Z-VSScopy.exe

Z-VSScopy

Andreas Baumann

It runs as a separate (within the context of its own process) windows Service named “Z-VSScopy”.
Publisher:
IMU-BerliNet  (signed by Andreas Baumann)

Product:
Z-VSScopy

Description:
Volume Shadow Client

Version:
1.07.0008

MD5:
f5849d567b30966a08fe2d6c3025eb34

SHA-1:
fe6ca6a2e7166fd0cd2368a6b135d7b614206335

SHA-256:
261e2f80f5026b1baca99abf143205f6a9c8f799f7ef3105b6cc4d795e218275

Scanner detections:
4 / 68

Status:
Clean  (4 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/19/2024 2:11:52 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Dr.Web
BACKDOOR.Trojan
9.0.1.079

McAfee
Artemis!F5849D567B30
5600.6821

Trend Micro House Call
Suspicious_GEN.F47V0723
7.2.79

File size:
740.6 KB (758,376 bytes)

Product version:
1.07.0008

Copyright:
© Andreas Baumann 2010 - 2013

Original file name:
Z-VSScopy.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\z-vsscopy\z-vsscopy.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/10/2012 5:30:00 AM

Valid to:
2/19/2014 5:29:59 AM

Subject:
CN=Andreas Baumann, OU=SECURE APPLICATION DEVELOPMENT, O=Andreas Baumann, L=Berlin, S=Berlin, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
753BC7598F9981E43A04D477D6382D3D

File PE Metadata
Compilation timestamp:
11/6/2012 7:28:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:u/q4juHsbSTuDtTwgFXi5phGJeWsqU3Ge0dnmH+FwwnHabzPWMWUX48X:u/q4yHs2QwgFXi5phGJeWsqU3Ge0dnmr

Entry address:
0x9008

Entry point:
B8, D4, 46, 68, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 98, 4B, BC, 28, 7C, AD, E9, B3, 4F, 13, 74, F2, CE, 34, 59, BE, 09, 97, A5, 97, 35, 6A, 48, CC, 11, 7D, A5, C6, CC, CD, 38, 39, 16, D1, 60, 05, D9, 65, 7B, FC, C0, E1, 78, 2A, DD, 2F, C1, C8, 7C, 01, BA, 28, D4, FB, 76, 08, 41, 17, 5D, EA, 4A, 68, 33, E6, B0, 96, 51, 25, 71, B1, 23, 9E, 98, 55, 5A, E7, 01, E0, 9C, 33, A5, 80, 47, EC, 46, F4, 55, 31, 69, F3, F2, 77, 34...
 
[+]

Entropy:
6.8107

Packer / compiler:
PECompact v2

Code size:
1.6 MB (1,683,456 bytes)

Service
Display name:
Z-VSScopy

Description:
Allows Z-DBackup and Z-VssCopy to access the volume shadow copies of Windows.

Type:
Win32OwnProcess


The file Z-VSScopy.exe has been discovered within the following program.

Z-VSScopy  by IMU Andreas Baumann
http:\\www.z-dbackup.de
About 4% of users remove it
 
Powered by Should I Remove It?

Scan Z-VSScopy.exe - Powered by Reason Core Security