jre-6u43-windows-i586-iftw_96a39e8f.exe

Java Platform SE 6 U43

Sun Microsystems, Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from ref.gamer.com.tw and multiple other hosts.
Publisher:
Sun Microsystems, Inc.  (signed and verified)

Product:
Java(TM) Platform SE 6 U43

Description:
Java(TM) Platform SE binary

Version:
6.0.430.1

MD5:
94e60342f1f030995a894d7988bed56a

SHA-1:
0df845d287824adf436cf0bc6782fa95c7073435

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 11:57:58 AM UTC  (today)

File size:
893.9 KB (915,376 bytes)

Product version:
6.0.430.1

Copyright:
Copyright © 2013

Original file name:
jinstall.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\jre-6u43-windows-i586-iftw_96a39e8f.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/6/2012 2:00:00 AM

Valid to:
7/19/2015 1:59:59 AM

Subject:
CN="Sun Microsystems, Inc.", OU=Sun Microsystems, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Sun Microsystems, Inc.", L=Palo Alto, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4BBBE0D8257CD9711A1B57E6BB9C660F

File PE Metadata
Compilation timestamp:
3/1/2013 3:28:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
24576:Y2MqvPIy3FuwmkHpdKTTorwVUdSq3zKMA2:Y2rnIyXKTTVVUdz3M2

Entry address:
0x1BA140

Entry point:
60, BE, 00, 70, 4E, 00, 8D, BE, 00, A0, F1, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 27, 85, 1B, 00, 57, 83, C3, 04, 53, 68, 36, 31, 0D, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
848 KB (868,352 bytes)

The file jre-6u43-windows-i586-iftw_96a39e8f.exe has been discovered within the following program.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
 
Powered by Should I Remove It?

The file jre-6u43-windows-i586-iftw_96a39e8f.exe has been seen being distributed by the following 5 URLs.

http://ref.gamer.com.tw/redir.php?url=http://javadl.sun.com/webapps/.../AutoDL?BundleId=75107

http://javadl.sun.com/webapps/.../AutoDL?BundleId=75107