windows 7 validation tool.exe

RunWindows

The executable windows 7 validation tool.exe has been detected as malware by 15 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dl.dropboxusercontent.com and multiple other hosts.
Product:
RunWindows

Version:
1.0.0.0

MD5:
3c13d7d768dd29150ce7a3e291d64053

SHA-1:
8f958604ea56f6c7628e6e99324551c5a124429d

SHA-256:
0cc4ca064427b8790b54c4d872284baf95de2255afcbcba39ff9a5a21789a7c5

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
4/25/2024 12:28:50 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.10115883
1136

Bitdefender
Trojan.Generic.10115883
1.0.20.1795

Bkav FE
W32.Clod83c.Trojan
1.3.0.4677

Emsisoft Anti-Malware
Trojan.Generic.10115883
8.13.12.25.08

F-Secure
Trojan.Generic.10115883
11.2013-25-12_4

G Data
Trojan.Generic.10115883
13.12.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.2.2.29

K7 AntiVirus
Riskware
13.175.10881

McAfee
Artemis!3C13D7D768DD
5600.7270

MicroWorld eScan
Trojan.Generic.10115883
14.0.0.1077

nProtect
Trojan.Generic.10115883
14.01.17.02

Sophos
Troj/Keygen-IA
4.96

Trend Micro House Call
TROJ_GEN.R0C1H08JV13
7.2.359

VIPRE Antivirus
Trojan.Win32.Generic
25536

ViRobot
Backdoor.Win32.A.Ceckno.545280
2011.4.7.4223

File size:
532.5 KB (545,280 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2009

Original file name:
Windows 7 Validation.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\windows 7 validation tool.exe

File PE Metadata
Compilation timestamp:
2/13/2009 7:51:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:FJ5CQSojuQ8SRyYnaNSOuxJ5CQSojuQ8SR0UIuYnaNSOu:YQuJNYnncQuJrnuYnn

Entry address:
0x64A8E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
395 KB (404,480 bytes)

The file windows 7 validation tool.exe has been seen being distributed by the following 2 URLs.

Remove windows 7 validation tool.exe - Powered by Reason Core Security