WEXTRACT.EXE

Windows Internet Explorer

Microsoft Corporation

Publisher:
Microsoft Corporation  (signed and verified)

Product:
Windows® Internet Explorer

Description:
Win32 Cabinet Self-Extractor

Version:
9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)

MD5:
7c1fc2021cf57fed3c25c9b03cd0c31a

SHA-1:
f8f1217f666bf2f6863631a7d5e5fb3a8d1542df

SHA-256:
8746ee1a84a083a90e37899d71d50d5c7c015e69688a466aa80447f011780c0d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/26/2024 2:31:39 AM UTC  (today)

File size:
95.6 MB (100,271,992 bytes)

Product version:
9.00.8112.16421

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
WEXTRACT.EXE .MUI

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\wextract.exe .mui

Digital Signature
Authority:
Microsoft Corporation

Valid from:
2/21/2011 3:53:12 PM

Valid to:
5/21/2012 4:53:12 PM

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
6101B29B000000000015

File PE Metadata
Compilation timestamp:
3/8/2011 7:46:37 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1572864:5eKHwu9mdcsB10CvInhZfiuM3Or17hWocUW1o6vSxfcBLuGgf3FmVOUxXBKYSJTP:ZwuAdf0CvIjfiu62hgUW1bSxkQGgPb0m

Entry address:
0x6B42

Entry point:
E8, 5D, 07, 00, 00, E9, 4D, FD, FF, FF, CC, CC, CC, CC, CC, 3B, 0D, C4, C2, 00, 01, 75, 03, C2, 00, 00, E9, D9, 07, 00, 00, CC, CC, CC, CC, CC, FF, 25, 7C, 12, 00, 01, CC, CC, CC, CC, CC, CC, FF, 25, 78, 12, 00, 01, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 81, EC, D0, 02, 00, 00, A1, C4, C2, 00, 01, 33, C5, 89, 45, FC, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC, FD, FF, FF, 66, 8C, 95, F8, FD, FF, FF, 66, 8C, 8D, EC, FD...
 
[+]

Code size:
43.5 KB (44,544 bytes)

The file WEXTRACT.EXE has been discovered within the following program.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
 
Powered by Should I Remove It?

The file WEXTRACT.EXE has been seen being distributed by the following 50 URLs.

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/es/download/file/.../

http://indir.gezginler.net/i/887/3838375f323031372d30312d3033/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://www.lo4d.com/get-file/directx-9-0c/.../

http://filehippo.com/it/download/file/.../

http://filehippo.com/pl/download/file/.../

http://www.lo4d.com/get-file/directx-9-0c/.../

http://filehippo.com/download/file/.../

http://download1822.mediafire.com/1gl1fgp3l38g/.../directx_Jun2010_redist.exe

http://filehippo.com/download/file/.../

http://directx-end-user-runtimes.software.informer.com/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/es/download/file/.../

http://filehippo.com/download/file/.../

http://gsf-cf.softonic.com/f8f/121/.../file?SD_used=0&channel=WEB&fdh=no&id_file=30107&instance=softonic_fr&type=PROGRAM&Expires=1486852833&Signature=FH~dxdgrPaiv78oWiPkedWMkFtb6eNZxXNQKkatn~sHJi1rWBe9Lsw80YMZjsD0wXLreLpkBkq6R-wINBf1t6fe0XXRMfg7vDuNplef2djjBBEe4BHnyENmES4-TwmGkMX2buJh86CrKcT7q6A1c-81NUHqS-RMhTEUT1wEZRh0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=directx_Jun2010_redist.exe

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/es/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/it/download/file/.../

http://filehippo.com/download/file/.../

Latest 30 of 2,508 download URLs