wizard101 setup.exe

7-Zip

Igor Pavlov

The application wizard101 setup.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from software.softwaredownloadguru.com.
Publisher:
Igor Pavlov

Product:
7-Zip

Description:
7z Setup SFX

Version:
9.20

MD5:
3bc1f2cba74782eeeff43250ed6c295d

SHA-1:
afeea6064baefcdcc8429debf8f3cb283e0b1e1f

SHA-256:
c9b4285d84c20bfb6e7bdf879b14d71940fee0be09d3162cbc2cbce49e8e497a

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
5/20/2024 1:58:04 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160518-2

ESET NOD32
Win32/DownloadAssistant.C potentially unwanted application
8.0.319.0

F-Secure
Variant.Application.Bundler
5.15.96

VIPRE Antivirus
Threat.4150696
48878

File size:
1.1 MB (1,131,799 bytes)

Product version:
9.20

Copyright:
Copyright (c) 1999-2010 Igor Pavlov

Original file name:
7zS.sfx.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\wizard101 setup.exe

File PE Metadata
Compilation timestamp:
11/18/2010 11:27:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:91OYdaz4ezcIZrSsWl6scxglIRdCxbJqowYB3lmOlSg+CCej/two/1lekxFiwq:91OsW1hSd6scxQIRd0JtBDoE/tj3eqq

Entry address:
0x14B04

Entry point:
55, 8B, EC, 6A, FF, 68, E0, B9, 41, 00, 68, 2C, 4A, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 74, B0, 41, 00, 33, D2, 8A, D4, 89, 15, D0, 33, 42, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, CC, 33, 42, 00, C1, E1, 08, 03, CA, 89, 0D, C8, 33, 42, 00, C1, E8, 10, A3, C4, 33, 42, 00, 6A, 01, E8, 96, 0E, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 48, 09, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
7.9233

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
102.5 KB (104,960 bytes)

The file wizard101 setup.exe has been seen being distributed by the following URL.

Remove wizard101 setup.exe - Powered by Reason Core Security