12_avira_launcher.exe

Mega Boost

Star Grate

The application 12_avira_launcher.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.panningmanybanded.site.
Publisher:
Star Grate

Product:
Mega Boost

Description:
smart install

Version:
227.237.116.205

MD5:
996af42671901f8e01fff85ae4daf7a1

SHA-1:
8b32936f56d37e9e8ddb1eb213fe072a862b0947

SHA-256:
91fc0c556d58e20a819a8b2358ae0acbd75a2adce71efc22a32e99fa339e7358

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
5/13/2025 2:10:33 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Amonetize.NL potentially unwanted application
7.0.302.0

F-Secure
Trojan.Heur2.RP.cv0@a0Mobfji
5.15.96

Norman
Gen:Trojan.Heur2.RP.cv0@a0Mobfji
02.04.2016 17:35:19

Reason Heuristics
Adware.InstallMonetizer.StarGrat.Installer.Meta (M)
16.5.7.15

File size:
1 MB (1,086,976 bytes)

Product version:
227.237.116.205

Copyright:
Rights 2000

Trademarks:
SW Good M

Original file name:
file.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\12_avira_launcher.exe

File PE Metadata
Compilation timestamp:
5/7/2016 10:17:49 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:rdVWk2w7yRXfx9X+ZjOFMqR5aJjbGf1zI:RV/TOxfx9WOFJRsRbGtz

Entry address:
0x833A

Entry point:
E8, 56, 27, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 68, 1D, 41, 00, 89, 0D, 64, 1D, 41, 00, 89, 15, 60, 1D, 41, 00, 89, 1D, 5C, 1D, 41, 00, 89, 35, 58, 1D, 41, 00, 89, 3D, 54, 1D, 41, 00, 66, 8C, 15, 80, 1D, 41, 00, 66, 8C, 0D, 74, 1D, 41, 00, 66, 8C, 1D...
 
[+]

Code size:
50 KB (51,200 bytes)

The file 12_avira_launcher.exe has been seen being distributed by the following URL.

Remove 12_avira_launcher.exe - Powered by Reason Core Security