windows_xp_home.exe

Salih DEMIRGAN

This is a setup program which is used to install the application. The file has been seen being downloaded from adbim.com and multiple other hosts.
Publisher:
Salih DEMIRGAN  (signed and verified)

MD5:
adfddf32703d86447ed16bf18d1a279e

SHA-1:
bb69ae36d3ff20c45666b5580ef3810c04985422

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/27/2024 5:06:49 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.Salih
2015.0.3475

File size:
3.3 MB (3,455,440 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\documents and settings\t&t\belgelerim\downloads\windows_xp_home.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/20/2013 2:00:00 AM

Valid to:
11/21/2014 1:59:59 AM

Subject:
CN=Salih DEMIRGAN, O=Salih DEMIRGAN, STREET=Abdül Aziz Mh. Şirin Hanım Sk. No:19, L=Konya, S=Meram, PostalCode=n-a, C=TR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D93C4C5A7797EED44FF4F38F7E699B06

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:aBb1AyBteoP+bI4rBbadNgtWEDNj8ctytol4/W2ETsh5H/k9J93WOMWOFWOV:al1A2EfrcN1ED18ctbl4/W2pM9J9t+DV

Entry address:
0x285D80

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 98, 56, 68, 00, E8, F7, 18, D8, FF, 8B, 1D, 9C, EA, 69, 00, 8B, 03, E8, CE, 15, DF, FF, 8B, 0D, 50, ED, 69, 00, 8B, 03, 8B, 15, 08, F4, 67, 00, E8, D3, 15, DF, FF, 8B, 0D, DC, ED, 69, 00, 8B, 03, 8B, 15, 10, E4, 67, 00, E8, C0, 15, DF, FF, 8B, 0D, E8, E9, 69, 00, 8B, 03, 8B, 15, 04, E8, 67, 00, E8, AD, 15, DF, FF, 8B, 0D, F4, E6, 69, 00, 8B, 03, 8B, 15, B4, EA, 67, 00, E8, 9A, 15, DF, FF, 8B, 03, E8, 13, 16, DF, FF, 5B, E8, 11, EE, D7, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.5 MB (2,641,408 bytes)

The file windows_xp_home.exe has been seen being distributed by the following 2 URLs.

Scan windows_xp_home.exe - Powered by Reason Core Security