vsubst_1.0.6.exe

Visual Subst

Alexander Avdonin

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with Visual Subst. The file has been seen being downloaded from www.netzwelt.de and multiple other hosts.
Publisher:
NTWind Software  (signed by Alexander Avdonin)

Product:
Visual Subst

Version:
1.0.6.0

MD5:
b183e3061dd2bfe8e090d553ffc85df4

SHA-1:
6c2c5118b4281bd1792ba532dd4b79727dc0bf10

SHA-256:
d2d4e1ab1aa92cffebf215b224d3d89e5ad0d77f01fa078167fb5a7dbb5353f5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 12:56:19 PM UTC  (today)

File size:
110.4 KB (113,096 bytes)

Product version:
1.0.6.0

Copyright:
© 2006-2008 NTWind Software

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vsubst_1.0.6.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
2/26/2007 7:00:00 PM

Valid to:
2/27/2008 6:59:59 PM

Subject:
CN=Alexander Avdonin, O=Alexander Avdonin, STREET=Menshikovsky pr. 3-25, L=Saint Petersburg, S=Saint Petersburg, PostalCode=195067, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
3E5ABF29BA6BBDFBC0CB1793FE97875A

File PE Metadata
Compilation timestamp:
7/14/2007 11:12:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:OYG6UVYxmJPbOrvlQwq32J+FoyGQ//FdDw:7hDrUm8FFGe

Entry address:
0x3265

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 78, 72, 40, 00, 6A, 08, A3, F4, 3F, 42, 00, E8, C7, 2A, 00, 00, A3, 44, 3F, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 00, F5, 41, 00, FF, 15, 54, 71, 40, 00, 68, 1C, 92, 40, 00, 68, 40, 37, 42, 00, E8, A3, 27, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 91, 27, 00, 00...
 
[+]

Entropy:
7.6493

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file vsubst_1.0.6.exe has been discovered within the following program.

Visual Subst  by NTWind Software
Publisher's description - “Visual Subst is a small tool that allows you to associate the most accessed directories with virtual drives. It uses an API similar to the console 'subst' utility, but makes it easier to create and remove virtual drives in a GUI way.”
www.ntwind.com/software/utilities/visual-subst.html
10% remove it
 
Powered by Should I Remove It?

The file vsubst_1.0.6.exe has been seen being distributed by the following 18 URLs.

https://www.netzwelt.de/.../9872_2-visual-subst.html?sig=ef9b0869a9c22198049531504c5a3ff3

https://visual-subst.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAPSrYusXNoXmQc9Q4pHzEhsIv1rY9DnwGWoMMBNufET kM6iVPFssd2LvFPK1jSIL0h4Jk8T0bqr4VG8S3qgozoVmLJBga/FYAG7x9/.../ot1Y 0GSOWZePQ 6xoY3Anx0=

http://visual-subst.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAPSrYusXNoXmQc9Q4pHzEhsIv1rY9DnwGWoMMBNufET kM6iVPFssd2LvFPK1jSIL0h4Jk8T0bqr4VG8S3qgozoVmLJBga/FYAG7x9/.../ot1Y 0GSOWZePQ 6xoY3Anx0=

http://gsf-cf.softonic.com/6c2/c51/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55994&instance=softonic_en&type=PROGRAM&Expires=1448160019&Signature=GrX944hOWLmtPNJyYrdS3i1JNu97Lhwt0cJyuuCQCbS86JenNi0jk0UvtSB0Hs4L~5J0XFDInx4dbb1k1HREaibSvPwVdke235yTcrl9UOs9fSrqJ9smQy-nJZb87Fk6jxUq~DgsW2vy5vS1Y1L-2wHcDdJMgGUsYUiHWJbbKBU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=VSubst_1.0.6.exe

Scan vsubst_1.0.6.exe - Powered by Reason Core Security