audi1_scr.exe

ScreenTime for Flash

This is a self-extracting archive and installer. The file has been seen being downloaded from www.screensaversplanet.com.
Product:
ScreenTime for Flash

Description:
Screen Saver Installer

Version:
3.2.1.0

MD5:
44284470ab01704a179a910531e2211a

SHA-1:
b12056a120cf1fff16323d56bad4db33099e8787

SHA-256:
906c340e5d6191240db5e2947a32e92c67337cd7a98f5a7cb9d0d11f26528b16

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/15/2024 1:49:07 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
21473

File size:
2.8 MB (2,915,448 bytes)

Product version:
Unlimited

Copyright:
Copyright 2004 ScreenTime Media. All Rights Rsvrd.

Trademarks:
ScreenTime is a registered trademark of ScreenTime Media.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\audi1_scr.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:B1pvdST89zv8GIazvQPTcUyag+H/ZeGjOadSRRqAqK41KZeP2MaDXiAzt:BneoIYIYDd+Hheiy0KZpXDXiQt

Entry address:
0x895F0

Entry point:
55, 8B, EC, 83, C4, E8, 53, 56, 33, C0, 89, 45, EC, 89, 45, E8, B8, 30, 93, 48, 00, E8, DE, D5, F7, FF, BB, 9C, EB, 48, 00, BE, 68, 42, 4D, 00, 33, C0, 55, 68, BB, 96, 48, 00, 64, FF, 30, 64, 89, 20, 8B, 03, E8, 13, A2, FB, FF, BA, D4, 96, 48, 00, 8B, 03, E8, F7, 9D, FB, FF, 8B, CE, 8B, 15, EC, 4A, 48, 00, 8B, 03, E8, 08, A2, FB, FF, 8D, 55, E8, 8B, 03, E8, 86, A8, FB, FF, 8B, 45, E8, 8D, 55, EC, E8, AF, FD, F7, FF, 8B, 55, EC, 8B, 06, E8, 4D, 09, FC, FF, BA, D4, 96, 48, 00, 8B, 06, E8, 89, B6, FF, FF, 83...
 
[+]

Entropy:
7.8066

Developed / compiled with:
Microsoft Visual C++

Code size:
546 KB (559,104 bytes)

The file audi1_scr.exe has been seen being distributed by the following URL.

Scan audi1_scr.exe - Powered by Reason Core Security