posisoft desktop manager.exe

dotNetInstaller

Kaydar LLC

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application posisoft desktop manager.exe by Kaydar has been detected as adware by 4 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme.
Publisher:
DeFelsko Corp.  (signed by Kaydar LLC)

Product:
dotNetInstaller

Version:
1.0.0.0

MD5:
749ce501956e5e936ab9fcfb50d6dd30

SHA-1:
bbb3034f70badc39eecb1ff32692bb0c61b6e583

SHA-256:
e40435105e6d5f5debcae49646b9f5ec143af7aecb3b38ec908143f78c322862

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
11/24/2024 5:38:20 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.MultiPlug
4.0.3.15719

Dr.Web
Trojan.Crossrider1.36887
9.0.1.0200

Microsoft Security Essentials
SoftwareBundler:Win32/InstalleRex
1.1.11804.0

Reason Heuristics
PUP.WebPick.Kaydar.Installer (M)
15.7.19.1

File size:
4.5 MB (4,692,920 bytes)

Product version:
1.0.0.0

Trademarks:
All Rights Reserved

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\posisoft desktop manager.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/23/2014 6:07:10 PM

Valid to:
9/24/2015 6:07:10 PM

Subject:
E=kaydarmail@gmail.com, CN=Kaydar LLC, O=Kaydar LLC, L=Dnipropetrovsk, C=UA

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B6A21E20070BBBE8F29381995228CCD8

File PE Metadata
Compilation timestamp:
5/28/2012 11:02:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:0Lix3gCqzwChR0sB1t8YM7cOSsX70ZMXI9rV8RHcBi45Gp:0WJg0y1qcOSsX70mXgrnxGp

Entry address:
0x8D263

Entry point:
E8, 9F, CC, 00, 00, E9, 17, FE, FF, FF, 55, 8B, EC, 53, 56, 8B, 75, 08, 57, 33, FF, 39, 7D, 14, 75, 10, 3B, F7, 75, 10, 39, 7D, 0C, 75, 12, 33, C0, 5F, 5E, 5B, 5D, C3, 3B, F7, 74, 07, 8B, 5D, 0C, 3B, DF, 77, 1B, E8, 0E, 39, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, FE, 11, 00, 00, 83, C4, 14, 8B, C6, EB, D5, 39, 7D, 14, 75, 05, 66, 89, 3E, EB, C9, 8B, 55, 10, 3B, D7, 75, 05, 66, 89, 3E, EB, CF, 83, 7D, 14, FF, 8B, C6, 75, 14, 0F, B7, 0A, 66, 89, 08, 40, 40, 42, 42, 66, 3B, CF, 74, 24, 4B, 75, EE...
 
[+]

Entropy:
7.8126  (probably packed)

Code size:
832 KB (851,968 bytes)

The file posisoft desktop manager.exe has been seen being distributed by the following URL.

Remove posisoft desktop manager.exe - Powered by Reason Core Security