regsvr.exe

The executable regsvr.exe has been detected as malware by 4 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler. While running, it connects to the Internet address ir1.fp.vip.ne1.yahoo.com on port 80 using the HTTP protocol.
MD5:
fc338c09704eebe2ca0762742c9e8ff5

SHA-1:
8176a8813688241f7921d5069512ecbebf99106d

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
5/16/2025 6:59:23 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160917-0

F-Prot
W32/Trojan2.DFYJ
4.6.5.141

F-Secure
IM-Worm:W32/Sohanad.HM
5.15.154

Kaspersky
Worm.Win32.AutoRun
15.0.2.529

File size:
662.2 KB (678,049 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\regsvr.exe

File PE Metadata
Compilation timestamp:
11/25/2007 2:51:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0xA5001

Entry point:
60, 6A, 00, FF, 15, 60, 5F, 4A, 00, E8, 00, 00, 00, 00, 01, F1, 23, CF, 0F, BC, FE, 1C, CB, 59, 81, C1, A1, 1D, 26, 00, 0F, BA, F2, 38, 33, D9, 86, C3, 81, E9, B0, BD, 24, 00, 87, C3, 0F, C1, C3, 15, B7, 9E, E9, 08, 51, 81, C1, 20, 10, 00, 00, C1, F3, B9, 88, F0, 0F, BB, F7, 81, C1, 34, 09, 00, 00, 69, FE, DE, 29, 48, EB, 0F, C0, D4, 0F, C0, C3, 81, E9, 3E, 08, 00, 00, 0F, B7, FD, 0F, BC, FE, 0F, CF, 51, 81, E9, A1, 1D, 26, 00, 0F, B7, FD, D1, D0, 8B, C5, 81, C1, 8B, 0C, 26, 00, F7, D0, F6, D8, 8D, 05, 67...
 
[+]

Entropy:
7.4170

Code size:
404.5 KB (414,208 bytes)

Scheduled Task
Task name:
At1

Path:
C:\WINDOWS\Tasks\At1.job

Trigger:
Weekly (Runs weekly on Mondays at 9:00 AM)

Description:
Created by NetScheduleJobAdd.


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ns3035593.ip-149-202-207.eu  (149.202.207.191:80)

TCP (HTTP):
Connects to ns3328060.ip-37-59-28.eu  (37.59.28.133:80)

TCP (HTTP):
Connects to ir1.fp.vip.ne1.yahoo.com  (98.138.253.109:80)

TCP (HTTP):
Connects to dev.ucoz.net  (195.216.243.102:80)

Remove regsvr.exe - Powered by Reason Core Security