windows-loader-2.2.exe

Операционная система Microsoft Windows

Smart Finekspert, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application windows-loader-2.2.exe, “Исполняемый файл для игры "Солитер"” by Smart Finekspert, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from frogrush.ru.
Publisher:
Microsoft Corporation  (signed by Smart Finekspert, TOV)

Product:
Операционная система Microsoft® Windows®

Description:
Исполняемый файл для игры "Солитер"

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
4dcf57f0031c54673aba8ef5f57a12e4

SHA-1:
52c6ac08e7f26e4b57f9e2aa306cb447ba524c2e

SHA-256:
adf24f9a829aac1ebc9588ca3cba4a877bc47e42631d62dbb424ea250fb391e0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/21/2024 5:08:27 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SmartFin
17.2.25.10

File size:
4.1 MB (4,295,656 bytes)

Product version:
6.1.7600.16385

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
freecell.exe.mui

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\windows-loader-2.2.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/13/2016 4:00:00 AM

Valid to:
5/11/2017 3:59:59 AM

Subject:
CN="Smart Finekspert, TOV", OU=IT, O="Smart Finekspert, TOV", STREET="Dekabrystiv, 38A/9", L=Mykolayiv, S=Mykolayivska, PostalCode=54017, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009E7DF9BEED6E2C61477A3A241B54B4E6

File PE Metadata
Compilation timestamp:
4/23/2012 8:05:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x3F65E6

Entry point:
E8, 69, 11, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 60, 50, 80, 00, E8, 04, 17, 00, 00, E8, 3A, 13, 00, 00, 0F, B7, F0, 6A, 02, E8, FC, 10, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, BB, 08, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
4 MB (4,191,744 bytes)

The file windows-loader-2.2.exe has been seen being distributed by the following URL.

http://frogrush.ru/146705072691019487/windows-loader-2/.../?load=1

Remove windows-loader-2.2.exe - Powered by Reason Core Security