ms4432.tmp.exe

proZplus4.2.0.4339

4.2.0.4339ZoomWebLists

The application ms4432.tmp.exe has been detected as a potentially unwanted program by 17 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from pitchalign.com.
Publisher:
4.2.0.4339ZoomWebLists

Product:
proZplus4.2.0.4339

Version:
4.2.0.4339

MD5:
e1130c16416a227a41d7dc3cc374014e

SHA-1:
692257260ad188fc87d651e5172a544415d0381f

SHA-256:
727db73149fc7bb2536a2941fd3cbd1461c3f7d41a99f21a1babdffb45858917

Scanner detections:
17 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/27/2024 10:49:27 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Mikey.23752
5718393

Agnitum Outpost
PUA.Similagro
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.09.29

Arcabit
Trojan.Mikey.D5CC8
1.0.0.567

AVG
Generic6
2016.0.2972

Bitdefender
Gen:Variant.Mikey.23752
1.0.20.1355

Comodo Security
Application.Win32.AdWare.Similagro.EA
23319

Emsisoft Anti-Malware
Gen:Variant.Mikey.23752
10.0.0.5366

ESET NOD32
multiple threats
7.0.302.0

F-Secure
Gen:Variant.Mikey.23752
11.2015-28-09_2

G Data
Gen:Variant.Mikey.23752
15.9.25

IKARUS anti.virus
PUA.Similagro
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.210.17358

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1355

MicroWorld eScan
Gen:Variant.Mikey.23752
16.0.0.813

Norman
Gen:Variant.Mikey.23752
03.12.2014 13:20:04

Rising Antivirus
PE:PUF.Similagro!1.A0AE[F1]
23.00.65.15926

File size:
161.9 KB (165,806 bytes)

Product version:
4.2.0.4339

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\ms4432.tmp.exe

File PE Metadata
Compilation timestamp:
10/7/2014 6:40:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:KM1BjoYNXoKDIJBXJPVdj8uZwBSdvS2BXhBVjkzKpnlzI488147DzPWs/CfyYOEx:KMMYNXqBBVdj8iwMdvNBXhBOuMDz/6K0

Entry address:
0x30B6

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, 98, 37, 42, 00, E8, A8, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 98, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 52, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 40, 2A...
 
[+]

Entropy:
7.8540

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file ms4432.tmp.exe has been seen being distributed by the following URL.

Remove ms4432.tmp.exe - Powered by Reason Core Security