installer26__7934_il13539.exe

The application installer26__7934_il13539.exe has been detected as a potentially unwanted program by 27 anti-malware scanners. This is a setup program which is used to install the application. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from downloadmee.com.
Version:
1.1.5.90

MD5:
019c0c1a78888081181c87dd6410f0a1

SHA-1:
0cb85997be82b00cab662c78b2230eedd7e5d6ab

SHA-256:
f16da1ed120c039f23237eb8893d579f73e61c557fc1d60f9b2bec7dc5ea1757

Scanner detections:
27 / 68

Status:
Potentially unwanted

Analysis date:
1/12/2025 10:41:58 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.563195
358

Agnitum Outpost
PUA.Amonetize
7.1.1

AhnLab V3 Security
PUP/Win32.Amonetiz
2015.03.17

Avira AntiVirus
ADWARE/Adware.Gen2
7.11.217.240

avast!
Win32:Dropper-gen [Drp]
2014.9-160212

Baidu Antivirus
PUA.Win32.Amonetize
4.0.3.16212

Bitdefender
Gen:Variant.Kazy.563195
1.0.20.215

Bkav FE
HW32.Packed
1.3.0.6379

Emsisoft Anti-Malware
Gen:Variant.Kazy.563195
8.16.02.12.03

ESET NOD32
Win32/Amonetize.EA potentially unwanted (variant)
10.11331

Fortinet FortiGate
Riskware/Amonetize
2/12/2016

F-Secure
Gen:Variant.Kazy.563195
11.2016-12-02_6

G Data
Gen:Variant.Kazy.563195
16.2.25

K7 AntiVirus
Trojan
13.201.15282

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
14.0.0.674

Malwarebytes
PUP.Optional.Amonetize
v2016.02.12.03

McAfee
RDN/Generic PUP.x!c2m
5600.6492

MicroWorld eScan
Gen:Variant.Kazy.563195
17.0.0.129

NANO AntiVirus
Riskware.Win32.Amonetize.doukvl
0.30.0.296

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
2.16.14.00

Reason Heuristics
PUP.Amonetize (M)
16.2.12.3

Sophos
Generic PUA AM
4.98

Trend Micro House Call
TROJ_GEN.R021C0EC815
7.2.43

Trend Micro
TROJ_GEN.R021C0EC815
10.465.12

Vba32 AntiVirus
AdWare.Amonetize
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
38498

File size:
697.5 KB (714,240 bytes)

Product version:
1.1.5.90

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\installer26__7934_il13539.exe

File PE Metadata
Compilation timestamp:
2/25/2015 11:01:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:MXm61JbZ9DvakMeza6L3nuGZSR/Z4rZ6xHf1C7V7+m8CvKp:MXmkDCkMMyGZWRhHNaIpsK

Entry address:
0xBEA98

Entry point:
60, 9C, 9C, E8, DA, 50, 03, 00, CF, 04, F1, 00, 5F, 4F, 61, 3A, C6, 29, 31, 74, 73, A0, 47, 9C, 5B, 84, 48, DA, 1D, E6, 64, 59, A7, 6B, 8C, 43, AD, 6D, 8A, 65, 18, BD, D1, DC, F1, A5, 34, 2C, 11, A2, 2E, C1, 2F, E3, FA, 6F, 1F, F7, CC, 5D, 34, 12, 3A, 35, A8, 78, 0D, 19, 41, 50, C1, EB, DF, 36, 0F, 34, 7C, 27, 44, 4B, E9, 50, E2, FB, 4E, B7, F3, CA, 9A, E8, B4, 6F, CB, 22, EA, 4A, 9D, 54, 9C, F0, 62, BB, 99, F0, 56, 44, 7F, DA, 9F, F1, E5, 44, 5A, A5, 46, CB, 4D, CE, 88, E1, 59, 4F, AC, 6E, EC, E3, 75, D4...
 
[+]

Code size:
353 KB (361,472 bytes)

The file installer26__7934_il13539.exe has been seen being distributed by the following URL.

Remove installer26__7934_il13539.exe - Powered by Reason Core Security