reset epson l110-l210-l300-l350-l355.exe

4shared Desktop Setup

New IT Solutions

The application reset epson l110-l210-l300-l350-l355.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from dc634.4shared.com.
Publisher:
New IT Solutions

Product:
4shared Desktop Setup

Version:
4.0.3.1

MD5:
be9ea220b0043fbc4ad7fd19bf11e5a3

SHA-1:
a5df68f3e5eaa3f611273268115d4e260223e4ba

SHA-256:
26db03c5284a5f89240877697991120a5acaa2746174320ddeacd548a2e2576b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 3:26:39 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.NewITSolutions.Installer.Meta (L)
15.6.19.9

File size:
5.6 MB (5,844,576 bytes)

Copyright:
New IT Solutions

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\reset epson l110-l210-l300-l350-l355.exe

File PE Metadata
Compilation timestamp:
4/10/2010 9:19:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:0eIO7Z+ByxlOyexgcs6ArgkStxQM7osPuI+sPtumURA8oGNoD8MyeDFtGi5PHgSJ:0078By/OyexgT1l+P7jPz+dtHoKc/GMH

Entry address:
0x354B

Entry point:
60, F7, C5, A5, F4, 7C, 1D, 51, 4F, 88, D0, 3A, C5, 84, E6, FE, C9, FE, C1, FE, CD, 2C, B6, 8D, 3D, F8, BA, B8, 34, 84, DD, 53, 81, EA, D5, E9, 80, 25, E8, 4A, 00, 00, 00, 84, CB, 1A, E0, 84, EC, 69, CF, 46, 87, 3B, 43, 23, F3, 20, E6, 48, 8B, C9, F6, C6, F9, 88, C1, 0F, BF, F6, 8D, 06, 3B, FA, 72, 09, 0F, AF, F6, C7, C2, CE, 3C, EE, A2, 84, CC, 8B, F8, 8D, 0D, 5C, 03, 38, 99, 03, F7, 8B, F1, 8B, C0, F3, F7, C3, 70, 75, 2F, 96, 8D, 1F, 2A, E8, 04, 7D, 03, EB, F3, 58, F3, 4E, FF, C9, F7, C2, 7B, BD, 67, 55...
 
[+]

Code size:
25 KB (25,600 bytes)

The file reset epson l110-l210-l300-l350-l355.exe has been seen being distributed by the following URL.

Remove reset epson l110-l210-l300-l350-l355.exe - Powered by Reason Core Security