vosrv.exe

The application vosrv.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “VO Service component”.
MD5:
4bac9bc53202986eb35a22f4866b455a

SHA-1:
4614f3b76dcfd6a6f6590547c9fd65c14f2f4408

SHA-256:
0cdf3723e22a1943d2288af4b7b9fdbfb241db4a4a12f5a0778743a676bfca89

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 9:53:06 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Adware/Win32.Agent
2015.03.12

Avira AntiVirus
Adware/VOPack.133632.57
7.11.216.60

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150419

AVG
Generic_r
2016.0.3135

Baidu Antivirus
Adware.Win32.VOPackage
4.0.3.15419

ESET NOD32
Win32/VOPackage.BA potentially unwanted (variant)
9.11305

Fortinet FortiGate
Riskware/VOPackage
4/19/2015

IKARUS anti.virus
PUA.Vopackage
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.200.15235

McAfee
Artemis!4BAC9BC53202
5600.6791

NANO AntiVirus
Riskware.Win32.VOPack.dkwrnl
0.30.0.296

Norman
Suspicious_Gen4.IALLF
11.20150419

Panda Antivirus
Trj/Genetic.gen
15.04.19.05

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.4.19.1

Trend Micro House Call
TROJ_GEN.R002C0OBR15
7.2.109

Trend Micro
TROJ_GEN.R002C0OBR15
10.465.19

VIPRE Antivirus
Trojan.Win32.Generic
38344

File size:
130.5 KB (133,632 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\vopackage\vosrv.exe

File PE Metadata
Compilation timestamp:
12/13/2014 10:35:52 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:fbeltz7B4tPGYSijMmGy2BzqcEAy5QrZMUdq3vPbk:fbel5eSAHHED+PDk

Entry address:
0x6A11

Entry point:
E8, C9, 52, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 54, 53, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, D0, 1B, 42, 00, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, 40, 53, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 29, F3, A5, FF, 24, 95, A0, 6B, 40, 00, 8B...
 
[+]

Entropy:
6.5091

Code size:
101 KB (103,424 bytes)

Service
Display name:
VO Service component

Service name:
servervo

Description:
Ongoing updates responsible service.

Type:
Win32OwnProcess


Remove vosrv.exe - Powered by Reason Core Security