qiwihack2015.exe

Astonsoft DeepBurner

MALITEK

The application qiwihack2015.exe by MALITEK has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Astonsoft  (signed by MALITEK)

Product:
Astonsoft DeepBurner

Version:
1.9.0.228

MD5:
707882960f59a940a001eb6b88372afc

SHA-1:
e489c148428fb1e09a80b2aad87428b1f7b7fdea

SHA-256:
c3ac8c6b6e5280497c8aa44e1846aeefbfa2c79ac306e417a2db5bdbbc396d05

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/2/2024 5:24:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallMonster (M)
17.2.10.21

File size:
2.7 MB (2,856,888 bytes)

Product version:
1.8

Copyright:
Astonsoft (c) 2002 - 2006

Original file name:
DeepBurner.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\qiwihack2015.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/12/2016 7:00:00 AM

Valid to:
3/13/2017 6:59:59 AM

Subject:
CN=MALITEK, O=MALITEK, STREET="Gazovikov, 30, 160", L=Tyumen, S=RU, PostalCode=625022, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EE626B9BCE0A4EB8C590A5CF0E187D8D

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

Entry address:
0x76D000

Entry point:
33, C0, B8, A4, CF, B6, 00, 83, C0, 70, 50, C3, C2, 08, 00, B9, 20, 10, 00, 00, B8, 01, 00, 00, 00, 8B, 90, 98, A3, B6, 00, 0F, B6, 12, 80, EA, B1, 83, EA, 07, 0B, D2, 75, 20, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, E9, F5, 06, 00, 00, DA, 81, E9, DB, E3, AC, 00, E9, A3, 06, 00, 00, 98, 15, 97, 51, EB, 14, 6F, DC, B8, 9D, EB, 03, 9C, EB, 01, C3, 81, 6C, 24, 04, 28, 10, A4, A0, EB, EF, 68, 7B, E7, 5A, A1, EB, EB, EE, 2D...
 
[+]

Code size:
648.5 KB (664,064 bytes)

Remove qiwihack2015.exe - Powered by Reason Core Security