WindowsToUSBLite.exe

Windows to USB Lite

DKey Software

The application WindowsToUSBLite.exe by DKey Software has been detected as a potentially unwanted program by 5 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from files1.majorgeeks.com and multiple other hosts.
Publisher:
Dkey-Software  (signed by DKey Software)

Product:
Windows to USB Lite

Version:
1.3.2.0

MD5:
1cd61b045cfd8fa592b6b43cab45a635

SHA-1:
2cd2af67689e4c4d30a715c78f71e17b7913a6c9

SHA-256:
0ee8501312150378006b281d15feac2053c34b898a332abce26893d9c8ceb403

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
4/18/2024 10:10:03 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3430

Dr.Web
Adware.Conduit.101
9.0.1.0179

NANO AntiVirus
Trojan.Win32.Conduit.deinwc
0.28.2.62286

Trend Micro House Call
Suspicious_GEN.F47V0624
7.2.179

VIPRE Antivirus
Conduit
30702

File size:
4.5 MB (4,705,680 bytes)

Product version:
1.3.2.0

Original file name:
WindowsToUSBLite.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\windowstousblite.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/10/2014 1:00:00 AM

Valid to:
3/11/2015 12:59:59 AM

Subject:
CN=DKey Software, O=DKey Software, STREET="Entuziastov str., 18", L=Podolsk, S=Moscow region, PostalCode=142103, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008BFA03E6FD819296CC22AE859D66CEAD

File PE Metadata
Compilation timestamp:
6/23/2014 10:13:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:LPLti05h+wK0KgIjRa/h4SgxnlYiwOBpIeWRsTpL6:jLz5zIFDQi1zwRsTp2

Entry address:
0x2B97BC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 7C, F5, 6A, 00, E8, C0, 14, D5, FF, A1, D8, 65, 6C, 00, 8B, 00, E8, 78, 2A, E5, FF, A1, D8, 65, 6C, 00, 8B, 00, B2, 01, E8, A6, 47, E5, FF, A1, D8, 65, 6C, 00, 8B, 00, BA, 2C, 98, 6B, 00, E8, 75, 24, E5, FF, 8B, 0D, A8, 68, 6C, 00, A1, D8, 65, 6C, 00, 8B, 00, 8B, 15, 74, AA, 6A, 00, E8, 59, 2A, E5, FF, A1, D8, 65, 6C, 00, 8B, 00, E8, 9D, 2B, E5, FF, E8, D0, CC, D4, FF, B0, 04, 02, 00, FF, FF, FF, FF, 11, 00, 00, 00, 57, 00, 69, 00, 6E, 00, 64, 00, 6F, 00, 77, 00, 73, 00, 54, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.7 MB (2,852,864 bytes)

The file WindowsToUSBLite.exe has been seen being distributed by the following 2 URLs.

Remove WindowsToUSBLite.exe - Powered by Reason Core Security