install_65.php

A&B Software LLC

The file install_65.php by A&B Software has been detected as a potentially unwanted program by 19 anti-malware scanners.
Publisher:
A&B Software LLC  (signed and verified)

MD5:
597ea68720ab0c86461f41a6b87e1817

SHA-1:
6d28935a59133141230fec44e30f3a30a21969f3

SHA-256:
dd360da1bd5926528bc3934ddccba0e88be094cc9ea1b57130a65d35e247e949

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 7:22:47 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Toolbar
7.1.1

Avira AntiVirus
Adware/Webalta.A.66
7.11.106.58

avast!
Win32:Webalta-E [PUP]
2014.9-160311

Baidu Antivirus
Downloader.Win32.Walta
4.0.3.16311

Bkav FE
W32.Clod410.Trojan
1.3.0.4246

Comodo Security
Application.Win32.AdWare.Webalta.AV
17068

Dr.Web
Adware.Downware.640
9.0.1.071

ESET NOD32
Win32/Adware.Toolbar.Webalta.AV (variant)
10.8887

Fortinet FortiGate
Riskware/Toolbar_Webalta
3/11/2016

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.0.127

Kaspersky
not-a-virus:HEUR:Downloader.Win32.Walta
14.0.0.530

McAfee
Artemis!597EA68720AB
5600.6463

Microsoft Security Essentials
Adware:Win32/Webalta
1.163.1557.0

Panda Antivirus
Trj/OCJ.B
16.03.11.11

Sophos
Generic PUA GN
4.93

Trend Micro House Call
TROJ_SPNR.08KF12
7.2.71

Trend Micro
TROJ_SPNR.08KF12
10.465.11

Vba32 AntiVirus
Downloader.Walta
3.12.24.3

VIPRE Antivirus
Trojan.Compcert.32812
22178

File size:
1.3 MB (1,366,248 bytes)

Common path:
C:\users\{user}\downloads\install_65.php

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/26/2011 7:34:30 PM

Valid to:
10/26/2012 7:34:30 PM

Subject:
CN=A&B Software LLC, O=A&B Software LLC, L=New London, S=CT, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11213B2BAB800978FCACAF8EC31B386C69A1

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:TCAKc8+BZaNsuLN7iAGWzL7jJy7MvjXIEoZA9ggPSbcL4tMVFbwlXdMlvg:2d2vaqGT1TYXA6gPS1MfKgvg

Entry address:
0x85F48

Entry point:
55, 8B, EC, 83, C4, F0, B8, 10, 5D, 48, 00, E8, D4, 09, F8, FF, A1, 10, 7A, 48, 00, 8B, 00, E8, A8, ED, FC, FF, 8B, 0D, 1C, 7B, 48, 00, A1, 10, 7A, 48, 00, 8B, 00, 8B, 15, CC, A3, 46, 00, E8, A8, ED, FC, FF, 8B, 0D, 58, 7B, 48, 00, A1, 10, 7A, 48, 00, 8B, 00, 8B, 15, 4C, A1, 46, 00, E8, 90, ED, FC, FF, 8B, 0D, C8, 79, 48, 00, A1, 10, 7A, 48, 00, 8B, 00, 8B, 15, 34, 5B, 48, 00, E8, 78, ED, FC, FF, A1, 10, 7A, 48, 00, 8B, 00, E8, EC, ED, FC, FF, E8, 6B, E4, F7, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
532 KB (544,768 bytes)

Remove install_65.php - Powered by Reason Core Security