lhsvc.exe

TODO: <제품 이름>

TODO: <회사 이름>

The executable lhsvc.exe has been detected as malware by 17 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘lhsvc’.
Publisher:
TODO: <회사 이름>

Product:
TODO: <제품 이름>

Description:
TODO: <파일 설명>

Version:
1.0.0.1

MD5:
e504e0051c2feae50c33aa4b7848f005

SHA-1:
ad332dea9d333a189d4d15eada85940a79c7b2d2

Scanner detections:
17 / 68

Status:
Malware

Analysis date:
5/2/2024 3:02:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8639890
-40

Avira AntiVirus
TR/Rogue.8639890
7.11.208.112

avast!
Win32:Malware-gen
2014.9-170315

AVG
SHeur4
2018.0.2438

Bitdefender
Trojan.Generic.8639890
1.0.20.370

Comodo Security
Heur.Suspicious
20995

Dr.Web
Trojan.DownLoader7.52603
9.0.1.074

Emsisoft Anti-Malware
Trojan.Generic.8639890
8.17.03.15.09

F-Secure
Trojan.Generic.8639890
11.2017-15-03_4

G Data
Trojan.Generic.8639890
17.3.25

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.8.6.0

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1314

McAfee
Artemis!E504E0051C2F
5600.6094

MicroWorld eScan
Trojan.Generic.8639890
18.0.0.222

Norman
Troj_Generic.GUUVP
11.20170315

nProtect
Trojan.Generic.8639890
15.02.06.01

VIPRE Antivirus
Trojan.Win32.Generic
37332

File size:
1.7 MB (1,772,544 bytes)

Product version:
1.0.0.1

Copyright:
TODO: (c) <회사 이름>. All rights reserved.

Original file name:
Update0731.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\microhelper\lhsvc.exe

File PE Metadata
Compilation timestamp:
9/22/2012 5:51:05 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1040C9

Entry point:
E8, 42, 7F, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 84, 99, 57, 00, 75, 02, F3, C3, E9, C4, 7F, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, AF, 17, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, D4, 81, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 84, 42, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, F3, 17, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Entropy:
6.5032

Code size:
1.2 MB (1,230,848 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
lhsvc

Command:
C:\Program Files\microhelper\lhsvc.exe


Remove lhsvc.exe - Powered by Reason Core Security