degooinstaller.exe

Degoo

Degoo Backup AB

The executable degooinstaller.exe, “Degoo Setup ” has been detected as malware by 10 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from d3t6cz01p3r2e4.cloudfront.net.
Publisher:
Degoo Backup AB

Product:
Degoo

Description:
Degoo Setup

MD5:
8bf615e21ed73512805438768c007895

SHA-1:
c945883f6c4c87f7fbb72c261a5854002c9577be

SHA-256:
f3518c7fad2f2bdfb7c57ce34c39bb58d5fda5564f1ba5de4119b1fcfe96ba48

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
5/6/2024 12:42:42 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160216-0

AVG
Win32/Sality
2015.0.4533

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.1919.0

VIPRE Antivirus
Threat.4758034
29708

File size:
1 MB (1,082,056 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\documents and settings\win-xp\meus documentos\downloads\degooinstaller.exe

File PE Metadata
Compilation timestamp:
7/9/2014 4:58:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ixGFOS5JMl1xVbxkDVaZBYoMZVeJycY1QIm97:H/5u1xxhMZVeWyIm97

Entry address:
0x113BC

Entry point:
74, 02, 09, FD, F6, DC, 39, D3, 0F, CD, 18, C1, 43, 0F, AF, FE, 0B, D6, EB, 0D, FF, CA, 0F, B7, FF, FE, C1, 8D, 2D, 21, 9A, 0A, 02, 8D, 1D, F3, 16, EC, 37, 8D, 05, 1E, AC, 01, 00, 13, D7, 2D, 1E, AC, 01, 00, 2D, 00, 00, 00, 00, 80, D2, 55, EB, 0D, 0F, B6, FA, 8A, CB, 0F, BF, EF, 0F, AF, ED, 33, D7, 05, CD, 95, 00, 00, 0F, BF, EE, 05, 28, 02, 00, 00, 85, F6, 33, F0, FE, C9, 69, C7, 31, A7, 79, D6, 05, F5, 40, 1A, 72, F6, D6, E8, 1F, 00, 00, 00, 74, 08, FE, C6, 8D, 2D, 0A, 91, 6D, FF, EB, 04, 88, F7, 30, CF...
 
[+]

Code size:
63.5 KB (65,024 bytes)

The file degooinstaller.exe has been seen being distributed by the following URL.

Remove degooinstaller.exe - Powered by Reason Core Security