEkWCIMq11XFMQ0smlP0OWcHNglnplT

Entry address:
0x5609A

Entry point:
E8, 2E, E4, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 80, DE, 58, 00, E8, D8, 69, 00, 00, 6A, 0E, E8, D8, 5E, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, BC, 5D, 5A, 00, BA, B8, 5D, 5A, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, D4, B4, FF, FF, 59, FF, 76, 04, E8, CB, B4, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, C7, 69, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, A3, 5D, 00, 00, 59, C3, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
7.0876

Code size:
1.2 MB (1,239,552 bytes)

Remove qhs.exe - Powered by Reason Core Security