usenext_freetrial_421828w.exe

Tangysoft Ltd.

The program is a setup application that uses the Inno Setup installer. This is installed with UseNeXT. The file has been seen being downloaded from update.tangysoft.net.
Publisher:
Tangysoft Ltd.

MD5:
f091d7b29796362cc616bcea5d350014

SHA-1:
ff3ee8e37e887fcd03742266035d346f225be713

SHA-256:
77258f8168605a936fa3d514041a2d98028805e08b22989e533b8a2164ffed28

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 7:01:16 AM UTC  (today)

File size:
2.8 MB (2,922,547 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
3/17/2011 11:22:54 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:Ufee5NrfvLy0dPH73lG0sUbEB07pvI6VcuEby2xGW4Ponvzzj9z45Sxx2beIjfTF:8eCJJ/X18qBXxE+2xGMvzzZzwOojTU2H

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file usenext_freetrial_421828w.exe has been discovered within the following program.

UseNeXT  by Tangysoft Ltd.
Publisher's description - “UseNeXT is an ad-free access to more than 2,500 terabytes worth of data. UseNeXT offers incredible fast access to more than 60,000 Usenet discussions including the files posted by users. Every day there are 6,000 Gigabytes of data added to the Usenet.”
www.usenext.com
About 5% of users remove it
 
Powered by Should I Remove It?

The file usenext_freetrial_421828w.exe has been seen being distributed by the following URL.

Scan usenext_freetrial_421828w.exe - Powered by Reason Core Security