385-inst-win7-a.exe

FileCompact

A.I.SOFT,INC.

This is a setup program which is used to install the application. The file has been seen being downloaded from welcome.solutions.brother.com and multiple other hosts.
Publisher:
A.I.SOFT,INC.

Product:
FileCompact

Description:
ZIP SELFEXTRACT

Version:
4, 0, 0, 0

MD5:
c36c885fd26a079a7cd5d0dc767f78aa

SHA-1:
e95d163bec9c986e8675cf964f5dfd1dd734a3b9

SHA-256:
9f2c3b171255b30e777f02bb6ce74430bf778459bc704dc4b88f22cd0fd03245

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/27/2024 1:55:46 AM UTC  (today)

Scan engine
Detection
Engine version

NANO AntiVirus
Trojan.Win32.Huhk.crkkle
0.28.0.58101

File size:
43.5 MB (45,604,003 bytes)

Product version:
4, 0, 0, 0

Copyright:
Copyright (C) A.I.SOFT,INC. 1996-2001

Original file name:
DXZIPSELF.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
12/4/2001 2:44:24 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:mzb3zyAm8LnOvsC0lqi6ZgrfDWU+y14y/sOxZPBvP/nxINu0b3P2WAYJvSq0:m3zbm8LOv4UIDWU+yflxZPBvHn0u0Tud

Entry address:
0x2B29

Entry point:
55, 8B, EC, 81, EC, 04, 01, 00, 00, 56, 6A, 00, FF, 15, 74, 50, 40, 00, 8D, 8D, FC, FE, FF, FF, 68, 04, 01, 00, 00, 51, 50, A3, 24, 72, 40, 00, FF, 15, 70, 50, 40, 00, FF, 15, 6C, 50, 40, 00, 8B, F0, 8A, 06, 3C, 22, 75, 0E, 8A, 46, 01, 46, 84, C0, 74, 18, 3C, 22, 74, 14, EB, F2, 84, C0, 74, 0E, 3C, 20, 74, 0A, 3C, 09, 74, 06, 8A, 46, 01, 46, EB, EE, 80, 3E, 00, 74, 01, 46, 6A, 00, FF, 15, 00, 51, 40, 00, 8D, 85, FC, FE, FF, FF, 56, 50, E8, 13, 00, 00, 00, 59, 59, FF, 15, 04, 51, 40, 00, 6A, 00, FF, 15, 68...
 
[+]

Entropy:
7.9990

Developed / compiled with:
Microsoft Visual C++

Code size:
16 KB (16,384 bytes)

The file 385-inst-win7-a.exe has been discovered within the following program.

www.Toolwiz.com
About 5% of users remove it
 
Powered by Should I Remove It?

The file 385-inst-win7-a.exe has been seen being distributed by the following 38 URLs.

http://welcome.solutions.brother.com/BSC/public/agreement_submit.aspx?serialno=&lang=French&dlfile=http://download.brother.com/welcome/.../385-INST-WIN7-A.EXE&guid=171bc4bf-5310-499f-903f-902437c296af&osname=win_7&prod=dcp387c_eu&c=fr&viewmode=0&dlid=dlf004123&dept=IDC

http://www.brotherdriver.com/.../aHR0cDovL2Rvd25sb2FkLmJyb3RoZXIuY29tL3dlbGNvbWUvZGxmMDA0MTIyLzM4NS1JTlNULVdJTjctQS5FWEU=

http://welcome.solutions.brother.com/BSC/public/agreement_submit.aspx?serialno=&lang=English&dlfile=http://download.brother.com/welcome/.../385-INST-WIN7-A.EXE&guid=2454f37c-edfc-4b2d-926f-28846d86a1e5&osname=win_7&prod=mfc490cw_all&c=us&viewmode=0&dlid=dlf004127&dept=IDC

