183737968_setup.exe

PC-Gizmos LTD

The application 183737968_setup.exe by PC-Gizmos has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This file is typically installed with the program Facebook Emoticons by PC Gizmos LTD. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from download.informer.com and multiple other hosts.
Publisher:
PC Gizmos  (signed by PC-Gizmos LTD)

Product:
PC Gizmos

Version:
1.0.0.1

MD5:
0a014903da051722b8ccd6e2f1703c97

SHA-1:
4198388bc14c57dfbc8f2821aad9f60cf8da441d

SHA-256:
57fc452a6e9a8af1df7771487c7c366e62e7d1929a2cbfb3d59523b33b263d1a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/10/2024 3:19:07 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.PCGizmos.P
14.2.20.23

File size:
2.1 MB (2,160,208 bytes)

Product version:
1.0.0.1

Copyright:
PC Gizmos

Original file name:
PCGizmos.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\183737968_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/6/2013 2:00:00 AM

Valid to:
5/7/2015 1:59:59 AM

Subject:
CN=PC-Gizmos LTD, OU=n/a, O=PC-Gizmos LTD, STREET=1 Azrieli Center, STREET=25 floor, STREET=C/O Banai Azriel Stern Law, L=Tel Aviv, S=Israel, PostalCode=67021, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
143B081CED3418BE6CF0EC063AD9318D

File PE Metadata
Compilation timestamp:
7/18/2013 11:52:42 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:z7KR9+XKXaPWnv1rrg5gxQjlltEurpwFTG1Rhjz4a5vQRTIQTy754YI4kzr:XKR2PWnvBrg5gxQjllrrpwFTkjzf5vQ1

Entry address:
0x13B6E5

Entry point:
E8, 5E, C0, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, 70, 32, 5D, 00, 75, 02, F3, C3, E9, E5, C0, 00, 00, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, 35, 00, 45, 57, 00, 57, FF, 35, 8C, D5, 5D, 00, FF, D6, FF, 35, 88, D5, 5D, 00, 8B, D8, 89, 5D, FC, FF, D6, 8B, F0, 3B, F3, 0F, 82, 81, 00, 00, 00, 8B, FE, 2B, FB, 8D, 47, 04, 83, F8, 04, 72, 75, 53, E8, F0, 9D, 00, 00, 8B, D8, 8D, 47, 04, 59, 3B, D8, 73, 48, B8, 00, 08, 00, 00, 3B, D8, 73, 02, 8B, C3, 03, C3, 3B, C3, 72, 0F, 50, FF, 75, FC, E8, 18, C2, 00, 00, 59, 59, 85...
 
[+]

Code size:
1.4 MB (1,516,544 bytes)

The file 183737968_setup.exe has been discovered within the following programs.

Facebook Emoticons  by PC Gizmos LTD
Publisher's description - “Facebook Emoticons gives you many emoticons, smiley and icons. It is a simple add-on to your Facebook page. It adds a wide variety of emoticons, smileys and icons for you to choose from.”
www.pc-gizmos.com
47% remove it
 
Powered by Should I Remove It?

The file 183737968_setup.exe has been seen being distributed by the following 2 URLs.

Remove 183737968_setup.exe - Powered by Reason Core Security