winthruster 1.exe

TRADE Develop, TOV

The application winthruster 1.exe by TRADE Develop, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
TRADE Develop, TOV  (signed and verified)

Version:
1.0.0.0

MD5:
48665c9b6c6644204c95094b9418630d

SHA-1:
c0ac5569afd1533d734d001d74eb53d4a29cfbf3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 6:29:48 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallMonster (M)
17.3.5.4

File size:
6.1 MB (6,350,896 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\documents and settings\felipao\meus documentos\downloads\winthruster 1.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/15/2016 9:00:00 PM

Valid to:
4/16/2017 8:59:59 PM

Subject:
CN="TRADE Develop, TOV", OU=IT, O="TRADE Develop, TOV", STREET="vul. Zhovtneva, 108", L=Sofiivka, S=Dnipropetrovska, PostalCode=53100, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
69DE196E3C690DB5E602D1BA23B23129

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x20560C

Entry point:
55, 8B, EC, B9, 0D, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 0C, 4C, 60, 00, E8, 2C, 24, E0, FF, 33, C0, 55, 68, 15, 62, 60, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, B8, 09, 00, 00, 00, E8, 35, 60, E0, FF, 8B, 45, E8, 50, 8D, 55, E4, A1, 1C, E7, 65, 00, 8B, 00, E8, 3E, 7E, E5, FF, 8B, 55, E4, B8, 8C, 6E, 66, 00, 59, E8, B4, FC, DF, FF, 83, 3D, 8C, 6E, 66, 00, 00, 75, 0F, B8, 8C, 6E, 66, 00, BA, 2C, 62, 60, 00, E8, D4, F9, DF, FF, BA, D8, 7E, 66, 00, B8, 48, 62, 60, 00, E8, 29, 63, E0, FF, 84...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2 MB (2,119,168 bytes)

Remove winthruster 1.exe - Powered by Reason Core Security