http://welcome.solutions.brother.com/BSC/public/agreement_submit.aspx?serialno=&lang=English&dlfile=http://download.brother.com/welcome/.../385-INST-WIN7-A.EXE&guid=07e95571-ea84-44db-a474-c4b06e514dd3&osname=win_7_x64&prod=mfc490cw_all&c=pl&viewmode=0&dlid=dlf004127&dept=IDC

http://welcome.solutions.brother.com/BSC/public/agreement_submit.aspx?serialno=&lang=English&dlfile=http://download.brother.com/welcome/.../385-INST-WIN7-A.EXE&guid=650ff9d2-e7a5-4b19-ab4f-dda012a7da21&osname=win_7_x64&prod=mfc490cw_all&c=us&viewmode=0&dlid=dlf004127&dept=IDC

http://welcome.solutions.brother.com/BSC/public/agreement_submit.aspx?serialno=&lang=English&dlfile=http://download.brother.com/welcome/.../385-INST-WIN7-A.EXE&guid=ad90d87c-c955-467c-8118-ff6f50ba4295&osname=win_7&prod=mfc250c_all&c=pl&viewmode=0&dlid=dlf004124&dept=IDC

http://www.brotherdriver.com/.../aHR0cDovL2Rvd25sb2FkLmJyb3RoZXIuY29tL3dlbGNvbWUvZGxmMDA0MTI0LzM4NS1JTlNULVdJTjctQS5FWEU=

http://interia.hit.gemius.pl/hitredir/id=0stLay_GdLtDbdkbymp0ldU7jwzB44_kkcXH2eUJVFv.07/url=http://download.brother.com/welcome/.../385-INST-WIN7-A.EXE

http://s10190.chomikuj.pl/File.aspx?e=VKN4GgFaVDFAFt0sDtcXY8CqQ86YLS0MXUT21lRNSaImMC8n1ADonaAmFUcUe_DIMzlL9NMIW8JYNKdF06sFWkO0j8N5G7UhEehqAoAqyZeZpiXr1Dv2sUPM1NvfwA39yFG-T6SAV59zMeueW6I1xCci--9tmMkLT3WATlJnsHX1ugCYezb1vCNEkULysN1x&pv=2

http://welcome.solutions.brother.com/BSC/public/agreement_submit.aspx?serialno=&lang=English&dlfile=http://download.brother.com/welcome/.../385-INST-WIN7-A.EXE&guid=e38aa20d-4145-46f5-85ac-310afdbdc3a3&osname=win_7_x64&prod=mfc990cw_all&c=nz&viewmode=0&dlid=dlf004129&dept=IDC

http://welcome.solutions.brother.com/BSC/public/agreement_submit.aspx?serialno=&lang=German&dlfile=http://download.brother.com/welcome/.../385-INST-WIN7-A.EXE&guid=938ab610-5e3a-4b0a-9f21-a347be98c2e3&osname=win_7&prod=dcp585cw_all&c=de&viewmode=0&dlid=dlf004127&dept=IDC

http://welcome.solutions.brother.com/BSC/public/agreement_submit.aspx?serialno=&lang=English&dlfile=http://download.brother.com/welcome/.../385-INST-WIN7-A.EXE&guid=e2d13ca3-6667-46cc-93c2-454e46b71be0&osname=win_7&prod=dcp165c_all&c=us_ot&viewmode=0&dlid=dlf004124&dept=IDC

http://www.brotherdriver.com/.../aHR0cDovL2Rvd25sb2FkLmJyb3RoZXIuY29tL3dlbGNvbWUvZGxmMDA0MTI3LzM4NS1JTlNULVdJTjctQS5FWEU=

http://welcome.solutions.brother.com/BSC/public/agreement_submit.aspx?serialno=&lang=English&dlfile=http://download.brother.com/welcome/.../385-INST-WIN7-A.EXE&guid=a8e4a081-5672-4d1f-b504-9d432eec3ff9&osname=win_7_x64&prod=mfc490cw_all&c=us&viewmode=0&dlid=dlf004127&dept=IDC

Latest 30 of 38 download URLs

Scan 385-inst-win7-a.exe - Powered by Reason Core Security