msconfig.EXE

System Configuration Utility

Microsoft Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MSConfig’. The file has been seen being downloaded from www.raymond.cc and multiple other hosts.
Publisher:
Microsoft Corporation

Product:
Microsoft® Windows® Operating System

Description:
System Configuration Utility

Version:
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)

MD5:
4fd22142f54692463a7b98b7de175573

SHA-1:
21d079909eeffda4b79dace30eafa0860bbd4c62

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:08:02 PM UTC  (today)

File size:
154.5 KB (158,208 bytes)

Product version:
5.1.2600.2180

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
msconfig.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\msconfig.exe

File PE Metadata
Compilation timestamp:
8/4/2004 9:06:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
3072:oV3Lvhd2FbXWoO6rUSEPNWrnWA8/3CIOezrHZkTTDTE8:w7vhd2s1TSE1Wrnx8/kez

Entry address:
0x1A1A3

Entry point:
6A, 70, 68, 40, 44, 00, 01, E8, 99, 04, 00, 00, 33, FF, 57, FF, 15, 64, 11, 00, 01, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 7D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, B9, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, B9, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 7D, FC, 6A, 02, 5B, 53, FF, 15, 88, 16, 00, 01, 59, 83, 0D, AC, 10, 02, 01, FF, 83, 0D, B0, 10...
 
[+]

Entropy:
5.8769

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
122 KB (124,928 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MSConfig

Command:
C:\windows\$ntservicepackuninstall$\msconfig.exe \auto


The file msconfig.EXE has been seen being distributed by the following 2 URLs.

Scan msconfig.EXE - Powered by Reason Core Security