install.exe

OZIPInstall

Hongkong zoekyu Technology Limited

The application install.exe by Hongkong zoekyu Technology Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Zoekyu Technology Ltd.  (signed by Hongkong zoekyu Technology Limited)

Product:
OZIPInstall

Version:
1.3.36.0

MD5:
f09e1612254f3642dc95dea0013e166b

SHA-1:
a755e1e6048541103f6aa04150da3f1ce6cb5eaf

SHA-256:
f6d407525bee082fa5282d3e783346a6c3572a3d276b72ae8fc9911a2a11036f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
2/25/2025 2:11:59 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yessearches (M)
17.1.20.2

File size:
3.3 MB (3,415,816 bytes)

Product version:
1.3.36.0

Copyright:
Copyright (c) 2015 Zoekyu Technology Limited All rights reserved.

Original file name:
OZIPInstall.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\_@app_000001\install.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/15/2017 7:54:36 PM

Valid to:
8/25/2017 9:34:22 PM

Subject:
CN=Hongkong zoekyu Technology Limited, O=Hongkong zoekyu Technology Limited, L=Hongkong, S=Hongkong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
6F7F05D6B8F14A33239ECEFA

File PE Metadata
Compilation timestamp:
1/31/2016 7:31:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x139A1A

Entry point:
E8, 0B, 7A, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 50, 70, 5B, 00, 75, 02, F3, C3, E9, 07, 01, 00, 00, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, A8, 20, 5C, 00, FF, 15, 08, 24, 56, 00, 85, C0, 75, 18, 56, E8, B7, 33, 00, 00, 8B, F0, FF, 15, 38, 24, 56, 00, 50, E8, BC, 33, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 77, 6F, 53, 57, A1, A8, 20, 5C, 00, 85, C0, 75, 1D, E8, 3C, 77, 00, 00, 6A, 1E, E8, 92, 77, 00, 00, 68, FF, 00, 00, 00, E8, FE, 33, 00, 00, A1, A8...
 
[+]

Entropy:
7.1123

Code size:
1.4 MB (1,444,352 bytes)

Remove install.exe - Powered by Reason Core Security