video32.exe

IT Proekt Invest, TOV

The application video32.exe by IT Proekt Invest, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
IT Proekt Invest, TOV  (signed and verified)

Version:
2.5.9.5

MD5:
af6b4b7ef1f7a2b21b0d24d9e86e5572

SHA-1:
ddfc6eaf1533342fc09871346c0310e031bfe289

SHA-256:
b811a1aeda6e4ebc6f5603efb93bdd6775e1bcbcdc12745d7eee95aafd1c7662

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 5:41:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.3.10.3

File size:
5.4 MB (5,624,800 bytes)

Product version:
2.5.9.5

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\video32.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/20/2016 1:00:00 AM

Valid to:
3/18/2017 12:59:59 AM

Subject:
CN="IT Proekt Invest, TOV", OU=IT, O="IT Proekt Invest, TOV", STREET="prosp. Vozzyednannya, 9", L=Kiev, S=Kiev, PostalCode=02160, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BFE3D72E3FB3938D9D5EBA447C681BDA

File PE Metadata
Compilation timestamp:
3/7/2011 8:36:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

Entry address:
0x4D2160

Entry point:
55, 8B, EC, 81, EC, 90, 07, 00, 00, 0F, B7, 85, 44, FE, FF, FF, 3D, 17, 47, 00, 00, 7F, 7E, 83, 7D, A8, 00, 73, 5C, 8B, 4D, 9C, 81, E9, 59, 95, 00, 00, 89, 8D, 70, FF, FF, FF, BA, 7E, 24, 00, 00, 66, 89, 95, F0, FE, FF, FF, C6, 85, 17, FF, FF, FF, 5C, 8B, 85, 6C, FF, FF, FF, 2D, E3, 6E, 00, 00, 23, 45, F0, 66, 89, 85, 2C, FE, FF, FF, 8B, 4D, 94, 81, E9, BA, 34, 00, 00, C1, E9, 09, 66, 89, 8D, D0, FE, FF, FF, C7, 85, 6C, FF, FF, FF, 00, 00, 00, 00, 8B, 55, C8, 89, 55, BC, EB, 1A, C7, 45, EC, AF, ED, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
5 MB (5,263,872 bytes)

Remove video32.exe - Powered by Reason Core Security