winplugin.exe

PluginSeg

FC Group Corporation LTDA

The executable winplugin.exe, “Segurança Interna” has been detected as malware by 31 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PluginSeg’.
Publisher:
FCLab CopyRight  (signed by FC Group Corporation LTDA)

Product:
PluginSeg

Description:
Segurança Interna

Version:
3.0.1.7

MD5:
2a9d71aedef564dad9fc09d4d5be012a

SHA-1:
644a6d9621fa162357b790152316257c4e69caa9

SHA-256:
89f50cfa3675298a1e2b18f4d51e690ab00a997adde06755f36be2c381b983fd

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
11/29/2024 9:24:59 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.172301
17.01.25

AegisLab AV Signature
Troj.Downloader.W32.Gen
2.1.4+

Agnitum Outpost
Trojan.PWS.BestaFera
7.1.1

AhnLab V3 Security
Malware/Gen.Generic
2015.12.19

Avira AntiVirus
TR/Spy.Banker.Gen
8.3.2.4

Arcabit
Trojan.Zusy.D2A10D
1.0.0.629

avast!
Win32:Malware-gen
2014.9-170125

AVG
PSW.Banker7
2018.0.2487

Baidu Antivirus
Trojan.Win32.Banker
4.0.3.17125

Bitdefender
Gen:Variant.Zusy.172301
1.0.20.125

Comodo Security
UnclassifiedMalware
23790

Dr.Web
Trojan.DownLoader18.7458
9.0.1.025

Emsisoft Anti-Malware
Gen:Variant.Zusy.172301
8.17.01.25.08

ESET NOD32
Win32/Spy.Banker.ABMV (variant)
11.12744

Fortinet FortiGate
W32/Banker.ABMV!tr.spy
1/25/2017

F-Secure
Gen:Variant.Zusy.172301
11.2017-25-01_4

G Data
Gen:Variant.Zusy.172301
17.1.25

IKARUS anti.virus
Trojan-Spy.Agent
t3scan.1.9.5.0

K7 AntiVirus
Spyware
13.212.18156

Kaspersky
Trojan-Banker.Win32.BestaFera
14.0.0.-1069

Malwarebytes
Trojan.Banker.NCU
v2017.01.25.08

McAfee
Artemis!2A9D71AEDEF5
5600.6143

Microsoft Security Essentials
TrojanSpy:Win32/Banker!rfn
1.1.12400.0

MicroWorld eScan
Gen:Variant.Zusy.172301
18.0.0.75

NANO AntiVirus
Trojan.Win32.DownLoader18.dzezki
1.0.10.5081

Panda Antivirus
Trj/CI.A
17.01.25.08

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.17123

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R00GC0DLD15
10.465.25

VIPRE Antivirus
Trojan.Win32.Generic
45916

ViRobot
Trojan.Win32.A.BestaFera.5655336[h]
2014.3.20.0

File size:
5.4 MB (5,655,336 bytes)

Product version:
3.0.1.7

Copyright:
FCLab CopyRight

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\appdata\roaming\winplugin.exe

Digital Signature
Authority:
FC Group Corporation LTDA

Valid from:
12/7/2015 5:28:06 PM

Valid to:
12/4/2025 5:28:06 PM

Subject:
E=carlosant30@hotmail.com, CN=Carlos B, OU=FC Group LTDA, O=FC Group Corporation LTDA, L=Sao Paulo, S=Sao Paulo, C=BR

Issuer:
E=carlosant30@hotmail.com, CN=Carlos B, OU=FC Group LTDA, O=FC Group Corporation LTDA, L=Sao Paulo, S=Sao Paulo, C=BR

Serial number:
009E743FF5EAF0B266

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xEFCC8

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, B8, 20, F8, 00, 08, E8, 72, 6B, F1, FF, 68, F0, FD, 00, 08, E8, F4, 77, F1, FF, 8B, F0, 68, F0, FD, 00, 08, 6A, FF, 6A, 00, E8, 64, 6E, F1, FF, 8B, D8, 85, DB, 74, 0C, E8, 61, 6F, F1, FF, 3D, B7, 00, 00, 00, 75, 14, 6A, 00, 6A, 00, 56, 68, FF, FF, 00, 00, E8, FB, 77, F1, FF, E9, CE, 00, 00, 00, A1, 0C, 80, 01, 08, 8B, 00, E8, 82, 64, F8, FF, A1, 0C, 80, 01, 08, 8B, 00, BA, 04, FE, 00, 08, E8, 69, 60, F8, FF, A1, 0C, 80, 01, 08, 8B, 00, C6, 40, 5B, 00, 8B, 0D, D4, 81, 01, 08...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
956 KB (978,944 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PluginSeg

Command:
C:\users\{user}\appdata\roaming\winplugin.exe


Remove winplugin.exe - Powered by Reason Core Security