fufd173.exe

OfferInstaller

The application fufd173.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. According to AVG, this software downloads additional adware offers during setup.
Product:
OfferInstaller

Version:
1.0.0.1

MD5:
462b1c0440441f4b3320535eea85a2f5

SHA-1:
55abf9ec8924b883f1644d65acfbcdec1474e2b4

SHA-256:
6f0ea913fcfa986de832dbc4531df74331ec45841c860696a361366c5262a5fb

Scanner detections:
21 / 68

Status:
Potentially unwanted

Analysis date:
1/14/2025 10:43:32 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2613924
550

AhnLab V3 Security
PUP/Win32.OfferInstaller
2015.08.03

Avira AntiVirus
TR/Dropper.MSIL.Gen
8.3.1.6

Arcabit
Trojan.Generic.D27E2A4
1.0.0.425

avast!
Win32:Adware-gen [Adw]
2014.9-150803

AVG
Downloader
2016.0.3028

Baidu Antivirus
Adware.MSIL.Imali
4.0.3.1583

Bitdefender
Trojan.GenericKD.2613924
1.0.20.1075

Comodo Security
ApplicUnwnt
22920

Emsisoft Anti-Malware
Trojan.GenericKD.2613924
8.15.08.03.11

ESET NOD32
MSIL/Adware.Imali (variant)
9.12034

Fortinet FortiGate
Adware/Imali
8/3/2015

F-Secure
Trojan.GenericKD.2613924
11.2015-03-08_2

G Data
Trojan.GenericKD.2613924
15.8.25

herdProtect (fuzzy)
2015.9.9.5

IKARUS anti.virus
AdWare.MSIL.Imali
t3scan.1.9.5.0

McAfee
Artemis!462B1C044044
5600.6684

MicroWorld eScan
Trojan.GenericKD.2613924
16.0.0.645

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.OfferInstaller.Bundler.Installer.Meta (M)
15.8.3.23

Sophos
Offer Installer
4.98

File size:
407.5 KB (417,280 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © 2014

Original file name:
OfferInstaller_dotnet2.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\users\{user}\appdata\local\temp\fufd173.exe

File PE Metadata
Compilation timestamp:
8/2/2015 4:44:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:RA72oFZT8qbTR7SquD4L8vioH/X8i9DLnHWcefjVo8bS5VH7oOBEJL:AvZwgVxGq86oH/MKvnolgfK1

Entry address:
0x66ABE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
403 KB (412,672 bytes)

Remove fufd173.exe - Powered by Reason Core Security