wallsvr.exe

孙中元

The application wallsvr.exe by 孙中元 has been detected as a potentially unwanted program by 14 anti-malware scanners.
Publisher:
孙中元  (signed and verified)

MD5:
1bc40c2a9b318b318681d472ad11535a

SHA-1:
008ddc3de7aac656565c8279f4e2ec8fba2bacb3

SHA-256:
13483c2b45592c020da124f7a3839c295d3e8524059ceb54b7ba1631c93d8415

Scanner detections:
14 / 68

Status:
Potentially unwanted

Analysis date:
11/28/2024 4:36:13 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.576932
286

Arcabit
Trojan.Kazy.D8CDA4
1.0.0.568

AVG
Generic6
2017.0.2764

Bitdefender
Gen:Variant.Kazy.576932
1.0.20.570

Emsisoft Anti-Malware
Gen:Variant.Kazy.576932
8.16.04.23.06

ESET NOD32
Win32/Adware.SBYinYing (variant)
10.12356

F-Secure
Gen:Variant.Kazy.576932
11.2016-23-04_7

G Data
Gen:Variant.Kazy.576932
16.4.25

IKARUS anti.virus
Trojan-Clicker.Win32.StartPage
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.210.17419

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.316

MicroWorld eScan
Gen:Variant.Kazy.576932
17.0.0.342

Qihoo 360 Security
Win32/Trojan.e6d
1.0.0.1015

Vba32 AntiVirus
TrojanClicker.Agent
3.12.26.4

File size:
14.6 KB (14,992 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\liangxiawallpaper\wallsvr.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
1/6/2014 8:00:00 AM

Valid to:
1/6/2015 8:00:00 AM

Subject:
CN="Open Source Developer, 孙中元", O=孙中元, C=CN

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
1EFA0F2B42B625FC1E90EF0F3C093B28

File PE Metadata
Compilation timestamp:
1/3/2015 9:10:39 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
384:bEmS3NZlmFm5EbF8QC3tBqyZ9oafeBDbUYf:FiQ+tBxoai0w

Entry address:
0x1A5A

Entry point:
E8, E2, 02, 00, 00, E9, 91, FE, FF, FF, 55, 8B, EC, FF, 15, 84, 30, 40, 00, 6A, 01, A3, 5C, 43, 40, 00, E8, 53, 05, 00, 00, FF, 75, 08, E8, 51, 05, 00, 00, 83, 3D, 5C, 43, 40, 00, 00, 59, 59, 75, 08, 6A, 01, E8, 39, 05, 00, 00, 59, 68, 09, 04, 00, C0, E8, 3A, 05, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 5F, 05, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 40, 41, 40, 00, 89, 0D, 3C, 41, 40, 00, 89, 15, 38, 41, 40, 00, 89, 1D, 34, 41, 40, 00, 89, 35, 30, 41, 40, 00, 89, 3D, 2C...
 
[+]

Entropy:
5.9739

Code size:
4.5 KB (4,608 bytes)

Remove wallsvr.exe - Powered by Reason Core Security