wallsvr.exe

LivePlex Corp

The application wallsvr.exe by LivePlex Corp has been detected as a potentially unwanted program by 22 anti-malware scanners.
Publisher:
LivePlex Corp  (signed and verified)

MD5:
104c1712c72f5ec3ed502b6a70481a93

SHA-1:
4ab317f4311f4a34710377e1adbca8e3b6967ae5

SHA-256:
b8d277312afe911dd9640b867268d77ad560754659a4c04f0deba78cc477feb0

Scanner detections:
22 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 12:15:36 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.576932
144

Agnitum Outpost
PUA.Agent
7.1.1

AVG
Generic6
2017.0.2622

Bitdefender
Gen:Variant.Kazy.576932
1.0.20.1280

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
ApplicUnwnt
21597

Emsisoft Anti-Malware
Gen:Variant.Kazy.576932
8.16.09.12.05

ESET NOD32
Win32/Adware.SBYinYing (variant)
10.11403

Fortinet FortiGate
Adware/Agent
9/12/2016

F-Secure
Gen:Variant.Kazy.576932
11.2016-12-09_2

G Data
Gen:Variant.Kazy.576932
16.9.25

K7 AntiVirus
Riskware
13.202.15432

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.-394

McAfee
Artemis!104C1712C72F
5600.6278

MicroWorld eScan
Gen:Variant.Kazy.576932
17.0.0.768

NANO AntiVirus
Riskware.Win32.Agent.dpmnjx
0.30.8.659

Panda Antivirus
Generic Suspicious
16.09.12.05

Qihoo 360 Security
Win32/Virus.Adware.fca
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R01TC0ECU15
7.2.256

Trend Micro
TROJ_GEN.R01TC0ECU15
10.465.12

VIPRE Antivirus
Trojan.Win32.Generic
38922

Zillya! Antivirus
Adware.Agent.Win32.48494
2.0.0.2122

File size:
14.9 KB (15,256 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\c80r013w\wallsvr.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/9/2012 8:00:00 AM

Valid to:
6/9/2014 7:59:59 AM

Subject:
CN=LivePlex Corp, O=LivePlex Corp, L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3F5542E2E71D8DB357041C9DD45B950A

File PE Metadata
Compilation timestamp:
7/25/2014 5:11:14 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
192:wvEmTuI5mJRlqZlmFm3fCItteZXY8QC78A7tA39sPtp9jn7mK8tF0ou7+wv:AEmCRQZlmFmZXWI8QC3tBBauh

Entry address:
0x1A4A

Entry point:
E8, E2, 02, 00, 00, E9, 91, FE, FF, FF, 55, 8B, EC, FF, 15, 84, 30, 40, 00, 6A, 01, A3, 5C, 43, 40, 00, E8, 53, 05, 00, 00, FF, 75, 08, E8, 51, 05, 00, 00, 83, 3D, 5C, 43, 40, 00, 00, 59, 59, 75, 08, 6A, 01, E8, 39, 05, 00, 00, 59, 68, 09, 04, 00, C0, E8, 3A, 05, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 5D, 05, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 40, 41, 40, 00, 89, 0D, 3C, 41, 40, 00, 89, 15, 38, 41, 40, 00, 89, 1D, 34, 41, 40, 00, 89, 35, 30, 41, 40, 00, 89, 3D, 2C...
 
[+]

Entropy:
5.9679

Code size:
4.5 KB (4,608 bytes)

Remove wallsvr.exe - Powered by Reason Core Security