installer.exe

Installer B1 Free Archiver

Catalina Group Ltd

The application installer.exe by Catalina Group has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program B1 Free Archiver by Catalina Group Ltd.
Publisher:
http://b1.org/  (signed by Catalina Group Ltd)

Product:
Installer B1 Free Archiver

Version:
2, 6, 27, 0

MD5:
f78efb4aa31bdeac1635bbd25d9650df

SHA-1:
50d996512eb5dd086f713a2e4aedded9cc2ffadd

SHA-256:
3e9624373ecd21b078c222c740f096e6a584bbf3e06870f27988a8ed7e1b902e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 12:43:56 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Catalina.CatalinaGroup.Installer (M)
15.10.6.15

File size:
26.9 MB (28,180,280 bytes)

Product version:
2, 6, 27, 0

Copyright:
Copyright(C) 2014

Original file name:
Installer

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\b1 free archiver\installer.exe

Digital Signature
Authority:
Catalina Group Ltd

Valid from:
4/16/2015 6:53:24 AM

Valid to:
12/31/2039 6:59:59 PM

Subject:
CN=Catalina Group Ltd

Issuer:
CN=Catalina Group Ltd

Serial number:
F16F6DA8DF8C458545A6335860591E9C

File PE Metadata
Compilation timestamp:
5/21/2015 7:22:09 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:Kvj5Q4yAO/Uu1hIBZby/+EExMD119R8dcTMnGGP:WQ4yrbhIbbnxMh19RKGGP

Entry address:
0x5B26A

Entry point:
E8, 9F, DA, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04...
 
[+]

Entropy:
7.9657  (probably packed)

Code size:
470 KB (481,280 bytes)

Program Uninstaller
Program name:
B1 Free Archiver

Display publisher:
Catalina Group Ltd

Display version:
0.0.0.0

Uninstall string:
"C:\Program Files (x86)\B1 Free Archiver\installer.exe" "C:\Program Files (x86)\B1 Free Archiver\uninstall.xml"


Remove installer.exe - Powered by Reason Core Security