490d0e0ededf117a8348275ce5a2f314_node-kit-pft.exe

Proxomitron

SBIS

The application 490d0e0ededf117a8348275ce5a2f314_node-kit-pft.exe by SBIS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Groom-A-Zebu (tm)   (signed by SBIS)

Product:
Proxomitron

Description:
The Proxomitron

Version:
4, 5, 0, 4

MD5:
bd01c6d657a5a1a0ab79223ced634b1e

SHA-1:
f65562e581049f499188d0451b87849e286537ca

SHA-256:
967d09732ec953d19ff6f71d61540f52744627a248383feeda558e42ba039325

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 8:33:59 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.15.5

File size:
604.4 KB (618,936 bytes)

Product version:
Naoko-4.5 2003-6-1

Copyright:
Copyright © 1999 - 2003 By Scott R. Lemmon

Trademarks:
Proxomitron, The, and the letters A-Z

Original file name:
Proxomitron.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\installmoney\490d0e0ededf117a8348275ce5a2f314_node-kit-pft.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/2/2015 12:00:00 PM

Valid to:
5/2/2016 11:59:59 AM

Subject:
CN=SBIS, O=SBIS, STREET="PR-T MOSKOVSKIJ, 12", L=YAROSLAVL, S=YAROSLAVL REGION, PostalCode=150001, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009CA0BE54A9516364680AD45D6408C6A2

File PE Metadata
Compilation timestamp:
6/19/1992 10:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x7DA29

Entry point:
E9, 2B, 68, 00, 00, D2, D0, 2C, 7E, 2C, 59, 89, DF, D2, F8, 80, FD, C9, B0, 2E, E8, A0, 6B, 00, 00, C7, 44, 24, 04, FF, 73, F0, E0, E8, CC, A2, 00, 00, 00, 00, 47, 65, 74, 53, 63, 72, 6F, 6C, 6C, 50, 6F, 73, 00, 38, EF, F8, 2C, 30, F8, F6, C4, 83, 3C, 09, E8, 8E, 4F, 00, 00, 88, 1C, 24, E8, 20, 36, 00, 00, 68, 11, C1, 49, 7D, 68, F6, 3D, 80, A1, C6, 04, 24, 8E, 60, 8D, 64, 24, 24, E9, 8B, CD, 00, 00, 8D, 64, 24, 34, 0F, 87, DD, 1C, 00, 00, 00, E0, 29, FB, F9, 66, 0F, BD, FC, 01, E3, 8D, 3C, CD, 4C, 12, FB...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
440 KB (450,560 bytes)