anvir_5457.exe

The application anvir_5457.exe has been detected as a potentially unwanted program by 15 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from secured.westsecurecdn.us.
MD5:
c13731093642ecf21e183f7ff1c3d3e7

SHA-1:
917ae06d2f63894185d4f5b061e2f665573f60f2

SHA-256:
07249f7e2e929365ebb019be6192e138297d25fb0d846ca9b7cc4363ec67b787

Scanner detections:
15 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
12/26/2024 11:00:44 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/InstallMonetizer.Gen
8.3.1.6

AVG
AdInstaller
2016.0.3034

Baidu Antivirus
Adware.NSIS.Agent
4.0.3.15728

Dr.Web
Adware.Downware.11265
9.0.1.0209

Kaspersky
not-a-virus:AdWare.NSIS.Agent
14.0.0.1666

Malwarebytes
PUP.Optional.CheckOffer
v2015.07.28.08

McAfee
Artemis!C13731093642
5600.6690

NANO AntiVirus
Trojan.Nsis.Downloader.djhpgw
0.30.24.2487

Panda Antivirus
Generic Suspicious
15.07.28.08

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1015

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.15726

SUPERAntiSpyware
Adware.InstallMonetizer/Variant
9725

Trend Micro
TROJ_GEN.R02KC0OG915
10.465.28

VIPRE Antivirus
Adware.NSIS.Agent
41860

Zillya! Antivirus
Adware.Agent.Win32.64384
2.0.0.2277

File size:
223.7 KB (229,110 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\anvir_5457.exe

File PE Metadata
Compilation timestamp:
12/5/2009 10:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:HFJ0WuLCUChCz0jf7pJ59E6rTUadigTZyt5q2pd5A8Wwf:fumUiCQjf7pBxddZybJd5A8v

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file anvir_5457.exe has been seen being distributed by the following URL.

Remove anvir_5457.exe - Powered by Reason Core Security