win 7 usb.exe

The application win 7 usb.exe has been detected as a potentially unwanted program by 7 anti-malware scanners. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from download659.mediafire.com.
MD5:
8fa37246a69843902f9c160d490f8516

SHA-1:
d7e2d8cf2c12ea3ffb2dbeab7b02daccd814396d

SHA-256:
a993413c8859d419d7dd82fb4b6bcfcd6c21719f0527d708a36282e769fe2fa8

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/24/2024 9:45:45 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Downloader
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.164.52

Clam AntiVirus
Win.Trojan.Agent-750502
0.98/19185

Dr.Web
Threat.Undefined
9.0.1.05190

IKARUS anti.virus
PUA.OutBrowse
t3scan.1.6.1.0

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Trend Micro House Call
Suspici.BBAC4570
7.2.208

File size:
1.2 MB (1,307,414 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\win 7 usb.exe

File PE Metadata
Compilation timestamp:
4/7/2014 7:01:46 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:upNlrNel7EzbBbo8fxqtupA+Zhkwt+Dlyvwi2VdW3T/pDkiyNXcVQzOke:2rS7Ez9k4OwA4h9oDE4i2ET/pDkiyNX6

Entry address:
0x1D57B

Entry point:
E8, 5C, 64, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 7A, FC, FF, FF, C7, 06, F0, B1, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, F0, B1, 42, 00, E9, 2F, FD, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, F0, B1, 42, 00, E8, 1C, FD, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 7E, C9, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Code size:
162 KB (165,888 bytes)

The file win 7 usb.exe has been seen being distributed by the following URL.

Remove win 7 usb.exe - Powered by Reason Core Security