190.exe

Stepan Rybin

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application 190.exe by Stepan Rybin has been detected as adware by 22 anti-malware scanners. The file has been seen being downloaded from groupsetzipmyjob.org.
Publisher:
Stepan Rybin  (signed and verified)

MD5:
d37bbe40080b14e10acb768cf8b7f050

SHA-1:
4a1702220f04ba49c21e92531e10ce280b1847bc

SHA-256:
186161c1cd708b119acde259c943702766fa34461c541c8746361a20608d45f3

Scanner detections:
22 / 68

Status:
Adware

Analysis date:
4/20/2024 3:05:26 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Mikey.8516
6749949

AhnLab V3 Security
PUP/Win32.MultiPlug
2015.03.09

Avira AntiVirus
PUA/MultiPlug.11245
7.11.214.212

avast!
Win32:MultiPlug-TP [PUP]
150101-1

AVG
Generic_r
2016.0.3177

Bitdefender
Gen:Variant.Adware.Mikey.8516
1.0.20.335

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.AdWare.MultiPlug.VA
21336

Emsisoft Anti-Malware
Gen:Variant.Adware.Mikey.8516
9.0.0.4799

ESET NOD32
Win32/Adware.MultiPlug.FK application
7.0.302.0

F-Prot
W32/MultiPlug.H.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Mikey
5.13.68

G Data
Gen:Variant.Adware.Mikey.8516
15.3.25

K7 AntiVirus
Unwanted-Program
13.200.15196

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

Malwarebytes
PUP.Optional.Unizeto
v2015.03.08.10

McAfee
Program.MultiPlug-FWG
16.8.708.2

MicroWorld eScan
Gen:Variant.Adware.Mikey.8516
16.0.0.201

Reason Heuristics
PUP.WebPick
15.3.8.10

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15306

Sophos
PUA 'MultiPlug' (of type Adware)
5.11

Vba32 AntiVirus
SScope.Adware.MultiPlug
3.12.26.3

File size:
1023.2 KB (1,047,752 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\{85bb42e5-a569-b1a5-85bb-b42e5a560b96}\190.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
6/27/2014 4:37:40 AM

Valid to:
6/27/2015 4:37:40 AM

Subject:
E=rybin.step@yandex.ru, CN=Stepan Rybin, O=Stepan Rybin, C=UA

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
47154C2151E9EB8DFA42C2C9E45BFC6C

File PE Metadata
Compilation timestamp:
4/9/2012 5:59:34 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:lGc1pw+ozcGGMAdDH6HzIuGTrFLIOVCuZb:lz1p5hMmHEUuGTrFEw

Entry address:
0xD8282

Entry point:
E8, DF, 14, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 30, AE, 4E, 00, E8, E8, 19, 00, 00, E8, AC, 16, 00, 00, 0F, B7, F0, 6A, 02, E8, 72, 14, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, E8, 02, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.3834

Code size:
883.5 KB (904,704 bytes)

The file 190.exe has been seen being distributed by the following URL.

Remove 190.exe - Powered by Reason Core Security