windows.exe

InstallShield

Macrovision Corporation

The program is a setup application that uses the InstallShield Setup installer. The file has been seen being downloaded from d2.driverscollection.com and multiple other hosts.
Publisher:
Macrovision Corporation

Product:
InstallShield

Description:
Setup.exe

Version:
12.0.58855

MD5:
880a53c64f160d7de4ba186ca25df887

SHA-1:
1727e4205702e39eb6a538fdeb9c5227ecbcf22d

SHA-256:
d4d997981266c4574f5cd2607d52bf47369c50624d5e7e281bd44ba58d583e32

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/5/2024 7:06:52 AM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Backdoor.Generic.21020
8.14.03.18.12

File size:
27.4 MB (28,773,065 bytes)

Product version:
12.0

Copyright:
Copyright (C) 2006 Macrovision Corporation

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Installer:
InstallShield Setup

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ralink\windows.exe

File PE Metadata
Compilation timestamp:
8/28/2007 10:22:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:RKfo7y0CVryk2+hvDOIHvlHYFDUteIz8buw2xyz3RgyCpFRJIlxASevn4otQOn:Co7y/VmkFDqQkf7z3RgntI07nN9

Entry address:
0x3B309

Entry point:
55, 8B, EC, 6A, FF, 68, 00, 87, 44, 00, 68, D0, EC, 43, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 40, 71, 44, 00, 33, D2, 8A, D4, 89, 15, 04, 2E, 45, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 00, 2E, 45, 00, C1, E1, 08, 03, CA, 89, 0D, FC, 2D, 45, 00, C1, E8, 10, A3, F8, 2D, 45, 00, 6A, 01, E8, EF, 26, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, E3, 23, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
280 KB (286,720 bytes)

The file windows.exe has been seen being distributed by the following 13 URLs.

https://d2.driverscollection.com/2ec2dca7cb9b6f/de6a8f2e809f1e5ea1a94fb9f71e7ce28ba1694b044857c0b5902f34e388395647ab479a86b30cba03507b5b397193d857cb3580/1/517/74/.../IS_AP_STA_RT2870_D-3.1.3.0_VA-3.1.3.0_W7-3.1.3.0_RU-4.0.0.0_AU-4.0.0.0_061710_1.5.8.0WP_Free.exe

http://www.powernetwork.com.br/assets/.../2232011110330.exe

https://d2.driverscollection.com/6e858a828272/fb447fa19db38a76296327a06bdf741afc3e5f0009b2948e04b3457cc32da805bf31ea3394ad6597d523dda51c447e7157f94c3e/1/517/74/.../IS_AP_STA_RT2870_D-3.1.3.0_VA-3.1.3.0_W7-3.1.3.0_RU-4.0.0.0_AU-4.0.0.0_061710_1.5.8.0WP_Free.exe

https://d2.driverscollection.com/1b015ba2607b168/1b244b68fee8a31da992ceff4c7ae47057bc75aba8b663e91ffe9bef0e5e605e36b61eadbe1804b9ddc1813d490da6755672b1f6/1/517/74/.../IS_AP_STA_RT2870_D-3.1.3.0_VA-3.1.3.0_W7-3.1.3.0_RU-4.0.0.0_AU-4.0.0.0_061710_1.5.8.0WP_Free.exe

http://www.kozumi-usa.com/.../IS_AP_STA_RT2870_D-3.1.3.0_VA-3.1.3.0_W7-3.1.3.0_RU-4.0.0.0_AU-4.0.0.0_061710_1.5.8.0WP_Free.exe

https://d2.driverscollection.com/1247ac993dcf0b76/6ef6086ded66c624dbab6907fa36a09c0648a9328ed31a42a6506684b45f565cfbf460de33b2a96344d23bc4e9849dbc580418e7/1/517/74/.../IS_AP_STA_RT2870_D-3.1.3.0_VA-3.1.3.0_W7-3.1.3.0_RU-4.0.0.0_AU-4.0.0.0_061710_1.5.8.0WP_Free.exe

Scan windows.exe - Powered by Reason Core Security