7smokerpro.exe

7Smoker Pro

WareSoft Software

The application 7smokerpro.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. This file is typically installed with the program Toolwiz Time Freeze 2014 by ToolWiz. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from software-files-a.cnet.com and multiple other hosts.
Publisher:
WareSoft Software

Product:
7Smoker Pro

Version:
7Smoker Pro

MD5:
abcaf24a058ff06816c16fa79666ecee

SHA-1:
1f9ce0a43402b034689cd14fd2792e0b647c697a

SHA-256:
17bd875b76b60688fabb72bdecb71e5281b3fa186e0391bb9260dd6abc7147f1

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
11/24/2024 7:24:58 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallMonetizer.AU
8.9822

Reason Heuristics
PUP.InstallMonetizer.Bundle (M)
16.3.10.15

File size:
1.6 MB (1,711,154 bytes)

Product version:
2.0

Copyright:
Copyright © 2013 WareSoft Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\7smokerpro.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:C9tkZTv7a8bpNPFnYaZPRSp4R3kzRED+p6Di:MtkV7a8bpTZPRHloRED2ki

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9921

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file 7smokerpro.exe has been discovered within the following program.

www.Toolwiz.com
About 1% of users remove it
 
Powered by Should I Remove It?

The file 7smokerpro.exe has been seen being distributed by the following 3 URLs.

Remove 7smokerpro.exe - Powered by Reason Core Security