3_avast_launcher.exe

Mega Boost

SPRT

The application 3_avast_launcher.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from www.fishmish.space.
Publisher:
SPRT

Product:
Mega Boost

Description:
tiny install

Version:
65.232.203.198

MD5:
baa1f2b403e22616adca6d11f4d2e460

SHA-1:
0dd535c0593be32ad298fa7e64f2c2f4cbcbf459

SHA-256:
1fa000d2ae8076fcdd5378e0c2598a49beee683799d1122e08ed281669a30eac

Scanner detections:
18 / 68

Status:
Potentially unwanted

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage).

Analysis date:
4/30/2024 7:31:41 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Application.Imonetize.2
280

Avira AntiVirus
ADWARE/Adware.Gen4
8.3.3.4

Arcabit
Application.Imonetize.2
1.0.0.672

avast!
Win32:Malware-gen
2014.9-160429

Baidu Antivirus
Win32.Trojan.WisdomEyes.151026.9950
4.0.3.16429

Bitdefender
Gen:Application.Imonetize.2
1.0.20.600

ESET NOD32
Win32/Amonetize.RG potentially unwanted (variant)
10.13385

Fortinet FortiGate
Riskware/Amonetize
4/29/2016

F-Secure
Gen:Application.Imonetize.2
11.2016-29-04_6

G Data
Gen:Application.Imonetize
16.4.25

IKARUS anti.virus
PUA.Toolbar.CrossRider
t3scan.2.0.9.0

Kaspersky
not-a-virus:Downloader.Win32.AdLoad
14.0.0.286

Malwarebytes
PUP.Optional.Amonetize
v2016.04.29.07

MicroWorld eScan
Gen:Application.Imonetize.2
17.0.0.360

Qihoo 360 Security
QVM10.1.Malware.Gen
1.0.0.1120

Reason Heuristics
Adware.Amonetize.ET (M)
16.4.29.19

Sophos
Generic PUA AN (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
48892

File size:
690.5 KB (707,072 bytes)

Product version:
65.232.203.198

Copyright:
Copyright 2015

Trademarks:
Kocl

Original file name:
sstup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
4/21/2016 9:23:49 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:c7/kWeazcp0xtjmHqx4x1QEZv+RZ9vyIsJKJPaWHFded+1RlC7V7Vmnat:c7Bcp0xtyK6jlv+R/vyIAWJHx1Dav0at

Entry address:
0xAD92

Entry point:
E8, A6, 36, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, B4, B6, 41, 00, FF, 15, 5C, 20, 41, 00, 85, C0, 75, 18, 56, E8, 2A, 0A, 00, 00, 8B, F0, FF, 15, 58, 20, 41, 00, 50, E8, 2F, 0A, 00, 00, 59, 89, 06, 5E, 5D, C3, 6A, 03, E8, F3, 35, 00, 00, 59, 83, F8, 01, 74, 15, 6A, 03...
 
[+]

Code size:
66.5 KB (68,096 bytes)

The file 3_avast_launcher.exe has been seen being distributed by the following URL.

Remove 3_avast_launcher.exe - Powered by Reason Core Security