activesmart241-scsi.exe

Microsoft Windows 2000 Operating System

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable activesmart241-scsi.exe, “Win32 Cabinet Self-Extractor ” has been detected as malware by 3 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.ariolic.com.
Publisher:
Microsoft Corporation*  (Invalid match)

Product:
Microsoft(R) Windows (R) 2000 Operating System

Description:
Win32 Cabinet Self-Extractor

Version:
5.50.4134.600

MD5:
8b18c098d683e393571e2cd0a1d394f4

SHA-1:
df54a608006e5c7f9c999fe3b5d66487aa18ab85

SHA-256:
65dfa6b3b6b6eb360b07d5825ea517c266b432c0276c84306007cdeece3c40ad

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
1/11/2025 5:26:52 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:WrongInf-A [Susp]
2014.9-131226

Bkav FE
W32.Clod67d.Trojan
1.3.0.4613

F-Prot
W32/Virut.AI!Generic
v6.4.7.1.166

File size:
881 KB (902,144 bytes)

Product version:
5.50.4134.600

Copyright:
Copyright (C) Microsoft Corp. 1981-2000

Original file name:
WEXTRACT.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\activesmart241-scsi.exe

File PE Metadata
Compilation timestamp:
6/6/2000 4:43:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
12288:3LnKqoOXFIK9LXQckgcG7u7zWakRJ01+RDwjWRYoIy0zV5:7eA3Fh7WSdZyWR0V5

Entry address:
0x2891

Entry point:
55, 8B, EC, 83, EC, 44, 56, FF, 15, DC, 10, 00, 01, 8B, F0, 8A, 06, 3C, 22, 75, 14, 8A, 46, 01, 46, 84, C0, 74, 04, 3C, 22, 75, F4, 80, 3E, 22, 75, 0D, 46, EB, 0A, 3C, 20, 7E, 06, 46, 80, 3E, 20, 7F, FA, 8A, 06, 84, C0, 74, 07, 3C, 20, 7F, 03, 46, EB, F3, 83, 65, E8, 00, 8D, 45, BC, 50, FF, 15, D8, 10, 00, 01, F6, 45, E8, 01, 74, 06, 0F, B7, 45, EC, EB, 03, 6A, 0A, 58, 50, 56, 6A, 00, 6A, 00, FF, 15, 60, 11, 00, 01, 50, E8, 0E, 00, 00, 00, 8B, F0, 56, FF, 15, D0, 10, 00, 01, 8B, C6, 5E, C9, C3, 56, 33, F6...
 
[+]

Entropy:
7.9599  (probably packed)

Code size:
34 KB (34,816 bytes)

The file activesmart241-scsi.exe has been seen being distributed by the following URL.

Remove activesmart241-scsi.exe - Powered by Reason Core Security