usenext5.28.exe

TangySoft Ltd.

The program is a setup application that uses the Inno Setup installer. This is installed with UseNeXT. The file has been seen being downloaded from update.tangysoft.net and multiple other hosts.
Publisher:
Tangysoft Ltd.   (signed by TangySoft Ltd.)

MD5:
55d3585a21714d978a07e8e358e47011

SHA-1:
4fe3dfb2830c7932ca5423a6066b70fc1d438520

SHA-256:
bb11e8befffd48736ea97e75cd25232435a2d12e04e40e7a926fa4d75a9f1af3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/27/2025 12:09:08 AM UTC  (today)

File size:
2.5 MB (2,624,144 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\705f49176579a643660bff5ff6ae3956\883e23fb41513303770e9bce5f413a3b\usenext5.28.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/8/2010 2:00:00 AM

Valid to:
9/16/2013 1:59:59 AM

Subject:
CN=TangySoft Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TangySoft Ltd., L=Hong Kong, S=Hong Kong, C=HK

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
682CC73DB4A7B0BF8BAD56887F497D97

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:4aEN4kPQmI9h9hoOA6KKRLavI6VcuEby2xo/VBS9lYfCregRUnyDUP/bTO9g4F7G:VjkAMOASRL+XxE+2xo/3S9C6yHWUW+

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file usenext5.28.exe has been discovered within the following program.

UseNeXT  by Tangysoft Ltd.
Publisher's description - “UseNeXT is an ad-free access to more than 2,500 terabytes worth of data. UseNeXT offers incredible fast access to more than 60,000 Usenet discussions including the files posted by users. Every day there are 6,000 Gigabytes of data added to the Usenet.”
www.usenext.com
About 5% of users remove it
 
Powered by Should I Remove It?

The file usenext5.28.exe has been seen being distributed by the following 2 URLs.

Scan usenext5.28.exe - Powered by Reason Core Security