pack-codecs-1.7.exe

The application pack-codecs-1.7.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. BetterSurf is a program that comes with software bundlers that offer free applications and will add a plugin to Internet Explorer, Firefox, and Chrome which displays advertisements on websites and search engines. In addition it will redirct various web browsing to various malvertisng sites. The file has been seen being downloaded from subpelis.info.
MD5:
0841cc75029bf25c16c19a0c9cc782a2

SHA-1:
d9f0ab2451ca2d8d36d6bbab45d7672985f8b0cf

SHA-256:
80f732ee4a7c0f60d3cc3bcd624ddf71bd8da13353e9bdda9722a79ab351c7bc

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Installed with software bundlers that offer free applications or games and adds a plugin to Internet Explorer, Firefox, and Chrome and will display ads as the user browses the Internet, both in websites and on search engine results

Analysis date:
11/27/2024 1:41:39 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
SFX:Agent-L
2014.9-141023

Dr.Web
DLOADER.Trojan
9.0.1.0296

Emsisoft Anti-Malware
Adware.BetterSurf
8.14.10.23.08

F-Prot
W32/Downloader-Web-based!Maximu
v6.4.7.1.166

G Data
Win32.Trojan.Agent.7VPEH9
14.10.24

IKARUS anti.virus
Trojan.Win32.Agent
t3scan.2.2.29

McAfee
Artemis!0841CC75029B
5600.6968

Norman
Suspicious_Gen4.ETBAC
11.20141023

File size:
753.5 KB (771,540 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pack-codecs-1.7.exe

File PE Metadata
Compilation timestamp:
3/15/2010 1:57:50 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:Autrzh9xOXkpBA1QlA3FFVcOv9go2/0WMnA+0W/+sWV7J0aQwhFN5S1LRNEtR:Autr5OUpBATF7vl4IAJo+p6azFNQ1NNU

Entry address:
0xA7B1

Entry point:
E8, E3, FE, FF, FF, 33, C0, 50, 50, 50, 50, E8, BE, 2B, 00, 00, C3, 56, 57, 8B, 7C, 24, 0C, 8B, F1, 8B, CF, 89, 3E, E8, D0, A7, FF, FF, 89, 46, 08, 89, 56, 0C, 8B, 87, 1C, 0C, 00, 00, 89, 46, 10, 5F, 8B, C6, 5E, C2, 04, 00, 8B, C1, 8B, 08, 8B, 50, 10, 3B, 91, 1C, 0C, 00, 00, 75, 0D, 6A, 00, FF, 70, 0C, FF, 70, 08, E8, AF, AC, FF, FF, C3, 55, 8B, EC, 83, EC, 1C, 56, 33, F6, 56, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 40, 22, 41, 00, 85, C0, 74, 21, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 44, 22, 41, 00, 8D, 45, E4...
 
[+]

Code size:
66 KB (67,584 bytes)

The file pack-codecs-1.7.exe has been seen being distributed by the following URL.

Remove pack-codecs-1.7.exe - Powered by Reason Core Security