1_spp_setpointp.exe

WEB_64 Setup

Logitech

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.techspot.com and multiple other hosts.
Publisher:
Logitech Inc.  (signed by Logitech)

Product:
WEB_64 Setup

Description:
Setup

Version:
6.32.20

MD5:
860705d63112500a83b4a9da046a62d4

SHA-1:
38956805b9f91852b7f87bddce2341e5d4f65d21

SHA-256:
d4e0080a0ea661e85e16bdf28290ace8c1b8821128f678d00871f1f85953b0a0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/8/2024 2:08:42 PM UTC  (today)

File size:
26.6 MB (27,941,800 bytes)

Copyright:
Copyright 2005-2011 Logitech. All Rights Reserved

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\1_spp_setpointp.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/28/2011 1:00:00 AM

Valid to:
4/28/2013 12:59:59 AM

Subject:
CN=Logitech, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Logitech, L=Fremont, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1EF05F3F3C037D743941DB75D7FB8637

File PE Metadata
Compilation timestamp:
9/9/2009 2:23:14 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:99FB2K0O/uiPZKZkcS80cSBaSstUkaI5mJfGA/7SfiLpQB:9zQZmrc5C+tUkaI0Jp/eXB

Entry address:
0x33E9

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 70, 85, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 78, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, 90, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 6C, 85, 40, 00, FF, 15, 80, 81, 40, 00, 68, 54, 85, 40, 00, 68, 80, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.9998

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file 1_spp_setpointp.exe has been discovered within the following program.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
 
Powered by Should I Remove It?

The file 1_spp_setpointp.exe has been seen being distributed by the following 6 URLs.

http://www.techspot.com/drivers/downloadnow/.../?evp=6619262a543df7d9d72e70e6e51e4e78&file=1