playnowradio.exe

Play now radio

Pay By Ads LTD

The application playnowradio.exe has been detected as adware by 20 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered by a time event. This file is typically installed with the program Play Now Radio by Montiera Technologies Ltd. which is a potentially unwanted software program.
Publisher:
Pay By Ads LTD

Product:
Play now radio

Version:
1.3.0.0

MD5:
acd935569c736cba21a367640886ceac

SHA-1:
60f113f79513bde957da19388a38a93eb2d795bd

SHA-256:
7742af6a28ee56561c2f34e7789526cd18368655f8b0f8facf1d5eb98beb80d6

Scanner detections:
20 / 68

Status:
Adware

Analysis date:
12/25/2024 7:21:35 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11857310
750

Avira AntiVirus
TR/Rogue.11857310
7.11.194.18

avast!
Win32:PUP-gen [PUP]
2014.9-150116

Baidu Antivirus
PUA.Win32.Montiera
4.0.3.15116

Bitdefender
Trojan.Generic.11857310
1.0.20.80

Dr.Web
Adware.Downware.5737
9.0.1.016

Emsisoft Anti-Malware
Trojan.Generic.11857310
8.15.01.16.01

ESET NOD32
Win32/Toolbar.Montiera (variant)
9.10855

F-Secure
Trojan.Generic.11857310
11.2015-16-01_6

G Data
Trojan.Generic.11857310
15.1.24

Malwarebytes
PUP.Optional.PlayNowRadio.A
v2015.01.16.01

McAfee
RDN/Generic PUP.x!cqg
5600.6884

MicroWorld eScan
Trojan.Generic.11857310
16.0.0.48

NANO AntiVirus
Riskware.Win32.Downware.dgxgde
0.28.6.63850

nProtect
Trojan.Generic.11857310
14.12.10.01

Reason Heuristics
PUP.Task.PayByAds
15.1.16.1

Sophos
PayByAds
4.98

Trend Micro House Call
ADW_MONTIERA
7.2.16

Trend Micro
ADW_MONTIERA
10.465.16

VIPRE Antivirus
Montiera
35598

File size:
372 KB (380,928 bytes)

Product version:
1.3.0.0

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\playnowradio\playnowradio\1.3.3.19\playnowradio.exe

File PE Metadata
Compilation timestamp:
1/22/2014 2:41:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:B+XMUCL/JWmnj5oblOkEkjJpDdiPCaBOXj6mgEURn81tZjV14+H:gcUCL/JWyj2lOkEkjJpDACaeNgEUR8Ln

Entry address:
0x30726

Entry point:
E8, E8, 6E, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 10, 53, 8B, 5D, 08, 56, 85, DB, 74, 11, 83, 7D, 0C, 00, 76, 11, 85, DB, 75, 23, 33, C0, E9, BC, 00, 00, 00, 83, 7D, 0C, 00, 74, EF, E8, 8A, 18, 00, 00, 6A, 16, 5E, 89, 30, E8, 2E, 18, 00, 00, 8B, C6, E9, A0, 00, 00, 00, FF, 75, 0C, 53, E8, A9, D1, FF, FF, 59, 59, 3B, 45, 0C, 72, 05, C6, 03, 00, EB, D5, 57, FF, 75, 10, 8D, 4D, F0, E8, FD, CB, FF, FF, 80, 3B, 00, 8B, FB, 8B, F3, 74, 63, 8A, 0F, 8B, 55, F4, 0F, B6, C1, 03, C2, 8A, 50, 1D, F6...
 
[+]

Code size:
259 KB (265,216 bytes)

Scheduled Task
Task name:
Play Now Radio

Trigger:
Time (Next runs on 26/01/2014 at 14:06)


The file playnowradio.exe has been discovered within the following program.

Play Now Radio  by Montiera Technologies Ltd.
This potentially unwanted ad-supported program will bundled a number of adware applications on install including: Criteo DealPly Revenue hits Matomy Jolly wallet Ac plus 50OnRed Superfish Offersbar Thinkthank
www.playnowradio.com
73% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to sage.parklogic.com  (69.39.236.56:80)

TCP (HTTP):
Connects to ec2-54-72-9-115.eu-west-1.compute.amazonaws.com  (54.72.9.115:80)

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.4.90:80)

TCP (HTTP):
Connects to ny1wv3280.xglobe.net  (204.145.82.20:80)

TCP (HTTP):
Connects to NY1WV3561  (204.145.82.26:80)

TCP (HTTP):
Connects to cds313.par.llnw.net  (87.248.223.223:80)

Remove playnowradio.exe - Powered by Reason Core Security