foxitreader602.0413_enu_setup.exe

Foxit Reader Setup

Foxit Corporation

This is a setup and installation application. The file has been seen being downloaded from relizua.com and multiple other hosts.
Publisher:
Foxit Corporation   (signed by Foxit Corporation)

Product:
Foxit Reader Setup

Version:
6.0.2.413

MD5:
cf97e0570345a55c84d6dc327bb0236e

SHA-1:
1e6492dc34b2374e4673733d8e91a5c8c24734d4

SHA-256:
5dc90fc14a5e5612ccd703445c7c625db8993fde525e3badc3194e57e87b957a

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/6/2025 6:57:18 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
7.9241

File size:
28.3 MB (29,679,000 bytes)

Product version:
6.0.2.413

Copyright:
Copyright © 2005-2013 Foxit Corporation

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\foxitreader602.0413_enu_setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
5/3/2010 3:33:52 PM

Valid to:
5/3/2013 3:33:52 PM

Subject:
CN=Foxit Corporation, O=Foxit Corporation, L=Fremont, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
64A7A038A7B2

File PE Metadata
Compilation timestamp:
4/10/2010 11:57:59 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
786432:T5O2WBle/wgIppsgOxs/SUcJFEjtaoQvcpcf68Ul:T5OfevgPrtaoQvcpf

Entry address:
0x163C4

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 54, 55, 41, 00, E8, 70, 04, FF, FF, 33, C0, 55, 68, 91, 6A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 4D, 6A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, A6, EF, FF, FF, E8, B1, EA, FF, FF, 8D, 55, EC, 33, C0, E8, FB, 87, FF, FF, 8B, 55, EC, B8, B0, D6, 41, 00, E8, A6, EA, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, B0, D6, 41, 00, B2, 01...
 
[+]

Entropy:
7.9788

Developed / compiled with:
Microsoft Visual C++

Code size:
85 KB (87,040 bytes)

The file foxitreader602.0413_enu_setup.exe has been discovered within the following program.

PC Matic 1.1.0.50  by PC Pitstop LLC
Publisher's description - “PC Matic is safe, secure, & simple to use software that automates the regular maintenance & preventative steps necessary to keep your PC fast & safe. Start with your Free Diagnosis today.”
pcmatic.com
50% remove it
 
Powered by Should I Remove It?

The file foxitreader602.0413_enu_setup.exe has been seen being distributed by the following 22 URLs.

http://relizua.com/.../FoxitReader.exe

http://soft.archive2.clubic.com/files/2cf77c3306034df4354a66bdbfab5187/519b67c0/.../foxit-reader_6-0-2-0413_fr_13808.exe

http://cdn.xmediacontent.com/?ic_user_id=9202

http://filehippo.com/download/file/.../

http://file.sinhvienit.net/download/869611a6/0d3d95a0b036e4fcf5b660873a66d77f/2013/.../SinhVienIT.Net--FoxitReader602.0413_enu_Setup.exe

Scan foxitreader602.0413_enu_setup.exe - Powered by Reason Core Security