websteroidsservice.exe

The executable websteroidsservice.exe has been detected as malware by 4 anti-virus scanners.
MD5:
4a1153e7764eb0629da5796109d9632b

SHA-1:
3ea875a72d70ba6811572fda44d02b8d955a3a98

SHA-256:
3bcec7a8d3622158d6a9b1c311e9ca060520c39f2e8bfb4746fc9042e5f20971

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
4/23/2024 8:42:27 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

Dr.Web
Trojan.Damaged.1
9.0.1.05190

Reason Heuristics
Threat.Win.Reputation
15.4.20.21

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10468

File size:
60.4 KB (61,816 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Application data\websteroids\websteroidsservice.exe

File PE Metadata
Compilation timestamp:
3/22/2014 4:33:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:2LnfTVnTzwCByzI8PLxm4w9caUo3ZWvnbDjB5JXjL:2rTVTs+yMkU4w9caUoQnbDjrxL

Entry address:
0xEBBE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 50, 00, 00, 80, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8516

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
51 KB (52,224 bytes)

Remove websteroidsservice.exe - Powered by Reason Core Security