5428.exe

Stepan Rybin

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application 5428.exe by Stepan Rybin has been detected as adware by 26 anti-malware scanners. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is also typically executed from the user's temporary directory.
Publisher:
Stepan Rybin  (signed and verified)

MD5:
cab67d26be9d66077dac14aefe1e20f3

SHA-1:
a5937aa37876cd65e96352880a12256747e932a7

SHA-256:
6fad5ad5776b862e2bc90fd5373a6f01b02245ad73d2ac0a34d5e04249ce8b7e

Scanner detections:
26 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/19/2024 11:34:01 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.MPLug.35
5650986

AhnLab V3 Security
PUP/Win32.MultiPlug
2015.04.21

Avira AntiVirus
PUA/MultiPlug.11245
3.6.1.96

avast!
Win32:Agent-AYLT [PUP]
150319-1

AVG
Adware Generic6.YRK
2014.0.4311

Bitdefender
Gen:Variant.Adware.MPLug.35
1.0.20.555

Comodo Security
Application.Win32.MultiPlug.VE
21843

Dr.Web
Trojan.Crossrider1.22656
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.MPLug.35
9.0.0.4799

ESET NOD32
Win32/Adware.MultiPlug.FQ application
7.0.302.0

Fortinet FortiGate
Riskware/MultiPlug
4/21/2015

F-Prot
W32/S-17fad164
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.MPLug
5.13.68

G Data
Gen:Variant.Adware.MPLug.35
15.4.25

IKARUS anti.virus
PUA.Multiplug
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.202.15655

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

Malwarebytes
PUP.Optional.Bundler
v2015.04.21.06

McAfee
Program.MultiPlug-FWS
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.197.2.0

MicroWorld eScan
Gen:Variant.Adware.MPLug.35
16.0.0.333

NANO AntiVirus
Riskware.Win32.MultiPlug.dpgmzz
0.30.20.1219

Reason Heuristics
Threat.WebPick.StepanRybin
15.4.21.1

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15419

Sophos
MultiPlug
4.98

Vba32 AntiVirus
SScope.Adware.MultiPlug
3.12.26.3

File size:
827.7 KB (847,560 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\5428.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
6/27/2014 12:37:40 PM

Valid to:
6/27/2015 12:37:40 PM

Subject:
E=rybin.step@yandex.ru, CN=Stepan Rybin, O=Stepan Rybin, C=UA

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
47154C2151E9EB8DFA42C2C9E45BFC6C

File PE Metadata
Compilation timestamp:
8/9/2013 11:08:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:Zuhg+U+9n4pMxNhAs7YmHZnFIWF3An0PbL:Zuhg+79nmoNh5Y+FuWFwSH

Entry address:
0xB2C8B

Entry point:
E8, 35, 13, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 00, 5E, 4C, 00, E8, 3F, 18, 00, 00, E8, 02, 15, 00, 00, 0F, B7, F0, 6A, 02, E8, C8, 12, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 77, 02, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
735.5 KB (753,152 bytes)

Remove 5428.exe - Powered by Reason Core Security