server.exe

FortiClient

Fortinet Inc.

The executable server.exe, “FortiClient Wsc Helper” has been detected as malware by 4 anti-virus scanners.
Publisher:
Fortinet Inc.

Product:
FortiClient

Description:
FortiClient Wsc Helper

Version:
5.4.0.0780

MD5:
16a4a31a32f2634bd4162a672c5c5494

SHA-1:
ed700896eb4519c4e15053d88ce16cb39b6e8622

SHA-256:
5639ca7f2a0438ddcd4c5555bcaa00824f575133d2d042f448ba33abb8a5d0c5

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
4/26/2024 2:23:50 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.Gen
8.3.3.4

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.17316

ESET NOD32
MSIL/Injector.OHA (variant)
11.15062

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

File size:
796 KB (815,061 bytes)

Product version:
5.4.0.0780

Copyright:
2015 Fortinet Inc. All rights reserved.

Original file name:
FCWsc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\install\server.exe

File PE Metadata
Compilation timestamp:
3/9/2017 10:51:38 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x20D8E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 0C, 00, 00, 00, 90, 3D, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
123.5 KB (126,464 bytes)

Remove server.exe - Powered by Reason Core Security