psupport_install.exe

The application psupport_install.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. Also know as BrowserDefender, this bundled service will prevent various web browser toolbars and extensions from running as well as block changes to the search page and provider. The file has been seen being downloaded from i1.stylefun.info.
MD5:
dbe272e42b3090d40068472b82f8a44f

SHA-1:
482bb2316877f1f54ea83e013ab2caef60964d03

SHA-256:
f1d135e7aafc660c98e4be533670e0bd17f096dca837ed333fcbeba83b273a8f

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
This service will prevent resources from modifying the web browser's home and search pages as well as the search provider set by the product, an affiliate search engine partner.

Analysis date:
11/5/2024 11:33:32 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Evo-gen [Susp]
160216-0

AVG
Adware Generic5.APZM
2015.0.4530

Dr.Web
Adware.BGuard.42
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.BHO.Bprotector
11.5.0.6191

ESET NOD32
Win32/SProtector.B potentially unwanted application
7.0.302.0

F-Prot
W32/Virut.AI!Generic
4.6.5.141

F-Secure
Variant.Adware.BHO
5.15.21

McAfee
Program.Generic PUP.a
18.0.204.0

Norman
Gen:Variant.Adware.BHO.Bprotector.1
29.02.2016 03:11:57

File size:
1.4 MB (1,504,931 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\psupport_install.exe

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:tuSvGbcyy0Yx56l0h/vfwxeudJuActqyHryfigj2rw9OrEvGbcyy0Yx56l0h/vfL:Ybct0Yxkl0h/vfwxeU4AmbqvyU9O5bcV

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9917

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file psupport_install.exe has been seen being distributed by the following URL.

Remove psupport_install.exe - Powered by Reason Core Security