cvs_mystartsearch.exe

4460_cvs_mystartsearch

Li Mo

The application cvs_mystartsearch.exe by Li Mo has been detected as adware by 23 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
Li Mo  (signed and verified)

Product:
4460_cvs_mystartsearch

Version:
7.0.1.4

MD5:
fda9ab822b5e6f498ca39a555915ea63

SHA-1:
8c5634a5a0c12b5db568e337dfc27b5f9b568654

SHA-256:
1fbe3bc24c14283034eea8690468679004ad7b745490e464a01619a36d08640d

Scanner detections:
23 / 68

Status:
Adware

Analysis date:
11/27/2024 12:56:17 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.1303122
462

Avira AntiVirus
TR/Crypt.ZPACK.175705
8.3.2.2

Arcabit
Adware.Generic.D13E252
1.0.0.425

Baidu Antivirus
Adware.Win32.ELEX
4.0.3.151031

Bitdefender
Adware.Generic.1303122
1.0.20.1520

Bkav FE
W32.HfsAdware
1.3.0.7133

Dr.Web
Adware.Mutabaha.634
9.0.1.0304

Emsisoft Anti-Malware
Adware.Generic.1303122
8.15.10.31.08

ESET NOD32
Win32/ELEX.EQ potentially unwanted (variant)
9.12149

Fortinet FortiGate
Riskware/LiMo
10/31/2015

G Data
Adware.Generic.1303122
15.10.25

K7 AntiVirus
Riskware
13.2017001

Malwarebytes
PUP.Optional.MyStartSearch.ShrtCln
v2015.10.31.08

McAfee
Artemis!FDA9AB822B5E
5600.6596

Microsoft Security Essentials
BrowserModifier:Win32/SupTab
1.1.12002.0

MicroWorld eScan
Adware.Generic.1303122
16.0.0.912

NANO AntiVirus
Riskware.Win32.Mutabaha.dvjvay
0.30.24.3079

Panda Antivirus
Trj/CI.A
15.10.31.08

Qihoo 360 Security
Win32/Trojan.e2b
1.0.0.1015

Reason Heuristics
PUP.ELEX.LiMo (M)
15.10.31.8

Sophos
Generic PUA IM (PUA)
4.98

Trend Micro
TROJ_GEN.R00JC0EHP15
10.465.31

VIPRE Antivirus
Trojan.Win32.Generic
43196

File size:
492.5 KB (504,344 bytes)

Product version:
7.0.1.4

Original file name:
demo.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\exe\666216dd04140db51c7272ddf2d6c926\cvs_mystartsearch.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
7/16/2015 2:00:00 AM

Valid to:
9/13/2016 2:00:00 PM

Subject:
CN=Li Mo, O=Li Mo, L=Guilin, S=Guangxi, C=CN

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
043D25C59C374D87F947A9A448031E94

File PE Metadata
Compilation timestamp:
8/14/2015 4:27:06 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:6cnxwqLhm6g16nJktbwQDVjXbJ2i8o+Atk04:6Ic6FnJkiQDVsid+z04

Entry address:
0x4B36B

Entry point:
E8, 90, 9C, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 14, 26, 47, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, B8, F5, 46, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 14, 26, 47, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F...
 
[+]

Code size:
388.5 KB (397,824 bytes)

Remove cvs_mystartsearch.exe - Powered by Reason Core Security