instantstorm_legacyscreensaverupdater.exe

InstantStorm Legacy Screensaver Updater

Jan Kolarik & Ondrej Vaverka

Publisher:
Jan Kolarik & Ondrej Vaverka

Product:
InstantStorm Legacy Screensaver Updater

Version:
1.0.0.0

MD5:
39366a938820fd2f7fbe9418f754a917

SHA-1:
ac96bf45adf6db2c3ac76e54807f53588b6a756e

SHA-256:
e04345f962b2d9ac5c04d244db545261f4fda64e9bfc666683ca202380655129

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/19/2024 3:49:02 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsOval
1.3.0.4959

File size:
1.4 MB (1,505,936 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2004-2010 Jan Kolarik & Ondrej Vaverka

Original file name:
instantstormupdater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\instantstorm_legacyscreensaverupdater.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ryYeZe8MhBhOOu2QaF5+AYDiMq0L2KhzRb:4gPhBhLQG5+N2MqjKX

Entry address:
0x75E3C

Entry point:
55, 8B, EC, B9, 14, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 24, 5C, 47, 00, E8, 28, 0E, F9, FF, 33, C0, 55, 68, 4B, 69, 47, 00, 64, FF, 30, 64, 89, 20, E8, 3D, CC, F8, FF, 85, C0, 7E, 0F, BA, 94, 9D, 47, 00, B8, 01, 00, 00, 00, E8, 8A, CC, F8, FF, 8D, 45, EC, 50, B9, 07, 00, 00, 00, BA, 01, 00, 00, 00, A1, 94, 9D, 47, 00, E8, 92, EE, F8, FF, 8B, 45, EC, BA, 64, 69, 47, 00, E8, 71, ED, F8, FF, 0F, 85, F7, 01, 00, 00, 33, C0, 55, 68, 82, 60, 47, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E4, 33, C0...
 
[+]

Entropy:
6.0101

Developed / compiled with:
Microsoft Visual C++

Code size:
471 KB (482,304 bytes)

The file instantstorm_legacyscreensaverupdater.exe has been seen being distributed by the following 4 URLs.

Scan instantstorm_legacyscreensaverupdater.exe - Powered by Reason Core Security