installercnf__7934_il106790.exe

The application installercnf__7934_il106790.exe has been detected as a potentially unwanted program by 17 anti-malware scanners. This is a setup program which is used to install the application. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from www.v4download.com.
Version:
1.1.5.90

MD5:
dfe44614692078f65e7f899ec62aba73

SHA-1:
2609f052de49dcba2942a5544474232ab0ee18a6

SHA-256:
41adce2a14b1b7e55f048c680a6420667eba4d4d9059f8093b7cc6a403351909

Scanner detections:
17 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 6:12:21 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.82
720

AhnLab V3 Security
PUP/Win32.Amonetiz
2015.02.15

Avira AntiVirus
ADWARE/Adware.Gen2
7.11.210.58

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.15214

Bitdefender
Gen:Variant.Barys.82
1.0.20.225

Bkav FE
HW32.Packed
1.3.0.6379

Emsisoft Anti-Malware
Gen:Variant.Barys.82
8.15.02.14.08

F-Secure
Gen:Variant.Barys.82
11.2015-14-02_7

G Data
Gen:Variant.Barys.82
15.2.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.6.0

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
14.0.0.2486

McAfee
Artemis!DFE446146920
5600.6854

MicroWorld eScan
Gen:Variant.Barys.82
16.0.0.135

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
2.15.14.00

Sophos
Generic PUA CG
4.98

Trend Micro House Call
TROJ_GEN.R047H09BE15
7.2.45

File size:
649.6 KB (665,160 bytes)

Product version:
1.1.5.90

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\installercnf__7934_il106790.exe

File PE Metadata
Compilation timestamp:
2/13/2015 5:03:21 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:ztmvlfH0t6pZObROrz0fKHMy0oVMwRjTvgK3VI34/t1C7V7+m8j:h8fQSYNkzcKsJqfV//3aIpj

Entry address:
0xCFAE9

Entry point:
60, E9, 7F, 35, 00, 00, B4, 8A, 3A, CE, DD, CE, 97, 8F, 2B, 47, 5F, 74, 44, 80, 53, 70, 75, 9C, 05, 3B, 87, AD, 26, F7, EB, 12, CB, FD, AC, E6, E3, 17, 38, 7C, 94, 59, 87, 28, 5A, 17, 44, DC, 9E, BB, 1D, 31, D1, 11, F1, F3, B7, 6F, EA, A8, E3, EB, 22, AE, 75, 97, 16, 3B, B7, F8, A3, 59, FA, 73, CA, 9D, 72, 69, EF, ED, 9D, 39, EF, 4F, 2A, 1D, 66, 4F, 5C, E5, 22, 33, 22, DA, CD, 06, 52, D7, 9D, 85, A2, E6, 9B, B9, 7F, 70, 7E, 83, 0B, 3B, 90, 2A, BE, DE, CC, B4, AD, 38, 53, 28, 36, 38, 27, 2C, 38, D4, 0D, B3...
 
[+]

Entropy:
7.8672

Packer / compiler:
ASProtect v1.1, 0xBRS

Code size:
410.5 KB (420,352 bytes)

The file installercnf__7934_il106790.exe has been seen being distributed by the following URL.

Remove installercnf__7934_il106790.exe - Powered by Reason Core Security