3d_analyzer-v2.36_installer.exe

Meta Installer LLC

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application 3d_analyzer-v2.36_installer.exe by Meta Installer has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. According to Microsoft Security Essentials, the software bundles and installs the Lolliport adware program (in many cases without a user's knowledge). It usually gets on your PC as an installer for a free game or application. This software bundler installs other potentially unwanted software, including Adware:Win32/Lollipop, at the same time as other software.
Publisher:
Meta Installer LLC  (signed and verified)

MD5:
7d1cb7e357f11ab8d481ba438a15ff62

SHA-1:
27a899ba85eabb074242a9745abbc707769e2deb

SHA-256:
580180b3ad26d592a085aa03ed92cf4bc9d6e98272055014b0c7b36f2e39c2fc

Scanner detections:
6 / 68

Status:
Adware

Explanation:
This software bundler installs other potentially unwanted software, including Adware:Win32/Lollipop during isntallation without a user's consent.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/19/2024 11:37:50 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.441
9.0.1.083

ESET NOD32
Win32/Adware.Lollipop
8.8772

Fortinet FortiGate
W32/Toolbar.BABYLON
3/24/2014

Microsoft Security Essentials
SoftwareBundler:Win32/Lolliport
1.163.1557.0

Reason Heuristics
PUP.MetaInstaller.AA
14.8.7.21

VIPRE Antivirus
Lollipop
21230

File size:
269.3 KB (275,736 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\3d_analyzer-v2.36_installer.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/6/2012 6:17:45 AM

Valid to:
2/16/2013 7:59:09 PM

Subject:
CN=Meta Installer LLC, O=Meta Installer LLC, L=Wilmington, S=DE, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
043DEA1F43D249

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:Fe34Q3dhk1Az5lm/S4hp8R9oSed8BUcVOkc4Wc40yUk:WhZlm/R3y1ed8jVOkcEk

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file 3d_analyzer-v2.36_installer.exe has been seen being distributed by the following URL.

Remove 3d_analyzer-v2.36_installer.exe - Powered by Reason Core Security