qkseeSvc.exe

qksee

Yanling Sun

The executable qkseeSvc.exe has been detected as malware by 10 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “qkseeService”.
Publisher:
Qksee Pvt Ltd.  (signed by Yanling Sun)

Product:
qksee

Description:
qksee service

Version:
3.2.33.81

MD5:
953bec2b4d1a51fd062f9ee303d4eb60

SHA-1:
f23893471ed5287016294ea18cacf07a273003c6

SHA-256:
39e3cfa8a66ec5032e68d6fa080bb6009f4e93dc49d7dd4d5b1ea322287df9e5

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
12/30/2024 8:54:45 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Pioneer-C
160518-2

AVG
Win32/Floxif.A
2015.0.4591

Dr.Web
Win32.FloodFix.7
9.0.1.05190

Emsisoft Anti-Malware
Win32.Floxif
11.5.0.6191

ESET NOD32
Win32/Floxif.H virus
8.0.319.0

F-Prot
W32/Floxif.B
4.6.5.141

Kaspersky
Virus.Win32.Pioneer
15.0.0.562

McAfee
Trojan.Dropper-FIY!953BEC2B4D1A
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.1465.0

Norman
Win32.Floxif.A
28.05.2016 13:03:37

File size:
820 KB (839,703 bytes)

Product version:
3.2.33.81

Copyright:
Copyright (c) 2015 Qksee Pvt Ltd. All Rights Reserved.

Original file name:
qkseeSvc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\qksee\qkseesvc.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/31/2016 5:00:00 PM

Valid to:
11/25/2016 3:59:59 PM

Subject:
CN=Yanling Sun, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
160B6F060C70190331C421618BBE6994

File PE Metadata
Compilation timestamp:
6/1/2016 5:03:07 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:bK/tMUc41JWmzy1Mhf4ba8CJT9TtRmNYrEH70:W/tFbuK6sJ5Ttkq

Entry address:
0x59EDC

Entry point:
E9, 03, 1D, FE, FF, E9, 7F, FE, FF, FF, 55, 8B, EC, 51, 83, 65, FC, 00, 56, 8D, 45, FC, 50, FF, 75, 0C, FF, 75, 08, E8, 2D, D5, 00, 00, 8B, F0, 83, C4, 0C, 85, F6, 75, 18, 39, 45, FC, 74, 13, E8, FA, 16, 00, 00, 85, C0, 74, 0A, E8, F1, 16, 00, 00, 8B, 4D, FC, 89, 08, 8B, C6, 5E, C9, C3, 55, 8B, EC, 8B, 45, 0C, 8B, 4D, 08, 83, EC, 0C, 85, C0, 74, 02, 89, 08, 85, C9, 75, 14, E8, CC, 16, 00, 00, C7, 00, 16, 00, 00, 00, E8, 7E, 47, 00, 00, 33, C0, C9, C3, 8B, 45, 10, 85, C0, 74, 0A, 83, F8, 02, 7C, E0, 83, F8...
 
[+]

Entropy:
6.2699

Packer / compiler:
Xtreme-Protector v1.05

Code size:
477.5 KB (488,960 bytes)

Service
Display name:
qkseeService

Type:
Win32OwnProcess

Group:
SchedulerGroup


Remove qkseeSvc.exe - Powered by Reason Core Security