download-winzix-1.0-setup.exe

ELTEDO

K.S.-GRUPP

The application download-winzix-1.0-setup.exe by K.S.-GRUPP has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
©Eedignodae   (signed by K.S.-GRUPP)

Product:
ELTEDO

Version:
1.7.9.4

MD5:
c3bfb39083c1eb2df36a5149ddb630ec

SHA-1:
33c4d4a3db28b04459f7bda97a340c5b34d5647a

SHA-256:
e17be457e4c639a79da131a0d364b60371f7f5f19f804a2fb27b9069479fc1a8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 10:37:14 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Bundler (M)
17.3.3.22

File size:
4.1 MB (4,259,136 bytes)

Product version:
1.7.9.4

Copyright:
©Eedignodae

Original file name:
eltedo.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\download-winzix-1.0-setup_7372466\download-winzix-1.0-setup\download-winzix-1.0-setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/2/2016 6:00:00 AM

Valid to:
12/3/2017 5:59:59 AM

Subject:
CN=K.S.-GRUPP, OU=K.S.-GRUPP, O=K.S.-GRUPP, STREET=Bud 17 V Vul Dotsenka, L=Chernigiv, S=Ukraine, PostalCode=14032, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5B5FA3D866750075EAEBBD10F74E4CFF

File PE Metadata
Compilation timestamp:
8/7/2015 7:33:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x21CDC0

Entry point:
55, 8B, EC, 83, EC, 30, A1, A0, A1, 80, 00, 89, 45, F4, C7, 45, EC, 33, 03, 00, 00, C7, 45, F4, 4A, 0F, 00, 00, EB, 09, 8B, 4D, F4, 83, C1, 1B, 89, 4D, F4, 81, 7D, F4, 65, 0F, 00, 00, 73, 53, 0F, B7, 55, F8, 39, 55, E0, 72, 48, C7, 45, EC, E7, 00, 00, 00, 0F, B6, 45, FC, 6B, 4D, FC, 00, 2B, C1, 89, 45, F0, 8B, 55, FC, 2B, 55, FC, 89, 55, F8, 8B, 45, EC, 83, C0, 0E, 89, 45, EC, 8B, 4D, E0, 0B, 4D, F0, 89, 4D, DC, 0F, B6, 55, E4, 0F, B6, 45, F8, 23, 45, E8, 0B, D0, 89, 55, F0, 81, 7D, EC, 03, 01, 00, 00, 72...
 
[+]

Entropy:
5.4269

Developed / compiled with:
Microsoft Visual C++

Code size:
2.1 MB (2,212,864 bytes)

Remove download-winzix-1.0-setup.exe - Powered by Reason Core Security