sims 3.exe

The application sims 3.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from getfile.eu.
Version:
1.0.0.0

MD5:
b52b3216fa5046e9275c473dbc73f888

SHA-1:
1e88ddf4ebcdec67e4a21b3f8fd8152d025144df

SHA-256:
c76694b5da3c76877696376df8e791d692e35f9a776ca095fd51b0579ff41508

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 5:08:43 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Banker-KIF [Trj]
160215-2

AVG
Adware BundleApp.LY
2015.0.4530

ESET NOD32
Win32/InstallMonstr.A potentially unwanted application
8.0.319.0

F-Secure
Variant.Strictor.42896
5.15.21

Norman
Gen:Variant.Strictor.42896
29.02.2016 03:11:57

Reason Heuristics
Adware.Bundler (M)
16.3.5.22

File size:
3.9 MB (4,104,393 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\sims 3.exe

File PE Metadata
Compilation timestamp:
6/30/2013 7:53:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:9RQIxn8uJb/25N9xqFbSabYg8XOZHx0W5FG67TnMUczy3y/gWYw0S:9R9Ne5f+8XA0W5FGkLcZ/gWOS

Entry address:
0x320128

Entry point:
55, 8B, EC, 83, C4, F0, B8, F0, 1A, 71, 00, E8, E0, FA, CE, FF, A1, E0, D0, 72, 00, 8B, 00, E8, 00, 47, EB, FF, A1, E0, D0, 72, 00, 8B, 00, B2, 01, E8, 12, 64, EB, FF, 8B, 0D, 6C, CA, 72, 00, A1, E0, D0, 72, 00, 8B, 00, 8B, 15, E8, 19, 70, 00, E8, F2, 46, EB, FF, A1, E0, D0, 72, 00, 8B, 00, E8, 4A, 48, EB, FF, E8, 81, A2, CE, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.1 MB (3,270,144 bytes)

The file sims 3.exe has been seen being distributed by the following URL.

Remove sims 3.exe - Powered by Reason Core Security