winservice86

winservice86

Known Malware

by Monkey Code Lab

What is winservice86?

winservice86 is software application developed by Monkey Code Lab. It is most commonly found on computers running Windows 7 with nearly 63.45% of installations running this operating system. winservice86's installer is typically 16.00 MB in size and installs around 498 files. The most common release is 1.36.01.22 with 54.82% of all installations currently using this version.

winservice86 is most popular in France with 33.33% of installations residing in this country.

winservice86 adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

Multiple virus scanners have detected malware in winservice86.

23140e48-208d-414b-9c88-2020b4a80c85-7.exe (MD5: b414477094f306254c7396d461829be4) has been flagged by 40 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.7u1@mK88uPcO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kyc
avast! Win32:Malware-gen
AVG Generic.619
Avira Adware/CrossRid.bqyp
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.bBM
Bitdefender Gen:Application.Heur.7u1@mK88uPcO
Dr.Web Trojan.Crossrider1.4239
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.BM potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Secure Gen:Application.Heur.7u1@mK88uPcO
G Data Gen:Application.Heur.7u1@mK88uPcO
K7 AntiVirus Unwanted-Program ( 0040f9e41 )
K7GW Unwanted-Program ( 0040f9e41 )
Malwarebytes PUP.Optional.WinService.A
MicroWorld-eScan Gen:Application.Heur.7u1@mK88uPcO
NANO AntiVirus Trojan.Win32.Crossrider1.dmjpuj
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.de5
Sophos AppRider
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.F0C2C00AH15
TrendMicro-HouseCall TROJ_GEN.F0C2C00AH15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2051
Comodo Security Application.Win32.Plush.GRI
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
F-Prot W32/A-1a27c920!Eldorado
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.hcd
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
nProtect Trojan/W32.Agent.1965976
Symantec Adware.Crossid
Clam AntiVirus Win.Adware.Crossrider-40
IKARUS anti.virus Trojan.GoogUpdate
McAfee Artemis!1165C7702FE8
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Vba32 AntiVirus Trojan.GoogUpdate
Rising Antivirus PE:Malware.Obscure!1.9C59
23140e48-208d-414b-9c88-2020b4a80c85-6.exe (MD5: f68c0a9ca8aa6a97dd607a72eb10b9bf) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.mz1@mawQAjpi
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kyc
avast! Win32:Malware-gen
AVG Generic.619
Avira Adware/CrossRid.bqyp
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BBM
Bitdefender Gen:Application.Heur.mz1@mawQAjpi
Cyren W32/Application.IOZQ-6442
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.BZ potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Secure Gen:Application.Heur.mz1@mawQAjpi
G Data Gen:Application.Heur.mz1@mawQAjpi
K7 AntiVirus Unwanted-Program ( 0040f9e41 )
K7GW Unwanted-Program ( 0040f9e41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kyc
Malwarebytes PUP.Optional.WinService.A
McAfee Artemis!F68C0A9CA8AA
McAfee-GW-Edition Artemis
MicroWorld-eScan Gen:Application.Heur.mz1@mawQAjpi
NANO AntiVirus Riskware.Win32.CrossRid.dmyzri
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos AppRider
Symantec Adware.Crossid
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.F0C2C00AL15
TrendMicro-HouseCall TROJ_GEN.F0C2C00AL15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2474
ALYac Gen:Variant.Adware.Graftor.171733
Bkav FE W32.HfsAdware.3F0C
CAT-QuickHeal PUA.BrightCircle.OD6
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
Dr.Web Trojan.Crossrider1.23209
SUPERAntiSpyware Adware.CrossRider/Variant
Clam AntiVirus Win.Adware.Crossrider-240
Comodo Security Application.Win32.Plush.GRI
F-Prot W32/Crossrider.C.gen!Eldorado
Vba32 AntiVirus AdWare.Adwapper
IKARUS anti.virus AdWare.PlusHD
Rising Antivirus PE:Trojan.Win32.Generic.178C41CB!395067851
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
nProtect Trojan/W32.Agent.1965976
23140e48-208d-414b-9c88-2020b4a80c85-5.exe (MD5: 61872efb4a83667059dd092f2335b969) has been flagged by 50 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.9u1@m4MLyPjO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kyc
Arcabit Application.Heur.EDF9C
avast! Win32:PUP-gen [PUP]
AVG Generic.619
Avira ADWARE/CrossRid.bqyp
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CC
Bitdefender Gen:Application.Heur.9u1@m4MLyPjO
Bkav FE W32.HfsAdware.52D8
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security ApplicUnwnt
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.23051
