shoppinhelper_setup.exe

Linkury

This is part of the Linkury monetization software, a web browser toolbar used to 'hijack' a user's search in order to collect revenues. The application shoppinhelper_setup.exe by Linkury has been detected as adware by 9 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from cdn.download2desktop.com.
Publisher:
Linkury  (signed and verified)

MD5:
4a9ff3754565869a13e1cdc9e49a2907

SHA-1:
8cc0548d90fcc8f023e4c7f4a6befdc79c6fd6eb

SHA-256:
37aec014b514ac1c359cc9aa31712e0da34c555b5eb07f0640834ed1280c9eb4

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
11/26/2024 9:48:19 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SmartBar-A [PUP]
2014.9-140728

AVG
AdInject.Resoft.dropper
2015.0.3590

Dr.Web
Adware.Downware.1560
9.0.1.0209

ESET NOD32
Win32/Toolbar.Linkury (variant)
8.9731

Malwarebytes
PUP.Optional.Linkury.A
v2014.01.18.03

McAfee
Artemis!DE89D8867F1E
5600.7055

Reason Heuristics
PUP.Installer.Linkury.T
14.8.7.19

Trend Micro House Call
TROJ_GEN.F47V0108
7.2.18

VIPRE Antivirus
Adware.Linkury
28650

File size:
7.8 MB (8,148,760 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\shoppinhelper_setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/12/2012 8:00:00 AM

Valid to:
5/12/2015 7:59:59 AM

Subject:
CN=Linkury, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Linkury, L=Ramat Gan, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
77A9B89A06B99100955A838E8BB46FF8

File PE Metadata
Compilation timestamp:
12/22/2013 9:16:24 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:qTj+thVvHKtJC8Si9lNp4Lq4Y3OqOD+obYlAevHzZvQoZYgb4m/xAxPdm3+Py3Cf:qYkpSsNGY+SofaVvQ+5Vog3BaDD

Entry address:
0x27B3A

Entry point:
E8, CE, A2, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8D, 45, 14, 50, 6A, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, B2, B0, 00, 00, 83, C4, 14, 5D, C3, E8, D0, 5E, 00, 00, 8B, 48, 6C, 3B, 0D, D8, 08, 45, 00, 74, 10, 8B, 0D, 8C, 06, 45, 00, 85, 48, 70, 75, 05, E8, 8C, 5C, 00, 00, A1, C8, 04, 45, 00, C3, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 0C, 53, 85, C0, 74, 52, 8B, 54, 24, 08, 33, DB, 8A, 5C, 24, 0C, F7, C2, 03, 00, 00, 00, 74, 16, 8A, 0A, 83, C2, 01, 32, CB, 74, 72, 83, E8, 01, 74, 32, F7...
 
[+]

Entropy:
7.8665  (probably packed)

Code size:
252 KB (258,048 bytes)

The file shoppinhelper_setup.exe has been seen being distributed by the following URL.

Remove shoppinhelper_setup.exe - Powered by Reason Core Security