setup.exe

AVII

ADP

Publisher:
ADP Dealer Services  (signed by ADP)

Product:
AVII

Version:
1.00.0004

MD5:
fcb454b6df1fdd8f8680709c77e56e69

SHA-1:
bb133214924a9032ef3a99e8328c8a67040be157

SHA-256:
368468e45ac826bbad36fee9b517901f7b9a66b23bb6509d73bca3a69f7e75be

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 10:32:21 PM UTC  (today)

File size:
117.3 KB (120,112 bytes)

Product version:
1.00.0004

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/24/2006 8:00:00 PM

Valid to:
11/17/2009 6:59:59 PM

Subject:
CN=ADP, OU=Dealer Services, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ADP, L=Portland, S=Oregon, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
42AF830E05A10118AA5719F5C5C8B7DC

File PE Metadata
Compilation timestamp:
7/18/2008 8:45:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:0Drp//vXfGX05WPDGNKwbG5DOrc4+OY307Nh5UZ4AHwe/:IYIEDOrc4+B30hhY4AHwW

Entry address:
0x1D2C

Entry point:
68, F8, 1E, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 78, 1B, 75, A2, 7E, 19, 18, 4A, A6, 1D, F8, 9C, BF, 4F, 98, 75, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, E8, 02, 00, 00, 5E, 01, 69, 6E, 73, 74, 61, 6C, 6C, 41, 56, 00, 68, 06, 00, 00, 46, 04, 00, 00, 00, 00, 01, 00, 03, 00, 5C, 2C, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 40, 2D, 40, 00, 50, A0, 41, 00, 02, 00, 00, 00, B4, 1D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0704

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
100 KB (102,400 bytes)

The file setup.exe has been seen being distributed by the following URL.

Scan setup.exe - Powered by Reason Core Security