SIW.EXE

System Information for Windows

Topala Software Solutions

The application SIW.EXE, “System Information” by Topala Software Solutions has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Topala Software Solutions  (signed and verified)

Product:
System Information for Windows

Description:
System Information

Version:
2012,10,04, 0

MD5:
85565da57adaa59fea17990e6f1823fe

SHA-1:
5222ed2171f8c03db7b716e9bfff743d45166e5b

SHA-256:
802117b424590399a55935a85638163cb191e828036e71536e186d2a8e7670c0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/5/2024 7:07:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.13.15

File size:
3 MB (3,135,600 bytes)

Product version:
2012,10,04, 0

Copyright:
Copyright © 2005-2012 Gabriel Topala

Original file name:
SIW.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\technician\siw.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/4/2012 3:00:00 AM

Valid to:
5/5/2015 2:59:59 AM

Subject:
CN=Topala Software Solutions, O=Topala Software Solutions, STREET="22 Elkhorn Dr., #251", PostalCode=M2K 1J4, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F1E362709E9545879CCFC63C3E7D085D

File PE Metadata
Compilation timestamp:
10/22/2012 2:58:01 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x11CE86

Entry point:
B8, 40, 12, F9, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 63, E9, 56, CD, 54, 71, 4D, D6, 95, 11, FD, 01, 97, 29, CA, B4, B1, 6B, 09, 78, D9, 18, 3E, 27, F6, 75, 57, 3B, 24, F1, 62, 92, CA, 56, 89, 52, FE, ED, D1, 53, F9, 75, 00, 47, 57, 74, B1, DB, B2, 70, 5B, 6B, D5, F0, 1E, 22, 70, D3, EA, 93, D2, 7B, 47, 99, 12, 5F, DE, C9, 9D, 33, 89, B1, 3E, 64, CF, 3B, 2C, 8E, 21, 2E, 1F, 2B, 58, 77, 6A, 73, 69, AB, CC, 9D, 09, F1, 47...
 
[+]

Entropy:
7.7142

Packer / compiler:
PECompact v2

Code size:
3.1 MB (3,230,208 bytes)

Remove SIW.EXE - Powered by Reason Core Security