syminstallstub.exe

SymInstallStub

Symantec Corporation

This is a self-extracting archive and installer. This is installed with Norton Security Scan. The file has been seen being downloaded from 113.171.224.170 and multiple other hosts.
Publisher:
Symantec Corporation  (signed and verified)

Product:
SymInstallStub

Version:
3.1.0.44

MD5:
870f53ffc53e1f4a9f8fee1b57740bc3

SHA-1:
ab3daee0e24ecd279303b1ecff98484858594e8d

SHA-256:
be13ad713712783c04af023f115240d5f827138be14b5efcd34bb770766998dd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 4:15:32 AM UTC  (today)

File size:
336.8 KB (344,888 bytes)

Product version:
3.1

Copyright:
Copyright (c) 2015 Symantec Corporation

Original file name:
SymInstallStub

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\norton security scan\engine\4.1.0.29\syminstallstub.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/8/2013 8:00:00 AM

Valid to:
1/7/2017 7:59:59 AM

Subject:
CN=Symantec Corporation, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Symantec Corporation, L=Mountain View, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
12DB9E53539B8E248BC77DD2BA611167

File PE Metadata
Compilation timestamp:
8/7/2015 6:52:21 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:dOMqjRlkfzSEc0kuKfhJD4DaWfehFbyp8zjxT43HBFrWOn86K/N6:BiRlk+Ec03Kf/DqfKmanoHDh8PF6

Entry address:
0x1000

Entry point:
B8, 24, BD, 54, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, B7, D4, A9, EA, 4A, 2D, 76, 4D, D7, 9F, F5, FB, CD, 50, A8, 49, D4, 70, 99, CB, 71, 82, 38, EB, 2D, 34, DE, B4, DA, FF, 83, D7, 89, 54, DC, 75, 3C, 28, 94, 37, F8, 5A, AB, 8A, DD, 3F, 6E, 4D, ED, 9A, 5B, 26, 95, 30, 52, 71, 73, 4E, EB, FE, 5F, E8, 40, 3A, 20, 17, A4, C1, 2E, 93, 1C, 38, 5C, 3B, 3C, 3B, 39, 59, 4D, 07, C0, 99, EF, 0A, 64, F2, 89, 9F, 1B, 59, 13, 61, FC...
 
[+]

Entropy:
7.9554

Packer / compiler:
PECompact v2

Code size:
730 KB (747,520 bytes)

The file syminstallstub.exe has been discovered within the following programs.

Norton Security Scan  by Symantec Corporation
Norton Security Scan is a software tool designed to help you understand if your computer is currently protected from known threats.
www.symantec.com/techsupp
53% remove it
 
Powered by Should I Remove It?

The file syminstallstub.exe has been seen being distributed by the following 20 URLs.

http://113.171.224.170/.../SymInstallStub.exe

http://103.1.138.155/liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production/IS/.../SymInstallStub.exe

http://120.52.72.24/liveupdate.symantecliveupdate.com/c3pr90ntc0td/upgrade/NSS/SymCCIS/Production/IS/.../SymInstallStub.exe

http://113.171.224.207/.../SymInstallStub.exe

http://113.171.224.169/.../SymInstallStub.exe

temp:SymInstallStub.exe

http://113.171.224.241/.../SymInstallStub.exe

http://113.171.224.176/.../SymInstallStub.exe

http://113.171.224.167/.../SymInstallStub.exe

http://113.171.224.203/.../SymInstallStub.exe

http://113.171.224.213/.../SymInstallStub.exe