kmspico 9.2.3 final by teamdaz.exe

Alexey Kurilenko

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application kmspico 9.2.3 final by teamdaz.exe by Alexey Kurilenko has been detected as adware by 17 anti-malware scanners. This is a setup program which is used to install the application. It uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme.
Publisher:
Alexey Kurilenko  (signed and verified)

MD5:
3c3a709990b5866bcb1f9dc7d3d96752

SHA-1:
43cf60b946080ea4cea08311a850303e98555d35

SHA-256:
7bb2f7ac075548f04221ba98d74fe1339b32891dc1c1e49cdd386a3e989d7a94

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
12/25/2024 4:11:41 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.MultiPlug
7.1.1

Avira AntiVirus
Adware/MultiPlug.aob
7.11.166.208

avast!
Win32:InstalleRex-CH [PUP]
2014.9-140814

AVG
Adware Generic5
2015.0.3383

Comodo Security
Application.Win32.GreenApp.RR
19188

Dr.Web
Trojan.Crossrider.28215
9.0.1.0226

ESET NOD32
Win32/AdWare.MultiPlug.BF (variant)
8.10242

IKARUS anti.virus
AdWare.SaveNet
t3scan.1.6.1.0

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
14.0.0.3405

Malwarebytes
PUP.Optional.DownloaderSS
v2014.08.14.03

McAfee
Trojan.Artemis!BB57FC5359EE
5600.7039

NANO AntiVirus
Riskware.Win32.MultiPlug.ddsvpv
0.28.2.61519

Panda Antivirus
PUP/TSUploader
14.08.14.03

Reason Heuristics
PUP.AlexeyKurilenko.CC
14.8.14.1

Sophos
MultiPlug
4.98

VIPRE Antivirus
Threat.4150696
31208

File size:
650.3 KB (665,952 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\kmspico 9.2.3 final by teamdaz.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/17/2014 5:20:17 AM

Valid to:
6/17/2015 5:20:17 AM

Subject:
E=Alexey.kurilenko@hotmail.com, CN=Alexey Kurilenko, O=Alexey Kurilenko, C=RU

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
15D51642691B3EE20985639A8FE865DD

File PE Metadata
Compilation timestamp:
8/6/2014 8:01:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:CZVunYav79cKnZxCAgX2QRkOSllkpGF57Lsth6RpoX/wR4u2y:wsp9cWZVnQecI7Q+pOEEy

Entry address:
0xC461

Entry point:
E8, 3E, 3C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 10, 9F, 41, 00, E8, 19, 16, 00, 00, E8, 0B, 3E, 00, 00, 0F, B7, F0, 6A, 02, E8, D1, 3B, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, C4, 2C, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.8681  (probably packed)

Code size:
82.5 KB (84,480 bytes)

The file kmspico 9.2.3 final by teamdaz.exe has been seen being distributed by the following URL.

Remove kmspico 9.2.3 final by teamdaz.exe - Powered by Reason Core Security