22477888_setup.exe

Pazera Free MKV to AVI Converter

Pazera Jacek

The application 22477888_setup.exe, “Pazera Free MKV to AVI Converter Setup ” by Pazera Jacek has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup.
Publisher:
Pazera Jacek   (signed by Pazera Jacek)

Product:
Pazera Free MKV to AVI Converter

Description:
Pazera Free MKV to AVI Converter Setup

MD5:
04d9e82fd6539d8087c7d8d82e5e4675

SHA-1:
0f1ea2b6a396f08bae3ba5d765f71da933b4d1c5

SHA-256:
cc590eea4bd238424ef0ee9b0161145b29cc4380359316807070390baad4dc7f

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/25/2024 10:04:51 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallMonetizer.AF potentially unwanted
9.11306

Reason Heuristics
PUP.InstallMonetizer.Bundle (M)
16.3.10.15

File size:
10.4 MB (10,880,640 bytes)

Product version:
1.2

Copyright:
Copyright © 2013 Jacek Pazera, http://pazera-software.com

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\22477888_setup.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
4/23/2013 8:27:14 AM

Valid to:
4/23/2014 8:27:14 AM

Subject:
E=jacekpazera@wp.pl, CN=Jacek Pazera, O=Pazera Jacek, C=PL

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
5103818FAACDB8E172D504668A9D9521

File PE Metadata
Compilation timestamp:
10/9/2012 11:48:22 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:a2b2zmx4NUHT9cy2GK5FHHN+jAWH4grsQQ/W8G9Pxl5NY2MLqUp+KEv:a2b2zE4N0T9cxGK55N+jPYgrsQQ/IPxn

Entry address:
0xF3BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 64, ED, 40, 00, E8, E8, 71, FF, FF, 33, C0, 55, 68, 89, FA, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 45, FA, 40, 00, 64, FF, 32, 64, 89, 22, A1, 48, 3B, 41, 00, E8, BE, F7, FF, FF, E8, 65, F3, FF, FF, 8D, 55, EC, 33, C0, E8, F7, C3, FF, FF, 8B, 55, EC, B8, 4C, 66, 41, 00, E8, 6A, 58, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 4C, 66, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
59 KB (60,416 bytes)

Remove 22477888_setup.exe - Powered by Reason Core Security