WmiPrvSE.exe

WmiPrvSE.exe

The executable WmiPrvSE.exe, “Windows Media Service” has been detected as malware by 7 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WmiPrv’.
Publisher:
Microsoft*  (Invalid match)

Product:
WmiPrvSE.exe

Description:
Windows Media Service

Version:
11.1.0.3

MD5:
ac09bd1e8b85d95b4fb8fceefc5fe473

SHA-1:
dfce585e0c90eb116d25406556f3f2bd222e15b6

SHA-256:
b67316ba4f1beb7bd668500c47d852dc7c92d4576e0f7ee94cc654c8d4028fde

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/25/2024 11:14:13 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Dropper/Win32.Urelas
14.03.30

avast!
Win32:Malware-gen
2014.9-140330

Baidu Antivirus
Trojan.Win32.Dropper
4.0.3.14330

Comodo Security
UnclassifiedMalware
17946

ESET NOD32
Win32/TrojanDropper.Agent.QMS (variant)
8.9553

G Data
Win32.Trojan.Agent.WXUH6H
14.3.24

Trend Micro House Call
TROJ_GEN.F47V0306
7.2.89

File size:
567 KB (580,608 bytes)

Product version:
11.1.0.3

Copyright:
Copyright (C) 2013

Original file name:
WmiPrvSE.exe

File type:
Executable application (Win32 EXE)

Language:
angol (Jamaica)

Common path:
C:\users\{user}\appdata\roaming\adobe\wmiprv\wmiprvse.exe

File PE Metadata
Compilation timestamp:
3/4/2014 7:22:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:XNG1fGf7mUn1iQa9JPQlXhuqF3l9x+lUUlqkt548PaBlx8OHvtIBO:F7V1l0GBhXX9azDJ2FHvtIBO

Entry address:
0x110D1

Entry point:
E8, 5D, 1C, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, D0, 92, 41, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 04, 91, 41, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, E8, 39, 18, 00, 00, 85, C0, 74, 07, 50, E8, F1, 19, 00, 00, 59, FF, 75, 08, FF, 15, 08, 91, 41, 00, CC, 6A, 0C, 68, 78, 83, 48, 00, E8, FE, 0A, 00...
 
[+]

Code size:
92.5 KB (94,720 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WmiPrv

Command:
C:\users\{user}\appdata\roaming\adobe\wmiprv\wmiprvse.exe


Remove WmiPrvSE.exe - Powered by Reason Core Security