bing4chrome.exe

The application bing4chrome.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from secured.secureeastcdn.us.
MD5:
e79d9151bcda23667be5cf0026e0cca9

SHA-1:
047c659c5c85092a3593757e228f8de74b060f7e

SHA-256:
366ad03e79940a8ed767497188ba37dd5ed3210d4d606991c560ddfca7bd8f28

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
11/30/2024 10:08:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1083842
749

Clam AntiVirus
Win.Adware.Linkury-2963
0.98/21511

Dr.Web
Trojan.AVKill.24016
9.0.1.016

ESET NOD32
Win32/Toolbar.Linkury
9.11024

F-Secure
Application.Generic.1083842
11.2015-16-01_6

G Data
Win32.Application.Linkury
15.1.24

IKARUS anti.virus
AdWare.Linkury
t3scan.1.8.6.0

Kaspersky
not-a-virus:WebToolbar.MSIL.SmartBar
14.0.0.2632

Malwarebytes
PUP.Optional.SmartBar
v2015.01.16.02

McAfee
Artemis!0B32F20D8AD7
5600.6883

MicroWorld eScan
Application.Generic.1085709
16.0.0.48

NANO AntiVirus
Riskware.Win32.Linkury.ddpups
0.30.0.64448

Qihoo 360 Security
Win32/Virus.WebToolbar.d99
1.0.0.1015

Trend Micro House Call
Suspici.46EFE19D
7.2.16

Trend Micro
JS_URYLINK.A
10.465.16

VIPRE Antivirus
InstallMonetizer
36706

File size:
7.4 MB (7,717,944 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\chk5xpee\bing4chrome.exe

File PE Metadata
Compilation timestamp:
12/5/2009 5:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:SWcbQdvj0qJT3lozYw4lYgYHWuLLoZFsDOgM7h7/Gj16V39I:q4vj5EzYJ2+Ld7R/k8V3a

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9996

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file bing4chrome.exe has been seen being distributed by the following URL.

Remove bing4chrome.exe - Powered by Reason Core Security