no ads web-freer-setup.exe

No Ads Web-freer

Avijeh,Mehdi.Z

The application no ads web-freer-setup.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The setup program uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme. The file has been seen being downloaded from s6.uplod.ir.
Publisher:
Avijeh,Mehdi.Z

Product:
No Ads Web-freer

Description:
Installer

Version:
2013.9.3.207

MD5:
eff60fce1894e632b829fcb344d0b815

SHA-1:
feb4c12688e8fe689c2c877d0328795db79f0772

SHA-256:
fb05cf73068e96866422b8814498590814fd4739bc5189bbe501eaefc82c6d7b

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
12/26/2024 8:25:34 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstalleRex
7.1.1

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.167.102

avast!
Win32:InstallMate-CJ [PUP]
2014.9-140816

AVG
Adware Agent.E
2015.0.3380

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.1459

Bkav FE
HW32.CDB
1.3.0.4959

Clam AntiVirus
Win.Trojan.8095309
0.98/19283

Comodo Security
Application.Win32.Bundledz.C
19193

Dr.Web
Adware.Downware.97
9.0.1.0228

ESET NOD32
Win32/InstalleRex.C potentially unwanted application
8.7.0.302.0

IKARUS anti.virus
AdWare.Allpremiumsoft
t3scan.1.7.5.0

McAfee
Trojan.Artemis!D222DDE6DA68
5600.7036

NANO AntiVirus
Riskware.Win32.Downware.hulry
0.28.0.56582

Panda Antivirus
PUP/TSUploader
14.08.16.09

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.8.16.21

Rising Antivirus
PE:Trojan.InstallRex!1.9CB0
23.00.65.14507

Sophos
PUA.InstallRex
54

SUPERAntiSpyware
Trojan.Agent/Gen-Installer
10417

Trend Micro House Call
HV_INSTALLEREX_CA08018C.TOMC
7.2.228

VIPRE Antivirus
Threat.4753027
32210

File size:
181 KB (185,344 bytes)

Product version:
1.0.3.504

Copyright:
Copyright © 2013 Avijeh,Mehdi.Z

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\no ads web-freer-setup.exe

File PE Metadata
Compilation timestamp:
11/18/2011 8:37:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:7MH/XHAIvRvZYb5lrZ4oDTumqq/0I+huGte6msjQLaCl/p9VwBJUbnqSqqWpg5d:QnrYb5lt4sTumqm+huGtLmZ+ClnAUvqk

Entry address:
0x1513

Entry point:
55, 8B, EC, 81, EC, 38, 0B, 00, 00, 53, 56, 57, 8D, 85, E0, FE, FF, FF, 50, C7, 85, E0, FE, FF, FF, 14, 01, 00, 00, FF, 15, 74, 30, 40, 00, 85, C0, 74, 11, 33, C0, 83, BD, F0, FE, FF, FF, 01, 0F, 94, C0, A3, 00, 40, 40, 00, 33, F6, 66, 89, B5, C8, F4, FF, FF, 89, 75, F4, 89, 75, FC, FF, 15, 70, 30, 40, 00, A3, 08, 40, 40, 00, FF, 15, 6C, 30, 40, 00, 89, 45, F8, 68, 04, 01, 00, 00, 8D, 85, D8, FC, FF, FF, 50, 56, FF, 15, 68, 30, 40, 00, 85, C0, 75, 22, FF, 15, 64, 30, 40, 00, 50, 68, D0, 33, 40, 00, E8, EA...
 
[+]

Entropy:
7.9012

Developed / compiled with:
Microsoft Visual C++

Code size:
8 KB (8,192 bytes)

The file no ads web-freer-setup.exe has been seen being distributed by the following URL.

Remove no ads web-freer-setup.exe - Powered by Reason Core Security