installplugin64.exe

Flash Player Installer/Uninstaller

Adobe Systems Incorporated

This is a setup and installation application. The file has been seen being downloaded from i.download.idg.pl and multiple other hosts.
Publisher:
Adobe Systems, Inc.  (signed by Adobe Systems Incorporated)

Product:
Flash® Player Installer/Uninstaller

Description:
Adobe® Flash® Player Installer/Uninstaller 11.1 r102

Version:
11,1,102,55

MD5:
f2b43d41f1c9d1fce2dc684d7a0b56b2

SHA-1:
51cde81a8f1ea33bed04873586449c45956b33f6

SHA-256:
b43a218abfda621393ab3ffb87a299abf0c2e5aa6f4643e3468286acb4107e93

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/23/2018 9:12:51 PM UTC  (today)

File size:
7.7 MB (8,111,264 bytes)

Product version:
11,1,102,55

Copyright:
Copyright © 1996-2011 Adobe, Inc.

Trademarks:
Adobe® Flash® Player

Original file name:
FlashUtil.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\installplugin64.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/15/2010 1:00:00 AM

Valid to:
12/15/2012 12:59:59 AM

Subject:
CN=Adobe Systems Incorporated, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Information Systems, O=Adobe Systems Incorporated, L=San Jose, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
15E5AC0A487063718E39DA52301A0488

File PE Metadata
Compilation timestamp:
11/1/2011 6:48:26 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:zrfPjDJU6miXvNMmFJ20pLYMyUvYmMt3pKSi8S2+HtoEUXOJ68Vg0f:zrj1Bm0JHpLYMyUgmc3Q8Y5nVg0f

Entry address:
0x60A8

Entry point:
48, 83, EC, 28, 45, 33, C9, 45, 33, C0, 33, D2, 33, C9, E8, 61, FB, FF, FF, CC, 40, 53, 48, 83, EC, 20, 48, 8B, D9, FF, 15, B5, AF, 00, 00, 4C, 8B, C3, 48, 8B, C8, 33, D2, 48, 83, C4, 20, 5B, 48, FF, 25, 99, AF, 00, 00, CC, 40, 53, 48, 83, EC, 20, 48, 8B, D9, FF, 15, 91, AF, 00, 00, 4C, 8B, C3, 48, 8B, C8, 33, D2, 48, 83, C4, 20, 5B, 48, FF, 25, 85, AF, 00, 00, CC, 4D, 85, C0, 74, 15, 4C, 8B, C9, 4C, 2B, CA, 8A, 02, 41, 88, 04, 11, 48, FF, C2, 49, 83, E8, 01, 75, F1, 48, 8B, C1, C3, CC, CC, 48, 89, 7C, 24...
 
[+]

Entropy:
7.9971  (probably packed)

Code size:
60.5 KB (61,952 bytes)

The file installplugin64.exe has been discovered within the following programs.

Horizon Assistant  by upc cablecom GmbH
About 6% of users remove it
upc cablecom assistant  by upc cablecom GmbH
About 1% of users remove it
 
Powered by Should I Remove It?

The file installplugin64.exe has been seen being distributed by the following 8 URLs.

http://i.download.idg.pl/fannef/b0d2767f6e30e4b9f31d5189856a968c/58494e77//zx/vol2/w95/flash/.../11.1.102.55_64bit.exe

http://172.16.99.2/res/.../install_flash_player_11_plugin_64bit.exe