install.exe

Install

Microgaming Software Systems Limited

The file install.exe by Microgaming Software Systems Limited has been detected as a potentially unwanted program by 12 anti-malware scanners.
Publisher:
Microgaming  (signed by Microgaming Software Systems Limited)

Product:
Install

Description:
Install Program

Version:
3.2.0.44

MD5:
02d9ea4a046efecd84df9478aeae919b

SHA-1:
593c8d28768ba780a8bb4f24aad96b043cd11889

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 4:25:04 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Downloader/Casino.461168
2012.04.24

Avira AntiVirus
GAME/Casino.Gen
7.9.1.14

Clam AntiVirus
Adware.Casino-22
0.98/171

ESET NOD32
Win32/PrimeCasino (variant)
9.4418

Fortinet FortiGate
Misc/CasOnline
2/25/2015

F-Prot
W32/Casino.F.gen
v6.4.5.1.85

IKARUS anti.virus
Spamtool.Win32.Casino
t3scan.1.1.72.0

K7 AntiVirus
Unwanted-Program
13.138.6711

McAfee
potentially unwanted program RubyFortune
5600.6844

Panda Antivirus
Suspicious file
15.02.25.07

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.1.13

Sophos
Phoenician Casino Installer
4.45

File size:
450.4 KB (461,168 bytes)

Product version:
3.2.0.44

Copyright:
Copyright © Microgaming, 2008

Original file name:
install.exe

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temp\vil1e0.tmp

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
1/21/2008 12:16:19 AM

Valid to:
2/7/2009 7:07:22 AM

Subject:
CN=Microgaming Software Systems Limited, OU=SoftSign, O=Microgaming Software Systems Limited, L=Isle of Man, S=England, C=GB

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
49E307443E5DF91F5E595CED7B205CCB

File PE Metadata
Compilation timestamp:
7/4/2008 9:25:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:/vyOeq04Z8/QpRSBqftEuL3vF1VYLB9ArvJ9oooooooooooooooooooooooooooX:/KLp4C/QpRScfWKYovZvV8jx4Ab

Entry address:
0x26EB1

Entry point:
E8, 3B, 56, 00, 00, E9, 16, FE, FF, FF, C7, 01, F0, 44, 43, 00, E9, 50, 16, 00, 00, 56, 8B, F1, C7, 06, F0, 44, 43, 00, E8, 42, 16, 00, 00, F6, 44, 24, 08, 01, 74, 07, 56, E8, E3, E3, FF, FF, 59, 8B, C6, 5E, C2, 04, 00, 56, 57, 8B, 7C, 24, 0C, 8B, 47, 04, 85, C0, 74, 49, 8D, 50, 08, 80, 3A, 00, 74, 41, 8B, 74, 24, 10, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08, 51, 52, E8, BE, 14, 00, 00, 85, C0, 59, 59, 74, 04, 33, C0, EB, 25, F6, 06, 02, 74, 05, F6, 07, 08, 74, F2, 8B, 44, 24, 14, 8B, 00, A8, 01, 74, 05, F6...
 
[+]

Entropy:
6.5274

Code size:
196 KB (200,704 bytes)

Remove install.exe - Powered by Reason Core Security