universal-usb-installer-1.9.6.4.exe

pendrivelinux.com

The executable universal-usb-installer-1.9.6.4.exe, “Universal Linux UFD Creator” has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. Infected by the Parite virus, a polymorphic file infecting virus that infects all portable EXE and SCR files found on local and shared network drives. The file has been seen being downloaded from www.pendrivelinux.com.
Publisher:
pendrivelinux.com

Description:
Universal Linux UFD Creator

Version:
1.9.6.4

MD5:
2e27470f3526671247c20b0e41a39673

SHA-1:
cf921a9b5e795d9533cee0f38b425b5b2c51c2e0

SHA-256:
4670229ff8c005ccf03dd47fb0861f6765f1039651ff18e854f85d595cbe5f4d

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
12/25/2024 5:56:26 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Parite
160518-2

AVG
Win32/Parite
2015.0.4604

Dr.Web
Win32.Parite.2
9.0.1.05190

Emsisoft Anti-Malware
Win32.Parite
16.07.10

ESET NOD32
Win32/Parite.B virus
8.0.319.0

F-Prot
W32/Parite.B
4.6.5.141

F-Secure
Win32.Parite.B
5.15.21

Kaspersky
Virus.Win32.Parite
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.469.0

Norman
Win32.Parite.B
22.05.2016 07:18:28

VIPRE Antivirus
Threat.46249
50516

File size:
1.2 MB (1,266,650 bytes)

Copyright:
Copyright ©2009-2013 Lance Pendrivelinux.com

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\universal-usb-installer-1.9.6.4.exe

File PE Metadata
Compilation timestamp:
12/11/2015 3:11:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:ryLwTaWhUE5KU6nVyViuqVKBLzTSjlnupNIL4qCw+3XGhMDWnug/X0Rf5:e0Gr4KU8VyouHBmw9NJWuZ

Entry address:
0x47000

Entry point:
90, 68, D1, 0C, 0A, 01, 5B, 90, 68, 20, 70, 44, 00, 5E, 90, 90, BF, 98, 05, 00, 00, 90, 31, 1C, 3E, 90, 4F, 83, EF, 03, 90, 90, 75, F4, 90, 90, 39, 71, 0B, 01, D1, 0C, 0A, 01, D1, 0C, 4A, 01, 0F, 3C, 0A, 01, BA, 91, 1A, 01, 0B, AF, 1A, 01, D1, BC, 08, 01, D0, 0C, 0A, 01, B5, 7C, 4A, 01, E3, 75, 4A, 01, 7D, 74, 4A, 01, 01, 68, 0A, 01, E1, 75, 0A, 01, 7B, 74, 0A, 01, B5, 6C, 0A, 01, E1, 75, 0A, 01, 7B, 74, 0A, 01, D1, 0C, 0A, 01, D1, 0C, 0A, 01, D1, 0C, 0A, 01, D1, 0C, 0A, 01, 01, 7C, 4A, 01, D1, 0C, 0A, 01...
 
[+]

Entropy:
7.9696  (probably packed)

Code size:
23 KB (23,552 bytes)

The file universal-usb-installer-1.9.6.4.exe has been seen being distributed by the following URL.

Remove universal-usb-installer-1.9.6.4.exe - Powered by Reason Core Security