addonsvpus-54495308d678c.exe

SavePs

The application addonsvpus-54495308d678c.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from cdn.file2desktop.com.
Publisher:
SavePs

Product:
SavePs

Version:
1.0

MD5:
7abdda54488f1269f1ddfc58fdcaf139

SHA-1:
7e7225561c5fd223c18bb5d4f1152dd4f1bf43da

SHA-256:
f7d8fdf8d529f33d22b35734aabfe306abee43f3fbef0aceff5812ce63e286b9

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/2/2024 5:30:50 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
W32.Sality
2.1.4+

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.180.234

avast!
Win32:Dropper-gen [Drp]
2014.9-141024

Baidu Antivirus
PUA.Win32.OutBrowse
4.0.3.141024

ESET NOD32
Win32/OutBrowse.AZ (variant)
8.10614

Malwarebytes
PUP.Optional.OutBrowse
v2014.10.24.08

NANO AntiVirus
Trojan.Win32.OutBrowse.dgnlgr
0.28.2.62841

File size:
10.1 MB (10,581,949 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\windows\temp\xtrm group ltd\mysafeproxy\1.0.11.0\addonsvpus-54495308d678c.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:RIazZ5lUVumXEk00Uq2LDC+OamUupJeDyCiYEGjr1bfHwS:uazZ0V/XEp0IDMleOCoS

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9993

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file addonsvpus-54495308d678c.exe has been seen being distributed by the following URL.

Remove addonsvpus-54495308d678c.exe - Powered by Reason Core Security