install.exe

Install

Microgaming Software Systems Limited

The file install.exe by Microgaming Software Systems Limited has been detected as a potentially unwanted program by 10 anti-malware scanners.
Publisher:
Microgaming  (signed by Microgaming Software Systems Limited)

Product:
Install

Description:
Install Program

Version:
3.2.0.44

MD5:
52c3a9cd08f227740ee150fc70c3537f

SHA-1:
ed504a5c979b42e8a3b739131cb62f7813842c8d

SHA-256:
a8dfb96395118a14a57a4a6dbb5e9bd92da4461b02378699fd65303eb7021549

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 9:23:55 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Downloader/Casino.461168
2012.04.24

Avira AntiVirus
GAME/Casino.Gen
7.11.212.112

Clam AntiVirus
Adware.Casino-22
0.98/20107

ESET NOD32
Win32/PrimeCasino potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/CasOnline
2/25/2015

F-Prot
W32/Casino.F.gen
4.6.5.141

K7 AntiVirus
Unwanted-Program
13.138.6711

McAfee
Program.CasFortune
16.8.708.2

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.1.13

Sophos
Phoenician Casino Installer
4.73 TP

File size:
493.3 KB (505,104 bytes)

Product version:
3.2.0.44

Copyright:
Copyright © Microgaming, 2008

Original file name:
install.exe

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temp\ric38.tmp

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
1/21/2008 12:16:19 AM

Valid to:
2/7/2009 7:07:22 AM

Subject:
CN=Microgaming Software Systems Limited, OU=SoftSign, O=Microgaming Software Systems Limited, L=Isle of Man, S=England, C=GB

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
49E307443E5DF91F5E595CED7B205CCB

File PE Metadata
Compilation timestamp:
7/4/2008 9:25:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:ivyOeq04Z8/QpRSBqftEuL3vF1VYLB9AZ/3zqzzzzzm0zPrz908A39KKpCbft:iKLp4C/QpRScfWKYe3zAl+KKp8t

Entry address:
0x26EB1

Entry point:
E8, 3B, 56, 00, 00, E9, 16, FE, FF, FF, C7, 01, F0, 44, 43, 00, E9, 50, 16, 00, 00, 56, 8B, F1, C7, 06, F0, 44, 43, 00, E8, 42, 16, 00, 00, F6, 44, 24, 08, 01, 74, 07, 56, E8, E3, E3, FF, FF, 59, 8B, C6, 5E, C2, 04, 00, 56, 57, 8B, 7C, 24, 0C, 8B, 47, 04, 85, C0, 74, 49, 8D, 50, 08, 80, 3A, 00, 74, 41, 8B, 74, 24, 10, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08, 51, 52, E8, BE, 14, 00, 00, 85, C0, 59, 59, 74, 04, 33, C0, EB, 25, F6, 06, 02, 74, 05, F6, 07, 08, 74, F2, 8B, 44, 24, 14, 8B, 00, A8, 01, 74, 05, F6...
 
[+]

Entropy:
6.4863

Code size:
196 KB (200,704 bytes)

Remove install.exe - Powered by Reason Core Security