noow-0.99b.exe

FAST MONSTER LTD

The application noow-0.99b.exe by FAST MONSTER has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider.
Publisher:
FAST MONSTER LTD  (signed and verified)

MD5:
91ccf0dca2664511c6af9d7af042a2ac

SHA-1:
3e632e6f062903ebf1061c81deaf361b302c2627

SHA-256:
c165076f54bdd2c3725da1e0baf9cf30409e2890bc32e4fda293ca7ebdb5c81d

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
11/23/2024 3:09:59 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
Win32/Toolbar.Babylon potentially unwanted application
7.0.302.0

VIPRE Antivirus
Zugo
11020

File size:
1.1 MB (1,120,392 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\noow-0.99b.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/9/2011 4:00:00 AM

Valid to:
9/9/2012 3:59:59 AM

Subject:
CN=FAST MONSTER LTD, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=FAST MONSTER LTD, L=Limassol, S=Limassol, C=CY

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6C4273961BD9EA3C36FD994C2233040C

File PE Metadata
Compilation timestamp:
12/6/2009 2:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:5Dn5d1Y7mzqu1p80OA6VmmnZQS13Omkocp4:5zlzzqQ8q6jZQBmkdq

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9898

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Remove noow-0.99b.exe - Powered by Reason Core Security