microsec.exe

Cobind

The application microsec.exe by Cobind has been detected as a potentially unwanted program by 3 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Microsoft SEC’.
Publisher:
Cobind  (signed and verified)

MD5:
d48f7564665c2d183afb776511a2d8f3

SHA-1:
a96e5ff1a0c3f4da369483fbe2502bdafbe2ed20

SHA-256:
4333f602fbe0a2a65340b4c06df62506e1b91100470367e0d31855b163d71ef9

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 7:30:20 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Evo-gen [Susp]
160807-0

ESET NOD32
MSIL/Injector.PZX trojan
6.3

Reason Heuristics
Adware.Cobind.Kryptic (M)
16.10.4.11

File size:
409.4 KB (419,232 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\microsec\microsec.exe

Digital Signature
Signed by:

Authority:
Cobind

Valid from:
8/5/2016 7:06:03 PM

Valid to:
8/3/2026 7:06:03 PM

Subject:
E=admin@cobind.com, CN=cobind.com, OU=Ques Unit, O=Cobind, L=New York City, S=New York, C=US

Issuer:
E=admin@cobind.com, CN=cobind.com, OU=Ques Unit, O=Cobind, L=New York City, S=New York, C=US

Serial number:
00ABF3127C9761E782

File PE Metadata
Compilation timestamp:
8/6/2016 6:08:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:jzc3UxqKTsFKpjHW8eUH2HGFCBSrGTIOCUvgNcq5IOvfi3AclQdmP/LPy9RkYd:jw3UMIGE2g+SrGsUvY5IcdmP/LLYd

Entry address:
0x58B8E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6711

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
348 KB (356,352 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Microsoft SEC

Command:
C:\users\{user}\appdata\roaming\microsec\microsec.exe


Remove microsec.exe - Powered by Reason Core Security