..exe

AVSoftware EOOD

The software installer uses the StartInstall.com download manager which bundles additional adware offers (toolbars and utilities such as the SafeSearch toolbar) during setup. The application ..exe by AVSoftware EOOD has been detected as adware by 2 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dsu7x9k8c43un.cloudfront.net.
Publisher:
AVSoftware EOOD  (signed and verified)

MD5:
65f4f9faede49d15f749fbf88668e88c

SHA-1:
273d9cad0c65c57ac9d10c8cd40370f4b92d4fd9

SHA-256:
40b439464a0e949f299aa8d03df60f35b0b50a3f1f0b4471b6edfe03ae755252

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/23/2024 9:48:06 PM UTC  (today)

Scan engine
Detection
Engine version

Malwarebytes
PUP.Optional.SoftM8.A
v2015.09.23.09

Reason Heuristics
PUP.AVSoftware EOOD.AVSoftwareEOOD (M)
15.9.23.21

File size:
960 KB (983,048 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\..exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/4/2013 7:00:00 PM

Valid to:
6/3/2016 7:59:59 PM

Subject:
CN=AVSoftware EOOD, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AVSoftware EOOD, L=Sofia, S=Sofia, C=BG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0EB840FECC84AE6DCA7A92109E2314ED

File PE Metadata
Compilation timestamp:
9/8/2014 4:27:03 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:K2V9uSWpPUQOiydvby0yzz3k12grzM+lylqqdEyB2uH+6qSegf/8siQxf9:K6ufPUQNGqngv2Yqjsp6qSeg5is

Entry address:
0x3004D0

Entry point:
60, BE, 00, 70, 61, 00, 8D, BE, 00, A0, DE, FF, C7, 87, 18, CA, 26, 00, 07, 10, C2, 4A, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.9209

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
936 KB (958,464 bytes)

The file ..exe has been seen being distributed by the following URL.

Remove ..exe - Powered by Reason Core Security