installer.exe

The application installer.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from www.currentgiftstock.com.
MD5:
13771c04264bdbedb58fc226537292bb

SHA-1:
e421048e148454423a3482ba0bbd8471e71f302d

SHA-256:
9e9982a0d941741102660c905a02d8a5b295dc2e985cfe28d0a0fe48b29b55f5

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 6:58:48 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.7400

Kaspersky
not-a-virus:AdWare.Win32.DealPly
15.0.0.562

Norman
Gen:Variant.Application.Bundler.71
11.01.2016 17:30:26

Panda Antivirus
Trj/Swizzor.S
16.01.15.02

Qihoo 360 Security
QVM08.0.Malware.Gen
1.0.0.1077

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48 [F]
23.00.65.16113

File size:
500 KB (512,000 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\installer.exe

File PE Metadata
Compilation timestamp:
1/14/2016 6:23:22 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:g5qRTbaenoyOg62ELmYUuaos4ULuLAzDIShku:g5q1badyuH3UTosxuCDNhF

Entry address:
0x70E86

Entry point:
6A, 60, 68, 40, 81, 47, 00, E8, 32, 15, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 82, 16, 00, 00, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 28, 80, 47, 00, 8B, 4E, 10, 89, 0D, 38, AC, 47, 00, 8B, 46, 04, A3, 44, AC, 47, 00, 8B, 56, 08, 89, 15, 48, AC, 47, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 3C, AC, 47, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 3C, AC, 47, 00, C1, E0, 08, 03, C2, A3, 40, AC, 47, 00, 33, F6, 56, 8B, 3D, 1C, 80, 47, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
476 KB (487,424 bytes)

The file installer.exe has been seen being distributed by the following URL.

Remove installer.exe - Powered by Reason Core Security