oiassistwtd.exe

WinZip 17

WinZip Computing

The application oiassistwtd.exe by WinZip Computing has been detected as a potentially unwanted program by 18 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address inst.avg.com on port 80 using the HTTP protocol.
Publisher:
WinZip Computing  (signed and verified)

Product:
WinZip 17

Description:
WinZip 17 Setup

Version:
1,18,0,2949

MD5:
0047123cbac230ec9284b3ef64d46ee7

SHA-1:
b9c30fbe56b4f3f521c1ff76696225f6219ae17c

SHA-256:
4e95a90c2064e72cc996f9c110ed6447e5e78e6517ff2b5eb95524478663e28b

Scanner detections:
18 / 68

Status:
Potentially unwanted

Explanation:
Includes Open Install, an installer which bundles legitimate programs with offers for additional 3rd-party applications that may be unwanted by the user.

Analysis date:
4/25/2024 8:56:15 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.OpenInstall
7.1.1

Avira AntiVirus
PUA/OpenInstall.Gen
8.3.2.2

Bkav FE
W32.HfsAdware
1.3.0.7237

Dr.Web
Adware.Downware.1348
9.0.1.046

Emsisoft Anti-Malware
Trojan.Win32.OpenInstall.AMN
8.16.02.15.01

ESET NOD32
Win32/OpenInstall (variant)
10.10150

Fortinet FortiGate
Riskware/OpenInstall
2/15/2016

K7 AntiVirus
Adware
13.210.17488

McAfee
Artemis!7AB1226C4256
5600.6488

MicroWorld eScan
Win32/OpenInstall
17.0.0.138

NANO AntiVirus
Riskware.Win32.Downware.dszcbf
0.30.26.3947

Norman
XPack.CX
11.20160215

Reason Heuristics
PUP.OpenInstall.WinZipComputing.Installer (M)
16.2.15.13

Sophos
4.98

Trend Micro House Call
TROJ_GEN.RCBH1A7
7.2.46

Vba32 AntiVirus
Backdoor.Swrort.aur
3.12.20.2

VIPRE Antivirus
Trojan.Win32.Generic
44428

Zillya! Antivirus
Adware.AlteredSoftware.Win32.67
2.0.0.2437

File size:
360.2 KB (368,856 bytes)

Product version:
1,18,0,2949

Copyright:
Copyright © 2012

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\oiassistwtd.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/16/2012 5:30:00 AM

Valid to:
4/14/2014 5:29:59 AM

Subject:
CN=WinZip Computing, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WinZip Computing, L=Mansfield, S=Connecticut, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E4842AC9691630B45F8266C0ADB1206

File PE Metadata
Compilation timestamp:
10/19/2012 9:04:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:53ctoLU3AfFKMxnG8PJf2BQV504y8KLBy2wtsWftySDNqsGTUbje:58QKknGcAk0/8KrXYtySDhGUbje

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, 18, 04, 00, 00, 53, 56, 57, BE, A4, 30, 40, 00, 8D, BD, E8, FB, FF, FF, A5, A5, A5, 6A, 7E, 66, A5, 59, 33, C0, 8D, BD, F6, FB, FF, FF, F3, AB, 66, AB, BB, 04, 01, 00, 00, 53, 8D, 85, E8, FB, FF, FF, 50, FF, 15, 5C, 30, 40, 00, 66, 83, A5, F0, FD, FF, FF, 00, 33, C0, B9, 81, 00, 00, 00, 8D, BD, F2, FD, FF, FF, F3, AB, 66, AB, 8D, 85, F0, FD, FF, FF, 50, 8D, 85, E8, FB, FF, FF, 50, C7, 45, F8, FD, FF, FF, FF, E8, 0F, 01, 00, 00, 84, C0, 59, 59, 74, 15, 8D, 75, F8, 8D, BD, F0, FD, FF, FF...
 
[+]

Entropy:
7.7399

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to oi.cloud.avg.com  (204.193.144.33:80)

TCP (HTTP):
Connects to inst.avg.com  (204.193.144.89:80)

Remove oiassistwtd.exe - Powered by Reason Core Security