WinFixProPackage.exe

WinFix Pro

IMALI - N.I. MEDIA TD

The application WinFixProPackage.exe by IMALI - N.I. MEDIA TD has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from rep.winfixprofessionals.com.
Publisher:
WinFix®  (signed by IMALI - N.I. MEDIA TD)

Product:
WinFix Pro

Description:
WinFix Package

Version:
1.816

MD5:
1b57f2f6de813ee17758f9acbfbdc2db

SHA-1:
9792e5795466a9f8b5dacce09145a27ecbe5359c

SHA-256:
7aa3a34cdcd6e841b8cf58c1f0d65597d3d609ae4a64287188fc1d70e4c63706

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/26/2024 10:17:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.IMALI (M)
16.9.20.6

File size:
12.7 MB (13,362,632 bytes)

Product version:
1.816

Copyright:
© WinFix 2014

Trademarks:
WinFix

Original file name:
WinFixProPackage.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\winfixpropackage.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
12/13/2014 10:00:00 PM

Valid to:
12/16/2015 10:00:00 AM

Subject:
CN=IMALI - N.I. MEDIA TD, O=IMALI - N.I. MEDIA TD, L=tel aviv, C=IL

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
017B4EC01F594ADE73E421BB2CDD9FE2

File PE Metadata
Compilation timestamp:
2/24/2012 4:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:GzK+KAxHaxAZU72e5ShjyDWO2KMQzmPXbIPSqrDtmu081SxyT4h2YrWcHcI+Ajp:GzK+JaGeqoSoQD8Sqr081SZh2ccjAp

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file WinFixProPackage.exe has been seen being distributed by the following URL.

http://rep.winfixprofessionals.com/.../WinFixProPackage1816x64.exe

Remove WinFixProPackage.exe - Powered by Reason Core Security