crossloopsetup.exe

CrossLoop, Inc

The application crossloopsetup.exe, “CrossLoop Setup ” by CrossLoop, Inc has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
CrossLoop   (signed by CrossLoop, Inc)

Description:
CrossLoop Setup

MD5:
9cfd488787921d85c7f535e6ffa7fd27

SHA-1:
c9bfb88c64091287b948fc501c664fedd9374d3e

SHA-256:
9d58376b023db7d205167646e8738b1ddbe6e7591a7d87f5f507ea6c580ca791

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 5:46:07 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Agent.720896.B
7.11.189.64

AVG
RemoteAdmin
2015.0.3243

Baidu Antivirus
HackTool.Win32.WinVNC
4.0.3.141231

Comodo Security
UnclassifiedMalware
20215

Dr.Web
Program.RemoteAdmin
9.0.1.0365

Kaspersky
not-a-virus:RemoteAdmin.Win32.WinVNC-based
14.0.0.2712

McAfee
Artemis!9CFD48878792
5600.6899

NANO AntiVirus
Riskware.Win32.RemoteAdmin.cvzmpy
0.28.6.63726

File size:
962.7 KB (985,840 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\utilities\crossloopsetup.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
10/31/2006 5:00:00 PM

Valid to:
11/1/2007 4:59:59 PM

Subject:
CN="CrossLoop, Inc", O="CrossLoop, Inc", STREET="1 Lower Ragsdale Dr., Bldg. 1,", STREET=Suite 210, L=Monterey, S=CA, PostalCode=93940, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00974F8D3710123B810DEC9F266DAFCEC0

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:DhSv3QhVNB7i40VB6/l+ItTmDzgNuferCRX4CZrDm2X3HrD:UvAhPVi40y0INm/9gCJxmw

Entry address:
0x9424

Entry point:
55, 8B, EC, 83, C4, B8, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, BC, 89, 45, B8, E8, 9F, 9C, FF, FF, E8, D6, AE, FF, FF, E8, 19, D1, FF, FF, E8, 60, D1, FF, FF, E8, DF, F5, FF, FF, BE, C4, BD, 40, 00, 33, C0, 55, 68, E3, 9A, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 94, 9A, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, EC, FE, FF, FF, E8, 9F, F9, FF, FF, 8D, 55, F0, 33, C0, E8, F9, D4, FF, FF, 8B, 55, F0, B8, B8, BD, 40, 00, E8, 50, 9D, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, B8, BD, 40, 00...
 
[+]

Entropy:
7.9811

Developed / compiled with:
Microsoft Visual C++

Code size:
35 KB (35,840 bytes)

Remove crossloopsetup.exe - Powered by Reason Core Security