2_avast_launcher.exe

Stpll

Old Tramolt

The application 2_avast_launcher.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup program which is used to install the application. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from www.panningmanybanded.site.
Publisher:
Old Tramolt

Product:
Stpll

Description:
cmpnnt

Version:
159.145.74.27

MD5:
82bf126b3039e60b6f3ce132bc093ad6

SHA-1:
3dbe3fd2938c5e0db22167b8402eeda753765aef

SHA-256:
0abe5faf22b812698817cb97ea49a9785a68782abc2d89f9f49a9efa717ea436

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
5/12/2025 2:24:32 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Gen:Variant.Application.Razy.12281
11.5.0.6191

F-Secure
Variant.Application.Razy
5.15.96

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize
15.0.0.562

Norman
Gen:Variant.Application.Razy.12281
10.04.2016 15:29:17

File size:
1.2 MB (1,222,656 bytes)

Product version:
159.145.74.27

Copyright:
LC 2015

Trademarks:
SW Good M

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
5/7/2016 8:47:14 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:9yOo/vjvYT/2M5VrlGJdRHQW0TTrSTBJ+1/fYu:9M/LQ1IlQWw+J+ZY

Entry address:
0x5140

Entry point:
E8, EF, 37, 00, 00, E9, 89, FE, FF, FF, 6A, 00, FF, 15, 0C, B0, 40, 00, C3, FF, 15, 20, B0, 40, 00, C2, 04, 00, 8B, FF, 56, FF, 35, 38, F3, 40, 00, FF, 15, 24, B0, 40, 00, 8B, F0, 85, F6, 75, 1B, FF, 35, 44, FF, 40, 00, FF, 15, 10, B0, 40, 00, 8B, F0, 56, FF, 35, 38, F3, 40, 00, FF, 15, 28, B0, 40, 00, 8B, C6, 5E, C3, A1, 34, F3, 40, 00, 83, F8, FF, 74, 16, 50, FF, 35, 4C, FF, 40, 00, FF, 15, 10, B0, 40, 00, FF, D0, 83, 0D, 34, F3, 40, 00, FF, A1, 38, F3, 40, 00, 83, F8, FF, 74, 0E, 50, FF, 15, 2C, B0, 40...
 
[+]

Code size:
38.5 KB (39,424 bytes)

The file 2_avast_launcher.exe has been seen being distributed by the following URL.

Remove 2_avast_launcher.exe - Powered by Reason Core Security