download.exe

Alexey Kurilenko

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application download.exe by Alexey Kurilenko has been detected as adware by 25 anti-malware scanners. This is a setup program which is used to install the application. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Alexey Kurilenko  (signed and verified)

MD5:
c74ffd7f6b9dc81459784e6403d83430

SHA-1:
c54133837fd214f2177612b3dcb17b06f89229f4

SHA-256:
282c640cbe1cff3796cef4e4c64fec30bb02bd11eca35fd200a78981d0647767

Scanner detections:
25 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/23/2024 5:32:25 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Kazy.481287
6089308

AhnLab V3 Security
PUP/Win32.MultiPlug
2014.12.09

Avira AntiVirus
Adware/MultiPlug.aob
7.11.193.180

avast!
Win32:MultiPlug-JU [PUP]
141130-1

AVG
Adware Generic_r.VD
2014.0.4235

Bitdefender
Gen:Variant.Adware.Kazy.481287
1.0.20.1710

Comodo Security
Application.Win32.Multiplug.CT
20307

Dr.Web
Trojan.Crossrider.36840
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Kazy.481287
9.0.0.4668

ESET NOD32
Win32/AdWare.MultiPlug.CT application
7.0.302.0

Fortinet FortiGate
Adware/MultiPlug
12/8/2014

F-Prot
W32/A-327c3a17
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Kazy.481287
11.2014-08-12_2

G Data
Gen:Variant.Adware.Kazy.481287
14.12.24

K7 AntiVirus
Unwanted-Program
13.186.14270

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

McAfee
Program.MultiPlug-FRO
16.8.708.2

MicroWorld eScan
Gen:Variant.Adware.Kazy.481287
15.0.0.1026

NANO AntiVirus
Riskware.Win32.MultiPlug.dfjscb
0.28.6.63850

Norman
Gen:Variant.Adware.Kazy.481287
04.12.2014 14:30:06

Panda Antivirus
PUP/TSUploader
14.12.08.08

Reason Heuristics
PUP.AlexeyKurilenko.I
14.12.8.20

Sophos
PUA 'MultiPlug' (of type Adware)
5.08

Vba32 AntiVirus
SScope.Adware.MultiPlug
3.12.26.3

VIPRE Antivirus
Threat.4786450
35418

File size:
878.4 KB (899,448 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\download.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/17/2014 1:20:17 PM

Valid to:
6/17/2015 1:20:17 PM

Subject:
E=Alexey.kurilenko@hotmail.com, CN=Alexey Kurilenko, O=Alexey Kurilenko, C=RU

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
15D51642691B3EE20985639A8FE865DD

File PE Metadata
Compilation timestamp:
6/2/2012 6:39:13 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:litdQLsyv/nOSGQM6x0c2C6k0n2khyrvsK71L:EtkRfdip2/rvsKhL

Entry address:
0x3E006

Entry point:
E8, 78, 48, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 10, C5, 44, 00, E8, E4, 0F, 00, 00, E8, 45, 4A, 00, 00, 0F, B7, F0, 6A, 02, E8, 0B, 48, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, D6, 08, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.7072  (probably packed)

Code size:
280.5 KB (287,232 bytes)

The file download.exe has been seen being distributed by the following URL.

Remove download.exe - Powered by Reason Core Security