oiassistwtd.exe

WinZip 17.5

WinZip Computing

The application oiassistwtd.exe, “WinZip 17.5 Setup” by WinZip Computing has been detected as a potentially unwanted program by 16 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from inst.winzip.com. While running, it connects to the Internet address inst.avg.com on port 80 using the HTTP protocol.
Publisher:
WinZip Computing  (signed and verified)

Product:
WinZip 17.5

Description:
WinZip 17.5 Setup

Version:
1,18,0,3287

MD5:
cb8f36a47768fdc222246f9fcbb50c3c

SHA-1:
382d272948d1601d580a1a71468965de96c2007c

SHA-256:
ca04384ece72696d1c1d1212d79a4b3f882f8c121b36447700d39a57e4365a22

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
Includes Open Install, an installer which bundles legitimate programs with offers for additional 3rd-party applications that may be unwanted by the user.

Analysis date:
11/27/2024 10:58:24 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.OpenInstall
7.1.1

Bkav FE
W32.Clod5eb.Trojan
1.3.0.4613

Dr.Web
Adware.Downware.1348
9.0.1.05190

ESET NOD32
Win32/OpenInstall potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OpenInstall
7/14/2014

K7 AntiVirus
Unwanted-Program
13.176.11510

McAfee
Artemis!6ED6AF019F8B
5600.7069

Reason Heuristics
PUP.OpenInstall.Installer.L
14.7.14.19

Sophos
4.98

Trend Micro House Call
TROJ_GEN.F47V1010
7.2.195

XVirus List
Win.Detected
2.3.31

Zillya! Antivirus
Dropper.Autoit.Win32.1746
2.0.0.1772

File size:
414.4 KB (424,392 bytes)

Product version:
1,18,0,3287

Copyright:
Copyright © 2013

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\oiassistwtd.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/16/2012 1:00:00 AM

Valid to:
4/14/2014 1:59:59 AM

Subject:
CN=WinZip Computing, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WinZip Computing, L=Mansfield, S=Connecticut, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E4842AC9691630B45F8266C0ADB1206

File PE Metadata
Compilation timestamp:
4/12/2013 12:55:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:hZ0lscVC2dgU0rIvtDJ/nDsoGcO1WK/kLl:hZ0PcprIv7/D84l

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, 1C, 04, 00, 00, 53, 56, 57, BE, C0, 30, 40, 00, 8D, BD, E4, FB, FF, FF, A5, A5, A5, 6A, 7E, 66, A5, 59, 33, C0, 8D, BD, F2, FB, FF, FF, F3, AB, 66, AB, BB, 04, 01, 00, 00, 53, 8D, 85, E4, FB, FF, FF, 50, FF, 15, 5C, 30, 40, 00, 66, 83, A5, EC, FD, FF, FF, 00, 33, C0, B9, 81, 00, 00, 00, 8D, BD, EE, FD, FF, FF, F3, AB, 66, AB, 8D, 85, EC, FD, FF, FF, 50, 8D, 85, E4, FB, FF, FF, 50, C7, 45, F8, FD, FF, FF, FF, E8, 3A, 01, 00, 00, 84, C0, 59, 59, 74, 15, 8D, 75, F8, 8D, BD, EC, FD, FF, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file oiassistwtd.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to oi.cloud.avg.com  (204.193.144.33:80)

TCP (HTTP):
Connects to inst.avg.com  (204.193.144.89:80)

Remove oiassistwtd.exe - Powered by Reason Core Security