setup-exchange-bkf-to-pst.exe

SysTools Exchange BKF To PST

SysTools Inc

The application setup-exchange-bkf-to-pst.exe, “SysTools Exchange BKF To PST Setup ” by SysTools Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from search.myfiledown.com.
Publisher:
SysTools Software Private Limited.   (signed by SysTools Inc)

Product:
SysTools Exchange BKF To PST

Description:
SysTools Exchange BKF To PST Setup

Version:
2.0.0.0

MD5:
6a2f41018c56fbe11c04b59a98372920

SHA-1:
5ef9039b97a0277f37eff86223340a7b9408a09f

SHA-256:
0ec316292e42dec0dad5f0dda48da8b9a811fa809506e1f884a610eb95a9dfe1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/24/2024 12:01:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.IM (L)
17.2.27.20

File size:
4.2 MB (4,389,344 bytes)

Product version:
2.0.0.0

Copyright:
© 2016 SysTools Software Private Limited.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup-exchange-bkf-to-pst.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/16/2016 7:00:00 AM

Valid to:
3/20/2019 7:00:00 PM

Subject:
CN=SysTools Inc, O=SysTools Inc, L=Holladay, S=Utah, C=US, PostalCode=84117, STREET="2105 Murray Holladay Road, Suite 3,", SERIALNUMBER=9374267-0142, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06212C472688C9F938864937C499EFB1

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.9985

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file setup-exchange-bkf-to-pst.exe has been seen being distributed by the following URL.

http://search.myfiledown.com/link.php?url=http://.../systools-exchange-bkf-to-pst.exe

Remove setup-exchange-bkf-to-pst.exe - Powered by Reason Core Security