windows loader v2_10924_i22940687_il345.exe

Runner Utility

BERSHNET LLC

The application windows loader v2_10924_i22940687_il345.exe by BERSHNET has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Dummy, Ltd.  (signed by BERSHNET LLC)

Product:
Runner Utility

Version:
1.0.0.187

MD5:
c2562f67f66eed59943b3ee6027b4846

SHA-1:
dddbb2abfe0ceb7024a2c6cc17a48e4d07d54472

SHA-256:
25a8c7a61811d5e7119d5c272ec95afc3caa7b9beb3f3ae1fd597ae2d7de0f16

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 3:16:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize (M)
17.3.14.23

File size:
1.4 MB (1,497,616 bytes)

Product version:
1.0.0.187

Copyright:
Copyright (C) 2013

Original file name:
runner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\windows+loader+v2_10924_i22940687_il345.exe\windows loader v2_10924_i22940687_il345.exe\windows loader v2_10924_i22940687_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/6/2015 5:30:00 AM

Valid to:
2/7/2016 5:29:59 AM

Subject:
CN=BERSHNET LLC, O=BERSHNET LLC, STREET="st. 600-richya b.66, of.10", L=Vinnitsya, S=Vinnitskaya, PostalCode=21027, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E2D6C6F8DDF832E09DCF766B299AD2A9

File PE Metadata
Compilation timestamp:
6/22/2015 7:13:14 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x3B941A

Entry point:
9C, C7, 04, 24, 6F, 45, 1D, FC, E9, B1, A5, 00, 00, E6, 55, 0E, D6, 91, 87, C6, 1E, 46, D9, A0, A2, 2B, 5A, 29, 3F, 48, 5E, 03, EA, 9D, 8B, E0, F6, 8F, 66, 01, 17, 4E, A7, C8, 6E, 2D, F5, BC, 55, 0E, D6, 83, 6C, 3F, 18, 6D, 63, 36, 48, D0, 89, 21, E8, BF, 98, 96, EB, 9B, FE, A5, F4, F8, AD, 77, F5, AE, 4F, 43, 18, E9, 8B, 61, 39, D2, 13, F4, 63, 47, 3B, 1C, 31, F9, 13, 97, 31, 69, 40, 4D, 67, E5, BE, 2D, DF, 07, E5, 53, 74, 56, BF, CA, 43, FB, 70, 4B, 38, 91, EC, 8A, AD, 5E, 2D, A7, 58, 31, 7A, DC, A1, 79...
 
[+]

Entropy:
7.9936  (probably packed)

Code size:
187.5 KB (192,000 bytes)

Remove windows loader v2_10924_i22940687_il345.exe - Powered by Reason Core Security