msnsusii.exe

Microsoft Windows 2000 Operating System

Test Company

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable msnsusii.exe, “Win32 Cabinet Self-Extractor ” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Test Company)

Product:
Microsoft(R) Windows (R) 2000 Operating System

Description:
Win32 Cabinet Self-Extractor

Version:
5.50.4134.600

MD5:
18df0e526a18c17ad4ed6b855a6b9482

SHA-1:
05e4aa89259e1b7c0b9d5b5ff625921642fbbaf9

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/28/2024 4:59:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.11.14

File size:
1.3 MB (1,402,584 bytes)

Product version:
5.50.4134.600

Copyright:
Copyright (C) Microsoft Corp. 1981-2000

Original file name:
WEXTRACT.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\msn\msncorefiles\install\msnsusii.exe

Digital Signature
Signed by:

Authority:
Root Agency

Valid from:
4/4/2001 3:11:27 PM

Valid to:
12/31/2039 3:59:59 PM

Subject:
CN=Test Company

Issuer:
CN=Root Agency

Serial number:
B00160C2D80DAC824AC6A36808C3F360

File PE Metadata
Compilation timestamp:
6/6/2000 1:43:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

Entry address:
0x2891

Entry point:
89, D6, 80, FE, AD, 81, C2, 16, 47, 19, A8, 12, E5, 15, 77, 29, B9, CC, 32, D6, C7, C2, C2, 63, 70, 2A, F3, 41, FE, CB, 0F, AF, D9, 86, FA, C6, C5, 7A, 49, 0F, AF, C9, 20, F7, B8, 00, 00, 00, 00, 89, D7, 0F, AF, FB, B8, 4E, 01, 00, 00, F6, C7, C0, C7, C1, 52, 53, 98, DB, 0F, AF, FA, 6B, C0, 02, 86, D1, 12, F1, BD, C0, 9A, A8, F3, 8A, D4, 88, D3, 8B, EF, 84, F7, 86, E9, 69, F5, D1, 8D, EF, 38, 4A, 8D, 0D, 3F, F7, 90, F9, 68, 8F, 06, 00, 00, 0F, B7, F5, 0F, AF, F8, 5B, 8D, 3D, 15, 5B, C4, C0, 80, E2, 05, 81...
 
[+]

Entropy:
7.9669  (probably packed)

Code size:
34 KB (34,816 bytes)

Remove msnsusii.exe - Powered by Reason Core Security