ezlookersilent_ddd_ftt_bg_bd_bvd.exe

ezLooker

Double Simple LLC

The application ezlookersilent_ddd_ftt_bg_bd_bvd.exe has been detected as a potentially unwanted program by 14 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from cdn.install.oibundles.com.
Publisher:
Double Simple LLC

Product:
ezLooker

Description:
Installer

Version:
2012.1.12.1059

MD5:
cc345b41e8bcb22e5e8bdd8749334453

SHA-1:
2029598e3ef514b289f3d9b8ae9ed122b1cd00a5

SHA-256:
1efeebb5d65410eba0afb501c1d1a455e6dba51231243375aacde28c2adb26dd

Scanner detections:
14 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 7:53:28 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Yontoo
7.1.1

avast!
Win32:Adware-gen [Adw]
2014.9-141008

Baidu Antivirus
Adware.Win32.Yontoo
4.0.3.14108

Comodo Security
Heur.Suspicious
19261

Dr.Web
Adware.Plugin.11
9.0.1.0281

ESET NOD32
Win32/Adware.Yontoo
8.10287

Fortinet FortiGate
Riskware/Yontoo
10/8/2014

F-Prot
W32/AdwareX.JUO
v6.4.7.1.166

IKARUS anti.virus
AdWare.Yontoo
t3scan.1.7.5.0

K7 AntiVirus
Adware
13.183.13113

NANO AntiVirus
Riskware.Win32.Siggen.cyptve
0.28.2.61721

Reason Heuristics
Threat.Win.Reputation.IMP
14.10.8.22

Rising Antivirus
PE:Trojan.Win32.Generic.151E4CB2!354307250
23.00.65.141006

Trend Micro House Call
TROJ_GEN.F47V0602
7.2.281

File size:
1.1 MB (1,161,112 bytes)

Product version:
1.00

Copyright:
Copyright (c) 2011 Double Simple LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
3/10/2011 6:55:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:VZN2yjQsIO/fXBT7yo0Hnhaksq8TEJIS12DraFn6Vewan:VHrjD/f50HAksq8csDr80d4

Entry address:
0x1627

Entry point:
55, 8B, EC, 81, EC, 58, 0B, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, A8, F4, FF, FF, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, B8, FC, FF, FF, 50, C7, 85, B8, FC, FF, FF, 14, 01, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, 30, 34, 40, 00, E8, 40, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, C5, 01, 00, 00, 68, 1C, 34, 40, 00, 68, 0C, 34, 40, 00, FF, 15, 68, 30, 40, 00, 50, FF, 15, 64, 30, 40, 00, 3B...
 
[+]

Entropy:
7.9963

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file ezlookersilent_ddd_ftt_bg_bd_bvd.exe has been seen being distributed by the following URL.

Remove ezlookersilent_ddd_ftt_bg_bd_bvd.exe - Powered by Reason Core Security