UsbFix.exe

UsbFix- www.SosVirus.net - www.UsbFix.net

Cedric Le Bozec

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from download.fosshub.com and multiple other hosts.
Publisher:
El Desaparecido - SosVirus.net - UsbFix.net  (signed by Cedric Le Bozec)

Product:
UsbFix- www.SosVirus.net - www.UsbFix.net

Description:
UsbFix - Remove Malware From Your Drive!

Version:
8.1.8.1

MD5:
871abb6f4fefc6aa047ca2abab2c207e

SHA-1:
539644e8a19afa7fc88db1c21abf76fde65acc45

SHA-256:
74ded2adde4bc71914f3e07f03c8025076d396965d7cd382666ff5051ed96e21

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/19/2024 11:04:52 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Fortinet FortiGate
Riskware/Dloader
1/7/2016

Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
1.0.0.1077

File size:
2.9 MB (3,071,552 bytes)

Product version:
8

Copyright:
© 2008/2016 - El Desaparecido - www.SosVirus.net

Trademarks:
Tous droits réservés.

Original file name:
UsbFix.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
11/30/2015 1:00:00 AM

Valid to:
12/7/2016 1:00:00 PM

Subject:
CN=Cedric Le Bozec, O=Cedric Le Bozec, L=Etaules, S=Bretagne, C=FR

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
04CE4D88B083C5D726BDFA5A3EF82C69

File PE Metadata
Compilation timestamp:
12/27/2015 6:38:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:xuXB6T6mR9fHmu4KY5jiQL8U1TPVfYe++ixPr/2IFsup/RnVDiDuG1Lx5g:xURmR9vjY5HD9RYeiPaDK5V2DPls

Entry address:
0x310D

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 57, 33, DB, 68, 01, 80, 00, 00, 89, 5C, 24, 1C, C7, 44, 24, 14, 88, 91, 40, 00, 33, F6, C6, 44, 24, 18, 20, FF, 15, B4, 70, 40, 00, FF, 15, B0, 70, 40, 00, 66, 3D, 06, 00, 74, 11, 53, E8, E4, 2D, 00, 00, 3B, C3, 74, 07, 68, 00, 0C, 00, 00, FF, D0, 68, 7C, 91, 40, 00, E8, 65, 2D, 00, 00, 68, 74, 91, 40, 00, E8, 5B, 2D, 00, 00, 68, 68, 91, 40, 00, E8, 51, 2D, 00, 00, 6A, 0D, E8, B4, 2D, 00, 00, 6A, 0B, E8, AD, 2D, 00, 00, A3, 44, EC, 42, 00, FF, 15, 34, 70, 40, 00, 53, FF...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file UsbFix.exe has been seen being distributed by the following 33 URLs.

https://download.fosshub.com/Protected/expiretime=1452780077;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/8eb71d537fdebd408ef5315f5ec4fb6cff3e60ea79b3e36634835b298278daf8/.../UsbFix_2016_8.181.exe

https://download.fosshub.com/Protected/expiretime=1452958846;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/072f629dbfae4c2a8fe1bb8c37248c2e299158c124acbde6fa684691d23b56e8/.../UsbFix_2016_8.181.exe

https://download.fosshub.com/Protected/expiretime=1453081762;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/d5bbb95025f9d688d3f5259b7915d38ad05754b7a30828228bfa32fc8753ace5/.../UsbFix_2016_8.181.exe

https://download.fosshub.com/Protected/expiretime=1452500029;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/6af42f3330a033d8efd72b0adaca3ce943fbc88e3e4d768ce00ec1b8dbe18a97/.../UsbFix_2016_8.181.exe

https://download.fosshub.com/Protected/expiretime=1453241580;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/72156a9ce50974582cadd84bb3d37e5b58acff8c5e78ad1a4c4b804d4deb8996/.../UsbFix_2016_8.181.exe

temp:UsbFix_2016_8.181.exe

http://www.telecharger.sosvirus.net/download/.../?wpdmdl=173&wpdmtoken=Z452NIRiNfAzOPtWvOhtwNTEUDvTPXi3LC1lp_brU8Y

https://download.fosshub.com/Protected/expiretime=1453215320;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/d02ddf94416114e8fc160703ca3ebafaa49a236e6df7b22f014ba64339bd5156/.../UsbFix_2016_8.181.exe

https://download.fosshub.com/Protected/expiretime=1452625379;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/067b04d817dbe76e8b52b6e977d7c1ce5b42765e483ebee3beb15436aa54b741/.../UsbFix_2016_8.181.exe

https://download.fosshub.com/Protected/expiretime=1452550938;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/a58261cb09e9d725d201d404bbb5a8710e4644ec0af17ccf42e8754bad8ea86f/.../UsbFix_2016_8.181.exe

https://download.fosshub.com/Protected/expiretime=1453239952;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/7f7977d7ed8999a3391abee66273506073858e3801ef7e24894c9c1476ef52a4/.../UsbFix_2016_8.181.exe

https://download.fosshub.com/Protected/expiretime=1452933432;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/b21bd36ade6ace3e2e0de8d8a03534c4318d784117227a46f9bef8e10ddc5b3f/.../UsbFix_2016_8.181.exe

https://download.fosshub.com/Protected/expiretime=1452867490;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Vc2JGaXguaHRtbA==/70dfb97b22f45a2254509511caadeae64e8cd4a30a2c434ce1ac164bf25d2aeb/.../UsbFix_2016_8.181.exe

http://download1582.mediafire.com/hk22bcca2q9g/.../UsbFix_2016_8.181.exe

Latest 30 of 33 download URLs

Scan UsbFix.exe - Powered by Reason Core Security