systemexplorersetup.exe

System Explorer

Miroslav Topolar

The executable systemexplorersetup.exe, “System Explorer 7.0.0 Installer ” has been detected as malware by 10 anti-virus scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Mister Group   (signed by Miroslav Topolar)

Product:
System Explorer

Description:
System Explorer 7.0.0 Installer

Version:
7.0.0

MD5:
ec4463ce0ecf2e345a83e0d2be0c44b6

SHA-1:
b4d626281acfd4f92799443c134b3aa51937af7f

SHA-256:
3cdd44600b67263a8a86d42057c112a6a6f69d3bdd5d457d956170432ebd46e2

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
4/28/2024 3:29:18 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Parite
160518-2

AVG
Win32/Parite
2015.0.4568

Dr.Web
Win32.Parite.2
9.0.1.05190

Emsisoft Anti-Malware
Win32.Parite
11.5.0.6191

ESET NOD32
Win32/Parite.B virus
8.0.319.0

F-Prot
W32/Parite.B
4.6.5.141

Kaspersky
Virus.Win32.Parite
15.0.0.562

McAfee
Virus.W32/Pate.b
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.654.0

Norman
Win32.Parite.B
22.05.2016 07:18:28

File size:
2.2 MB (2,301,916 bytes)

Product version:
7.0.0

Copyright:
Mister Group

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\My documents\downloads\programs\systemexplorersetup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/12/2016 2:26:10 PM

Valid to:
6/3/2017 9:04:22 PM

Subject:
E=topolar@gmail.com, CN=Miroslav Topolar, O=Miroslav Topolar, L=Vyskov, C=CZ

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121684D4615A4A3153C2C5D3F400D14DF8D

File PE Metadata
Compilation timestamp:
4/6/2016 8:39:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:XRcAFby2Ed6V2NFZyYZc7DUc5wEkF/sIVRd8npGMpe/K7gB8:htFbYvDIIc8c5EVvGnbpeAgG

Entry address:
0x28000

Entry point:
68, 16, CA, 00, 00, 5B, 68, 22, 80, 42, 00, 5A, 90, BF, 98, 05, 00, 00, 90, 90, FF, 34, 3A, 31, 1C, 24, 8F, 04, 3A, 4F, 83, EF, 03, 90, 90, 75, EF, 90, FE, B7, 01, 00, 16, CA, 00, 00, 16, CA, 40, 00, CA, DD, 01, 00, 76, A3, 20, 00, CA, A5, 20, 00, 16, 7A, 02, 00, E9, 35, FF, FF, 2E, 59, 41, 00, E0, 5F, 41, 00, 16, 5C, 41, 00, 32, DD, 01, 00, E2, 5F, 01, 00, E8, 5F, 01, 00, 2E, D3, 01, 00, E2, 5F, 01, 00, E8, 5F, 01, 00, 16, CA, 00, 00, 16, CA, 00, 00, 16, CA, 00, 00, 16, CA, 00, 00, 16, CA, 00, 00, 16, CA...
 
[+]

Entropy:
7.9702  (probably packed)

Code size:
65 KB (66,560 bytes)

Remove systemexplorersetup.exe - Powered by Reason Core Security