do_application_start.exe

Kpi Media Group

The application do_application_start.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup program which is used to install the application. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from intva6.routinetrends.com and multiple other hosts.
Publisher:
Kpi Media Group

Product:
Kpi Media Group

Version:
83.0.1.1579

MD5:
05d7ab516669ae69e5ce5383d5272929

SHA-1:
fd72dcac19bc65b7aad5aa5b79ac5c3a076af604

SHA-256:
f5a0ee170731d9d2f7e2ff681d034fcb70280f9ecefd8c7ebf8568a46579391b

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 11:03:45 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/DownloadAdmin.Q potentially unwanted application
8.0.319.0

Norman
Gen:Variant.Application.Bundler.DownloadAdmin.9
02.04.2016 17:35:19

File size:
885.8 KB (907,008 bytes)

Product version:
83.0.1.1579

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\do_application_start.exe

File PE Metadata
Compilation timestamp:
5/1/2015 12:18:10 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:zmZdPxJt5OxLdpBNF/pM9dVUcWNlBG51U9N55RRQNptlV3O9JVkhRbgBRim8QiV1:zmZdPxJt5OxLdpBNF/pM9dVUcWNlBG5p

Entry address:
0x1E06

Entry point:
E8, E5, C4, 00, 00, E9, E7, BD, 00, 00, FF, 25, 5C, 94, 47, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 83, EC, 78, 56, 57, E8, 46, FB, FF, FF, E8, 41, 2D, 00, 00, 8B, B4, 24, 88, 00, 00, 00, 8B, BC, 24, 84, 00, 00, 00, 56, 57, E8, 9C, F9, FF, FF, 56, 57, E8, 15, 25, 00, 00, 8B, 06, 83, C4, 10, 50, FF, 15, EC, 00, 41, 00, 83, F8, FF, 74, 2E, 8B, 0E, 68, 84, 91, 47, 00, 68, 78, 90, 47, 00, 68, 04, 01, 00, 00, 51, FF, 15, 08, 01, 41, 00, 85, C0, 74, 07, 3D, 04, 01, 00, 00, 76, 2A, 5F, B8, 3C, 00, 00, 00, 5E...
 
[+]

Entropy:
7.9642  (probably packed)

Code size:
56.5 KB (57,856 bytes)

The file do_application_start.exe has been seen being distributed by the following 6 URLs.

Remove do_application_start.exe - Powered by Reason Core Security