msvs.exe

Local Management Service

Intel(R)

The executable msvs.exe has been detected as malware by 14 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Intel(R) Local Management Service’.
Publisher:
Intel(R)

Product:
Local Management Service

Version:
1.424.56.3248

MD5:
2b40c40d1dd0d420c12f90c33b955268

SHA-1:
1ea458ecea88c9b8d99b36a86e8413676b85acc2

SHA-256:
33794aaa5138a9ebc6fd6b99265a520297f0dc37e08466463821e7ba46acc591

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
11/27/2024 11:44:25 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1944686
812

AVG
CoinMiner
2015.0.3290

Baidu Antivirus
Trojan.Win32.CoinMiner
4.0.3.141115

Bitdefender
Trojan.GenericKD.1944686
1.0.20.1595

Emsisoft Anti-Malware
Trojan.GenericKD.1944686
8.14.11.15.03

ESET NOD32
Win32/CoinMiner.VG
8.10657

F-Secure
Trojan.GenericKD.1944686
11.2014-15-11_7

G Data
Trojan.GenericKD.1944686
14.11.24

IKARUS anti.virus
Trojan.CoinMiner
t3scan.1.8.3.0

McAfee
Artemis!2B40C40D1DD0
5600.6946

nProtect
Trojan.GenericKD.1944686
14.10.31.01

Sophos
Mal/Generic-S
4.98

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
34448

File size:
65.5 KB (67,072 bytes)

Product version:
1.1.0.0

Copyright:
Intel(R) Local Management Service

Trademarks:
Intel(R)

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\users\{user}\appdata\roaming\intel\services\msvs.exe

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
768:KZ8KC6wixaptzXjYSAiAF/Q9KZoKx8Lkk4ykk81vwnWEmo4ttxHlzuI30lJBkvTQ:KAdTAiAFZ3CCkmvDDLHlzr3+Wvjxm

Entry address:
0x99D8

Entry point:
55, 8B, EC, 83, C4, E4, 53, 56, 33, C0, 89, 45, E8, 89, 45, E4, 89, 45, EC, B8, 68, 99, 40, 00, E8, 5F, B6, FF, FF, BB, B0, B7, 40, 00, BE, F4, B7, 40, 00, 33, C0, 55, 68, 44, 9B, 40, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 5C, 9B, 40, 00, E8, BA, F0, FF, FF, 8B, 55, EC, B8, A0, A2, 40, 00, E8, 31, A1, FF, FF, B8, 0C, B8, 40, 00, E8, AF, FB, FF, FF, 84, C0, 74, 10, B8, A0, A2, 40, 00, 8B, 15, 0C, B8, 40, 00, E8, 13, A1, FF, FF, 6A, 00, 6A, 00, 68, 10, B8, 40, 00, B9, 9C, 98, 40, 00, 33, D2, 33, C0, E8...
 
[+]

Entropy:
5.9644

Developed / compiled with:
Microsoft Visual C++

Code size:
35 KB (35,840 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Intel(R) Local Management Service

Command:
C:\users\{user}\appdata\roaming\intel\services\msvs.exe


Remove msvs.exe - Powered by Reason Core Security