setup_bw71_287.exe

fssyr.exe

LivePlex Corp

The executable setup_bw71_287.exe has been detected as malware by 11 anti-virus scanners.
Publisher:
抚顺市优而胜信息咨询有限公司  (signed by LivePlex Corp)

Product:
fssyr.exe

Version:
2.0.0.149

MD5:
c779c6a2e848637edbf5edb4249adecd

SHA-1:
902d145cceb654f593995616237af7035c3cec7b

SHA-256:
d352225040090749c8d63712ccae21ff8b014f7af71420f1743c7f09a65c8201

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
4/24/2024 10:54:18 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2147136
726

AVG
Win32/DH
2016.0.3204

Bitdefender
Trojan.GenericKD.2147136
1.0.20.200

Emsisoft Anti-Malware
Trojan.GenericKD.2147136
8.15.02.09.10

F-Secure
Trojan.GenericKD.2147136
11.2015-09-02_2

G Data
Trojan.GenericKD.2147136
15.2.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.6.0

McAfee
Artemis!C779C6A2E848
5600.6860

MicroWorld eScan
Trojan.GenericKD.2147136
16.0.0.120

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R02SH09B615
7.2.40

File size:
830.4 KB (850,352 bytes)

Product version:
1.0.0.0

Copyright:
fssyr.exe

Trademarks:
fssyr.exe

Original file name:
fssyr.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/9/2012 8:00:00 AM

Valid to:
6/9/2014 7:59:59 AM

Subject:
CN=LivePlex Corp, O=LivePlex Corp, L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3F5542E2E71D8DB357041C9DD45B950A

File PE Metadata
Compilation timestamp:
2/5/2015 6:50:45 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:BbgOpaNpo6t1DwNHxCPhBySyo+veF1v+ff:BANgE0SIveFkX

Entry address:
0x9FC50

Entry point:
55, 8B, EC, 83, C4, F0, B8, 50, 97, 49, 00, E8, D8, A1, F6, FF, A1, B8, 20, 4A, 00, 8B, 00, E8, EC, 6C, FF, FF, A1, B8, 20, 4A, 00, 8B, 00, B2, 01, E8, F6, 88, FF, FF, 8B, 0D, 28, 21, 4A, 00, A1, B8, 20, 4A, 00, 8B, 00, 8B, 15, 1C, 8D, 49, 00, E8, DE, 6C, FF, FF, A1, B8, 20, 4A, 00, 8B, 00, E8, 22, 6E, FF, FF, E8, A5, 61, F6, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6655

Developed / compiled with:
Microsoft Visual C++

Code size:
632.5 KB (647,680 bytes)

Remove setup_bw71_287.exe - Powered by Reason Core Security