kj+permanent+activator+2013.exe

Andrey Hmelnikov

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application kj+permanent+activator+2013.exe by Andrey Hmelnikov has been detected as adware by 24 anti-malware scanners. This is a setup program which is used to install the application. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Andrey Hmelnikov  (signed and verified)

MD5:
230f38c45e0061b0055514f3ce9c42cd

SHA-1:
25129b73406ce274a96c03620088e9af8e609d97

SHA-256:
707fdfd0cb24885441697fe148e97f08aba674480eb2ddae7f14a22fae771025

Scanner detections:
24 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
12/28/2024 11:49:43 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Kazy.481287
6135001

Avira AntiVirus
ADWARE/MultiPlug.Gen7
7.11.195.232

avast!
Win32:MultiPlug-LT [PUP]
141214-1

AVG
Adware Generic_r.VD
2014.0.4235

Bitdefender
Gen:Variant.Adware.Kazy.481287
1.0.20.1745

Comodo Security
Application.Win32.Multiplug.CT
20381

Dr.Web
Trojan.Crossrider.36840
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Kazy.481287
9.0.0.4668

ESET NOD32
Win32/AdWare.MultiPlug.CT application
7.0.302.0

Fortinet FortiGate
Adware/MultiPlug
12/15/2014

F-Prot
W32/A-327c3a17
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Kazy.481287
5.13.68

G Data
Gen:Variant.Adware.Kazy.481287
14.12.24

K7 AntiVirus
Unwanted-Program
13.187.14339

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

Malwarebytes
PUP.Optional.MultiPlug
v2014.12.15.11

McAfee
Program.MultiPlug-FRO
16.8.708.2

MicroWorld eScan
Gen:Variant.Adware.Kazy.481287
15.0.0.1047

NANO AntiVirus
Riskware.Win32.MultiPlug.dfjscb
0.28.6.64267

Norman
Gen:Variant.Adware.Kazy.481287
04.12.2014 14:30:06

Reason Heuristics
PUP.AndreyHmelnikov.BB
14.12.15.23

Sophos
PUA 'MultiPlug' (of type Adware)
5.08

Vba32 AntiVirus
SScope.Adware.MultiPlug
3.12.26.3

Zillya! Antivirus
Backdoor.PePatch.Win32.53152
2.0.0.2007

File size:
873.9 KB (894,840 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\kj+permanent+activator+2013.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/23/2014 12:55:04 PM

Valid to:
6/23/2015 12:55:04 PM

Subject:
E=Andrey.Hmelnikov@hotmail.com, CN=Andrey Hmelnikov, O=Andrey Hmelnikov, C=RU

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
727B500ADD12D49F610A094EBFE02E4B

File PE Metadata
Compilation timestamp:
6/7/2013 5:00:26 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:4m8fdKWgmgZUqy9AN9hkVOWBzFKJ38ekaxbe6w:38V3AUqy9WhkVTzakalbw

Entry address:
0x3CB06

Entry point:
E8, 79, 48, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 10, A5, 44, 00, E8, E4, 0F, 00, 00, E8, 46, 4A, 00, 00, 0F, B7, F0, 6A, 02, E8, 0C, 48, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, D6, 08, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.7040  (probably packed)

Code size:
275.5 KB (282,112 bytes)

The file kj+permanent+activator+2013.exe has been seen being distributed by the following 3 URLs.

Remove kj+permanent+activator+2013.exe - Powered by Reason Core Security