294823_.exe

Sergei Ivanovich Drozdov

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application 294823_.exe by Sergei Ivanovich Drozdov has been detected as adware by 20 anti-malware scanners. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is also typically executed from the user's temporary directory.
Publisher:
Sergei Ivanovich Drozdov  (signed and verified)

MD5:
e77c3a57a37d11ca6a4f909a6d323760

SHA-1:
9e7a223017aba477aaed0f72af3d2be8ff268882

SHA-256:
5d8e8fb2203ba30598bc1fd183851ab3c371d930e17af50ec97247cd530c76eb

Scanner detections:
20 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/24/2024 6:12:33 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Dropper.101
1023

Avira AntiVirus
ADWARE/Adware.Gen7
7.11.144.50

avast!
Win32:MultiPlug-AJ [PUP]
2014.9-140418

AVG
Generic_r
2015.0.3501

Bitdefender
Gen:Variant.Adware.Dropper.101
1.0.20.540

Comodo Security
Application.Win32.MegaSearch.ATH
18125

Dr.Web
Trojan.Crossrider.11249
9.0.1.0108

Emsisoft Anti-Malware
Gen:Variant.Adware.Dropper.101
8.14.04.18.08

ESET NOD32
Win32/AdWare.MultiPlug (variant)
8.9694

F-Secure
Gen:Variant.Adware.Dropper.101
11.2014-18-04_6

G Data
Gen:Variant.Adware.Dropper.101
14.4.24

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
14.0.0.3998

Malwarebytes
PUP.Optional.MultiPlug.A
v2014.04.18.08

McAfee
PUP-FID!E77C3A57A37D
5600.7157

MicroWorld eScan
Gen:Variant.Adware.Dropper.101
15.0.0.324

Panda Antivirus
Trj/Genetic.gen
14.04.18.08

Reason Heuristics
PUP.SergeiIvanovichDrozdov.H
14.4.18.6

Rising Antivirus
PE:Malware.MultiPlug!6.13CF
23.00.65.14416

Sophos
MultiPlug
4.98

VIPRE Antivirus
Trojan.Win32.Generic
28350

File size:
1.4 MB (1,429,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\294823_.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
1/8/2014 12:24:34 AM

Valid to:
1/8/2015 12:24:34 AM

Subject:
E=drozdov54@hotmail.com, CN="Open Source Developer, Sergei Ivanovich Drozdov", OU=Sedro Soft, O=Sergei Ivanovich Drozdov, C=RU

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
4E05AFB21C1318DB8A2C0669760C9050

File PE Metadata
Compilation timestamp:
4/9/2014 11:36:43 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:snYUZBLaNQzE0BlWkeb61Ukdyjut785E8Ek5Prsmf1ClofuvCb4MDWNHFy8J+WUp:oZcQzE0mbzc66785E8Hzjffua0ysb4W4

Entry address:
0x10C6B

Entry point:
E8, BE, 4A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 98, 21, 42, 00, E8, 9F, 21, 00, 00, E8, E0, 07, 00, 00, 0F, B7, F0, 6A, 02, E8, 51, 4A, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 10, 38, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.9064  (probably packed)

Code size:
103.5 KB (105,984 bytes)

Remove 294823_.exe - Powered by Reason Core Security