KeyGen.exe

UltraISO PE 9.x Retail [KeyGen]

OnLyOnE

This is a setup program which is used to install the application.
Publisher:
OnLyOnE

Product:
UltraISO PE 9.x Retail [KeyGen]

Description:
KeyGen for UltraISO PE 9.x Retail

Version:
1.0.0.0

MD5:
55c8c0b31dbc9bfbf678d1c8cb9ee081

SHA-1:
4517a397c5aa1b72ba8d85234d53799aecdbc8e6

SHA-256:
42fd91cd54283ce77847ff02a73aaff572829e7c0cf485eb6bbbcb83bb234666

Scanner detections:
5 / 68

Status:
Clean  (5 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/26/2024 2:02:05 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Bkav FE
HW32.CDB
1.3.0.4959

Malwarebytes
Hacktool.Gen
v2014.03.03.05

Qihoo 360 Security
HEUR/Malware.QVM17.Gen
1.0.0.1015

ViRobot
Backdoor.Win32.A.ZAccess.29696.A
2011.4.7.4223

File size:
29 KB (29,696 bytes)

Product version:
1.0.0.0

Copyright:
© 2012 OnLyOnE

Original file name:
KeyGen.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\ultraiso\keygen.exe

File PE Metadata
Compilation timestamp:
7/24/2012 8:37:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.7

CTPH (ssdeep):
768:9T2BIRz+LimDOYl6YWR95Lp4w2KvvCDlB0Jdk:9TgqfRYsYAi8jdk

Entry address:
0x1B69

Entry point:
B8, EC, 2A, 41, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 07, B4, CC, 60, F5, 82, 1F, 72, AB, 43, C3, 74, 01, B8, 40, AF, 56, FB, 01, 7A, 1C, 8B, 47, 89, 2B, CB, 1E, 8C, DE, C5, 35, 37, 0E, A3, 63, 68, D8, F8, 52, B1, F0, 36, C7, 03, 61, 33, D6, 36, 8B, 13, 9E, B3, AE, 19, 90, 07, 5F, 0B, 89, DB, 17, 8D, 5F, EC, 68, EF, 48, 6A, 03, 99, E2, 08, 47, 55, 15, E4, 1B, 00, 1A, 39, 1F, 72, 71, 77, 1D, 51, 8D, 1C, 8D, EA, 45, 81, E2...
 
[+]

Packer / compiler:
PECompact v2

Code size:
9.3 KB (9,474 bytes)

The file KeyGen.exe has been seen being distributed by the following 3 URLs.

temp:KeyGen.exe

about:internet

Scan KeyGen.exe - Powered by Reason Core Security