Should I block it?
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization
Additional versions
(Note, Somoto Ltd. publishes each variation of this file with the same version, but the hashes are unique.)
Relationships
biclient.exe
Better Installer by Somoto Ltd. (Signed)
Version: | 2.0.0.0 |
MD5: | c66293ccd7cbe84b1b8f393ca5e4e6d7 |
SHA1: | c24089d407e6280b79bec86532e9de0118e4de71 |
SHA256: | ffbae29e2f233767fd42909720497165ce3552427ef93efb2fc714fb4204755f |
Warning 4 antivirus scanners has detected malware.
Overview
biclient.exe is malware that executes as a process with the local user's privileges. The file is digitally signed by Somoto Ltd. which was issued by the COMODO CA Limited certificate authority (CA).
Details
File name: | biclient.exe |
Publisher: | Somoto Ltd. |
Product name: | Better Installer |
Description: | Better Installer Host |
Typical file path: | C:\users\user\appdata\local\temp\biclient.exe |
Original name: | BetterInstaller.exe |
File version: | 2.0.0.0 |
Size: | 219 KB (224,256 bytes) |
Certificate |
Issued to: | Somoto Ltd. |
Authority (CA): | COMODO CA Limited |
Expiration date: | Saturday, September 20, 2014 |
Digital DNA |
File packed: | No |
.NET CLR: | No |
More details
Network connections
[UDP] listens on port 54758
Malware detections
Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
Antivirus engine | Engine version | Detection |
Emsisoft Anti-Malware |
3.0.0.575 |
Riskware.WebToolbar.Win32.BetterInstaller.AMN (A) |
ESET NOD32 |
7.8277 |
a variant of Win32/Somoto.A |
Sophos |
4.88.0 |
Somoto BetterInstaller |
ViRobot |
2011.4.7.4223 |
JS.A.Iframe.224256 |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00023988% | |
Kernel CPU: | 0.00018085% | |
User CPU: | 0.00005902% | |
Kernel CPU time: | 813 ms/min | |
Memory |
Private memory: | 22.75 MB | |
Private (maximum): | 46.62 MB | |
Private (minimum): | 45.76 MB | |
Non-paged memory: | 22.75 MB | |
Virtual memory: | 247.53 MB | |
Virtual memory (peak): | 272.03 MB | |
Working set: | 46.5 MB | |
Working set (peak): | 46.63 MB | |
Resource allocations |
Threads: | 17 | |
Handles: | 548 | |
GUI GDI count: | 24 | |
GUI GDI peak: | 27 | |
GUI USER count: | 40 | |
GUI USER peak: | 57 | |
Process properties
Integrety level: | Undefined |
Platform: | 64-bit |
Command line: | "C:\users\user\appdata\local\temp\biclient.exe" /initurl httC://bi.bisrv.com/:affiC:/:siC:/:uiC:? /affid "allgames2kryrf" /id "allgames2kwbnt" /name "allgames2k" /uniqid installer(1) |
Owner: | User |
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
33.33% |
|
Windows 7 Home Premium |
33.33% |
|
Windows 8 Pro with Media Center |
33.33% |
|
Distribution by country
Indonesia installs about 33.33% of Better Installer.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Acer |
50.00% |
|
Hewlett-Packard |
50.00% |
|