cw.exe

Chew-WGA v0.9

Anemeros Software

The application cw.exe, “The Perpetuation Endeavor” has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from soft-tracker-load.ru.
Publisher:
Anemeros Software

Product:
Chew-WGA v0.9

Description:
The Perpetuation Endeavor

Version:
0.9.0.0

MD5:
4800193717145222e20a02b20ac26e28

SHA-1:
1817339638c55fa229d38901c9bea86ed609ce64

SHA-256:
4a0393606bdcd7d85e407a054a1f18372a683a18378d33c39c6a7529d0302699

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 6:14:22 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:PUP-gen [PUP]
160518-2

Dr.Web
hacktool program Tool.Wpakill.4
9.0.1.05190

Microsoft Security Essentials
Threat.Undefined
1.225.2266.0

File size:
2.6 MB (2,723,592 bytes)

Product version:
0.9.0.0

Copyright:
Copyright (c) 2009 - Anemeros Software

Trademarks:
Chew-WGA

Original file name:
cw.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\cw.exe

File PE Metadata
Compilation timestamp:
6/23/2009 10:57:07 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:9h+IAf1vl2eC1Lb8K0qf0MOT6376xl3bsazbp5ZQdqGLdQhz37Ja5AIVxNGm:9EIO1vl2eAYHjT0GbsafTSd78kAKxNGm

Entry address:
0x173A6

Entry point:
55, 8B, EC, 6A, FF, 68, 90, 2C, 43, 00, 68, C4, BE, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, AC, 01, 43, 00, 33, D2, 8A, D4, 89, 15, A0, 0A, 44, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 9C, 0A, 44, 00, C1, E1, 08, 03, CA, 89, 0D, 98, 0A, 44, 00, C1, E8, 10, A3, 94, 0A, 44, 00, 6A, 01, E8, 45, 38, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 86, 1A, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
188 KB (192,512 bytes)

The file cw.exe has been seen being distributed by the following URL.

Remove cw.exe - Powered by Reason Core Security