winzip155.exe

WinZip Computing

This is the installation and setup package for WinZip, a file compression/decompression utilitiy that has a GUI to zip interface. The installer might bundle additional software offers during setup including the AVG browser toolbar. The application winzip155.exe by WinZip Computing has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup program which is used to install the application. It uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
WinZip Computing  (signed and verified)

MD5:
fc52b72cfb4d226e75155b600cc791ec

SHA-1:
6e9541bd83859540d2f81638583f22412c595fc9

SHA-256:
9be350482ba74cfcfe5b43e3f7eb56d8b6ca38c0367844ec849d89cfe029e269

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
The setup program might include offers for additional software during installation.

Analysis date:
4/26/2024 2:49:56 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
8.8912

Malwarebytes
PUP.Optional.OpenCandy
v2014.05.09.03

Reason Heuristics
PUP.OpenCandy (M)
16.11.29.22

File size:
16.1 MB (16,901,448 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/14/2009 1:00:00 AM

Valid to:
4/14/2012 12:59:59 AM

Subject:
CN=WinZip Computing, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WinZip Computing, L=Mansfield, S=Connecticut, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2091EC663B9B070DEF16CA9A237B705B

File PE Metadata
Compilation timestamp:
11/2/2009 8:24:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
393216:e/o2XA6ELQxyhZz5/UCtfNErMbIgpyxkXqENKAL7:e/o2+Qx4/UATpy6vL7

Entry address:
0x1479F

Entry point:
E8, 02, 67, 00, 00, E9, 17, FE, FF, FF, 3B, 0D, D8, C9, 42, 00, 75, 02, F3, C3, E9, 82, 67, 00, 00, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, 18, 48, 41, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, 54, E6, 00, 00, 8B, 45, 0C, 8B, 40, 04, 83...
 
[+]

Entropy:
7.9983  (probably packed)

Code size:
144 KB (147,456 bytes)

The file winzip155.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to oi.cloud.avg.com  (204.193.144.33:80)

TCP (HTTP):
Connects to inst.avg.com  (204.193.144.89:80)

Remove winzip155.exe - Powered by Reason Core Security