13-4_vista_win7_win8_32-64_sb.exe

CATALYST 13-4

ATI Technologies ULC

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www2.ati.com and multiple other hosts.
Publisher:
Advanced Micro Devices, Inc.  (signed by ATI Technologies ULC)

Product:
CATALYST 13-4

Description:
13-4_vista_win7_win8_32-64_sb

Version:
0309

MD5:
4628c997b493582deccaa6df80fa271c

SHA-1:
8f4e8639e21d117cde9379032837fc7e2a47b5c6

SHA-256:
5f8aa422e94f1961af3e795db68e1d7248fc861ea7102dd3590b4ebfea71567c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:24:33 AM UTC  (today)

File size:
26.4 MB (27,696,104 bytes)

Copyright:
Advanced Micro Devices, Inc.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\ProgramData\drivergenius\downloads\13-4_vista_win7_win8_32-64_sb.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/13/2011 1:00:00 AM

Valid to:
1/9/2015 12:59:59 AM

Subject:
CN=ATI Technologies ULC, OU=Product Deployment, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ATI Technologies ULC, L=Markham, S=Ontario, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
67E18A6937AE14C8BBB829BE916650FF

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:RdpLtFYH7wZvx5YlJtky+oL13o2Ej1Yv7:Rdppebwt/EkV0Jz/7

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file 13-4_vista_win7_win8_32-64_sb.exe has been discovered within the following program.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
 
Powered by Should I Remove It?

The file 13-4_vista_win7_win8_32-64_sb.exe has been seen being distributed by the following 4 URLs.