f656f03daf7f80efdc0dbd712583f300.pe

GIF图象引擎

The file f656f03daf7f80efdc0dbd712583f300.pe, “Microsoft 基础类图片程序” has been detected as malware by 34 anti-virus scanners.
Product:
GIF图象引擎

Description:
Microsoft 基础类图片程序

Version:
1, 0, 0, 1

MD5:
f656f03daf7f80efdc0dbd712583f300

SHA-1:
d7d0f58f328b086d9c1b3b5990e9212038548c77

SHA-256:
2704a155ea3e7ae820c1caab7ce87a0b447825efa8f1861e36c4a50a6dd129aa

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
5/10/2024 10:10:55 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.Elzob.10473
658

Agnitum Outpost
Trojan.PWS.QQShou
7.1.1

AhnLab V3 Security
Win-Trojan/QQShou.36864
2015.04.06

avast!
Win32:QQShou-BE [Trj]
2014.9-150418

AVG
PSW.Generic
2016.0.3136

Baidu Antivirus
Trojan.Win32.InfoStealer
4.0.3.15418

Bitdefender
Gen:Variant.Graftor.Elzob.10473
1.0.20.540

Comodo Security
Packed.Win32.MUPX.Gen
21663

Dr.Web
Trojan.PWS.Qqpass.358
9.0.1.0108

Emsisoft Anti-Malware
Gen:Variant.Graftor.Elzob.10473
8.15.04.18.09

ESET NOD32
Win32/PSW.QQShou (variant)
9.11430

Fortinet FortiGate
W32/QQShou.AU!tr.pws
4/18/2015

F-Prot
W32/Busky.B.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Graftor.Elzob.10473
11.2015-18-04_7

G Data
Gen:Variant.Graftor.Elzob.10473
15.4.25

IKARUS anti.virus
Trojan-PWS.Win32.QQShou
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.202.15489

Kaspersky
Trojan-PSW.Win32.QQShou
14.0.0.2173

Malwarebytes
Trojan.Agent
v2015.04.18.09

McAfee
Generic PWS.f
5600.6792

Microsoft Security Essentials
Trojan:Win32/Dynamer!ac
1.1.11502.0

MicroWorld eScan
Gen:Variant.Graftor.Elzob.10473
16.0.0.324

NANO AntiVirus
Trojan.Win32.QQShou.kidp
0.30.8.659

Norman
Banker.A!genr
11.20150418

Panda Antivirus
Trojan Horse
15.04.18.09

Qihoo 360 Security
Malware.Radar01.Gen
1.0.0.1015

Rising Antivirus
PE:Trojan.PSW.QQShou.a!1173763877
23.00.65.15416

Sophos
Mal/Behav-156
4.98

Total Defense
Win32/QQshou!generic
37.0.11533

Trend Micro House Call
TSPY_QQPASS.GEN
7.2.108

Trend Micro
TSPY_QQPASS.GEN
10.465.18

Vba32 AntiVirus
TrojanPSW.QQShou
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
39098

Zillya! Antivirus
Trojan.QQShou.Win32.1434
2.0.0.2128

File size:
50.6 KB (51,793 bytes)

Product version:
1, 0, 0, 1

Copyright:
版权所有 (C) Microsoft 2004

Original file name:
system.exe

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\f656f03daf7f80efdc0dbd712583f300.pe

File PE Metadata
Compilation timestamp:
4/30/2004 12:12:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:TLler29epBneGx6cDoM8Sm3TNQudv6cSpgMZBUno23pYMRHE:vlGlxZDonyAvugaGnv3ppRk

Entry address:
0x3B1A

Entry point:
55, 8B, EC, 6A, FF, 68, 20, 55, 40, 00, 68, A6, 3C, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 50, 52, 40, 00, 59, 83, 0D, A0, 77, 40, 00, FF, 83, 0D, A4, 77, 40, 00, FF, FF, 15, 54, 52, 40, 00, 8B, 0D, 94, 77, 40, 00, 89, 08, FF, 15, 58, 52, 40, 00, 8B, 0D, 90, 77, 40, 00, 89, 08, A1, 5C, 52, 40, 00, 8B, 00, A3, 9C, 77, 40, 00, E8, 1C, 01, 00, 00, 39, 1D, C8, 75, 40, 00, 75, 0C, 68, A2, 3C, 40, 00, FF, 15, 60, 52...
 
[+]

Entropy:
5.0559

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
12 KB (12,288 bytes)

Remove f656f03daf7f80efdc0dbd712583f300.pe - Powered by Reason Core Security