garena-plus.exe

Garena Plus

The application garena-plus.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from garena-plus.th.softonic.com.
Publisher:
Garena Plus

Product:
Garena Plus

Version:
2

MD5:
7003443e4917452991d285454436ec90

SHA-1:
43a6f198d493b871a0afec5817e4f108ea6668fc

SHA-256:
a46ea42ccf63c183eb47638d5655e5a997cb058a9c9352e21deee909416cef77

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
11/1/2024 11:32:35 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallMonetizer.AN potentially unwanted application
8.0.319.0

Reason Heuristics
PUP.InstallMonetizer.ET (M)
16.7.12.21

File size:
1.2 MB (1,239,784 bytes)

Product version:
2

Copyright:
Garena Plus

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\garena-plus.exe

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:NZHWk11HtGId7zpft9IIZo+xBw/bwg2XxPimkvL8BH1:ykV9zpft9/3zwTx2XxrPP

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.3362

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file garena-plus.exe has been seen being distributed by the following URL.

Remove garena-plus.exe - Powered by Reason Core Security