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CC potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Application.Heur.9u1@m4MLyPjO
G Data Gen:Application.Heur.9u1@m4MLyPjO
K7 AntiVirus Unwanted-Program ( 0040f9e41 )
K7GW Unwanted-Program ( 0040f9e41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kyc
Malwarebytes PUP.Optional.WinService.A
McAfee Artemis!61872EFB4A83
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.9u1@m4MLyPjO
NANO AntiVirus Trojan.Win32.Crossrider1.dmjicz
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Application.c72
Rising Antivirus PE:Malware.Adwapper!6.2370
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.F0C2C00AI15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2052
Jiangmin AdWare/NSIS.csm
nProtect Trojan-Clicker/W32.Agent.1013216
Sophos AppRider
TrendMicro-HouseCall TROJ_GEN.F0C2C00LN14
Vba32 AntiVirus AdWare.Adwapper
ViRobot Trojan.Win32.S.Agent.1013216[h]
Agnitum Outpost PUA.Toolbar.CrossRider!
IKARUS anti.virus Trojan.GoogUpdate
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
Kingsoft AntiVirus Win32.Troj.NSIS.ck.(kcloud)
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
ALYac Gen:Variant.Adware.Kazy.133003
Clam AntiVirus Win.Adware.Crossrider-273
22bb7416-1ab9-4baa-a8a1-f1ff9d076722-7.exe (MD5: c2cc839b0161c24b3eeac644945ebe58) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.ev1@mi6sYHlO
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Crossrider-AH [PUP]
AVG Generic.EC3
Avira ADWARE/CrossRider.Gen7
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BBM
Bitdefender Gen:Application.Heur.ev1@mi6sYHlO
Bkav FE W32.HfsAdware.3878
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.46104
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.BM potentially unwanted
Fortinet FortiGate Adware/Adwapper
F-Prot W32/S-a64d6097!Eldorado
F-Secure Gen:Application.Heur.ev1@mi6sYHlO
G Data Gen:Application.Heur.ev1@mi6sYHlO
K7 AntiVirus Unwanted-Program ( 0040f9a31 )
K7GW Unwanted-Program ( 0040f9a31 )
Malwarebytes PUP.Optional.WinService.A
McAfee Artemis!C2CC839B0161
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.ev1@mi6sYHlO
NANO AntiVirus Riskware.Win32.Crossrider.dkbbfq
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.a87
Sophos AppRider
Symantec Trojan.Gen
Tencent Win32.Adware.Bp-browser.Luqs
TrendMicro-HouseCall TROJ_GEN.R047C0EAF15
Vba32 AntiVirus AdWare.Adwapper
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Adwapper.Win32.1740
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
CAT-QuickHeal Trojan.NSIS.r5
Kaspersky Trojan.NSIS.GoogUpdate.cq
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Trend Micro TROJ_GEN.R0C1C0EJH14
Clam AntiVirus Win.Trojan.Crossrider-201
nProtect Trojan/W32.Agent.346480.B
ALYac Adware.Generic.1104710
Cyren W32/Adware.LDOS-2899
Emsisoft Anti-Malware Adware.Generic.1104710 (B)
Rising Antivirus PE:Malware.Obscure!1.9C59
SUPERAntiSpyware Adware.CrossRider/Variant
IKARUS anti.virus AdWare.PlusHD
22bb7416-1ab9-4baa-a8a1-f1ff9d076722-5.exe (MD5: 96499ff5f9dca4bce17d8c1055c4af7c) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.av1@myIFbEkO
AhnLab-V3 Win-PUP/CrossRider
avast! Win32:Crossrider-AO [PUP]
AVG Generic.EC3
Avira ADWARE/CrossRider.Gen7
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.BM
Bitdefender Gen:Application.Heur.av1@myIFbEkO
Bkav FE W32.HfsAdware.436B
Dr.Web Trojan.Crossrider.46105
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.BM potentially unwanted
Fortinet FortiGate Adware/Adwapper
F-Prot W32/Crossrider.C.gen!Eldorado
F-Secure Gen:Application.Heur.av1@myIFbEkO
G Data Gen:Application.Heur.av1@myIFbEkO
K7 AntiVirus Unwanted-Program ( 0040f9a31 )
K7GW Unwanted-Program ( 0040f9a31 )
Malwarebytes PUP.Optional.WinService.A
McAfee Artemis!96499FF5F9DC
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.av1@myIFbEkO
NANO AntiVirus Riskware.Win32.Crossrider.djtdpu
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos AppRider
Symantec Trojan.Gen
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.F0C2C00AA15
TrendMicro-HouseCall TROJ_GEN.F0C2C00AA15
Vba32 AntiVirus AdWare.Adwapper
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Adwapper.Win32.1747
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kti
CAT-QuickHeal PUA.BrightCircle.OD6
Cyren W32/Adware.GHOG-5847
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kti
SUPERAntiSpyware Adware.CrossRider/Variant
Comodo Security ApplicUnwnt
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Clam AntiVirus Win.Trojan.Crossrider-201
nProtect Trojan/W32.Agent.346480.B
ALYac Adware.Generic.1104710
Rising Antivirus PE:Malware.Obscure!1.9C59
IKARUS anti.virus AdWare.PlusHD

