serverx.exe

The executable serverx.exe has been detected as malware by 14 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Serverx’.
MD5:
e5d2cb683182497339b2b14ea03606ac

SHA-1:
0a4e7ac976c2cea822e0da589b078a72567564a2

SHA-256:
5d82f1ff9b94451c1fae318bde8ac3a25363bd452f2b7e33913e600a57addbcb

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
4/24/2024 8:52:29 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Virtob.Gen.12
5813612

avast!
Win32:Vitro
160119-0

AVG
Win32/Madang.C
2015.0.4477

Dr.Web
Win32.Virut.56
9.0.1.05190

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
10.0.0.5366

ESET NOD32
Win32/Virut.NBP virus
7.0.302.0

F-Prot
W32/MalwareS.UZC
4.6.5.141

F-Secure
Win32.Virtob.Gen.12
5.15.21

Kaspersky
Virus.Win32.Virut
15.0.0.562

McAfee
Virus.W32/Madangel.b
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5087.0

Norman
Win32.Virtob.Gen.12
03.12.2014 13:20:04

Sophos
Virus 'W32/Scribble-B'
5.22

VIPRE Antivirus
Threat.4737366
46826

File size:
36.2 KB (37,066 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\serverx.exe

File PE Metadata
Compilation timestamp:
12/13/1995 4:13:31 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
768:MAb22TkTtaRS1T+r2iXhtE6qn9oVHNttdzmWtwJ:MAi2TkTtaROijiWtHW

Entry address:
0xC0AE

Entry point:
83, 3C, 24, FE, 77, FE, 8D, 64, 24, CC, 60, 83, EC, DC, E8, FD, 01, 00, 00, 4B, 66, 4B, 75, FC, 47, 97, 40, 4F, FF, 73, 3C, 59, 81, E9, FD, FF, FF, 7F, 0F, 83, E7, FF, FF, FF, 81, D9, E6, 13, 00, 00, 71, DF, 3C, AA, 47, 47, FF, B4, 19, E4, 13, 00, 80, 83, C4, 04, 66, 81, 44, 24, FC, B0, BA, 75, C8, 40, 48, 46, 4F, 68, AD, 18, BA, B3, E8, 23, 01, 00, 00, 89, 74, 24, 44, E8, 43, 98, FF, FF, E9, BB, 00, 00, 00, 5B, 5F, FF, D7, E8, 73, FF, FF, FF, 81, BD, BC, FF, FF, FF, 5E, 01, 00, 00, 7E, 36, 9B, 90, B5, 7F...
 
[+]

Entropy:
7.3535

Code size:
512 Bytes (512 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Serverx

Command:
C:\Windows\System32\serverx.exe


Remove serverx.exe - Powered by Reason Core Security