Software Behaviors

Scheduled tasks:
  • 3be52380-8490-4173-80e9-b8e732adda95-1-6.exe is scheduled as a task named 'temp_2ca94415-973a-4c2c-99ef-43bb1755b01f-1-6'.
  • 68b93107-26be-4261-b20c-cd026d23dd77-7.exe is scheduled as a task named 'af48fba3-5a3c-407d-8670-3285e63a4f69-1'.
  • b3f660ed-2a88-4aee-a875-12a4c7108a59-7.exe is scheduled as a task named '4773723a-48ea-4c31-9e3c-3e88a7bf1f9d-1'.
  • b3190522-2363-4211-8554-f06830c0a829-4.exe is scheduled as a task named 'b3190522-2363-4211-8554-f06830c0a829-4'.
  • 22bb7416-1ab9-4baa-a8a1-f1ff9d076722-5.exe is scheduled as a task named '22bb7416-1ab9-4baa-a8a1-f1ff9d076722-5'.
  • 22bb7416-1ab9-4baa-a8a1-f1ff9d076722-12.exe is scheduled as a task named 'temp_22bb7416-1ab9-4baa-a8a1-f1ff9d076722-12'.

Startup Entries

Startup tasks:
  • c79089b8-ce15-4c74-a299-651c5bfa67ef-1-7.exe is automatically launched at startup through a scheduled task named c79089b8-ce15-4c74-a299-651c5bfa67ef-7.
  • b0a5a83e-48d6-4747-b918-a68e5d09e50a-10.exe is automatically launched at startup through a scheduled task named b0a5a83e-48d6-4747-b918-a68e5d09e50a-10_user.
  • b0a5a83e-48d6-4747-b918-a68e5d09e50a-7.exe is automatically launched at startup through a scheduled task named b0a5a83e-48d6-4747-b918-a68e5d09e50a-1-7.
  • 3be52380-8490-4173-80e9-b8e732adda95-1-6.exe is automatically launched at startup through a scheduled task named b0a5a83e-48d6-4747-b918-a68e5d09e50a-1-6.
  • 4b7f72ce-8bc7-4810-9ddf-c36466028e74-1-7.exe is automatically launched at startup through a scheduled task named 4b7f72ce-8bc7-4810-9ddf-c36466028e74-7.
  • 4b7f72ce-8bc7-4810-9ddf-c36466028e74-10.exe is automatically launched at startup through a scheduled task named 4b7f72ce-8bc7-4810-9ddf-c36466028e74-10_user.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\winservice86
Uninstaller:
C:\Program Files\winservice86\Uninstall.exe /fcp=1
Size:
16.00 MB
Language:
English

winservice86 Executable Details

Primary executable:
utils.exe
Name:
winservice86
Path:
C:\Program Files\winservice86\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by winservice86
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
DLL
5e8e81170731f5521bf540e5e374b011
DLL
06bef001533cc9b2aee78e0315432f94
EXE
a0bdc8051a740904d9e5f24d697f6875
DLL
054eb97126c57f5476abc3c6f8586eab
DLL
55bbde7f48a5ef7a8254bfeb3a5a39d7
DLL
9161b2db6facc5aa59f5eae689ec05af
EXE
e55abe718c872d0b912f64456b3dcdea
EXE
b414477094f306254c7396d461829be4