69a0.exe

Stepan Rybin

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application 69a0.exe by Stepan Rybin has been detected as adware by 26 anti-malware scanners. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is also typically executed from the user's temporary directory.
Publisher:
Stepan Rybin  (signed and verified)

MD5:
f08994469b2ea1f50063d324119026ad

SHA-1:
38e85142cc0a7d178d7eb1eddfae45cd80879ff1

SHA-256:
0f6af57e76a1c1ad667883aab63e3a4423e07e12a6827442aff2ce0bbaf10bd4

Scanner detections:
26 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/25/2024 8:02:06 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.MPlug.33
667

AhnLab V3 Security
PUP/Win32.MultiPlug
2015.04.01

Avira AntiVirus
PUA/MultiPlug.11245
3.6.1.96

avast!
Win32:Adware-gen [Adw]
150319-1

AVG
Generic6
2016.0.3153

Bitdefender
Gen:Variant.Adware.MPlug.33
1.0.20.495

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.MultiPlug.YTRA
21611

Dr.Web
Trojan.Crossrider1.22656
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.MPlug.33
8.15.04.09.03

ESET NOD32
Win32/Adware.MultiPlug.GX (variant)
9.11409

Fortinet FortiGate
Riskware/MultiPlug
4/1/2015

F-Prot
W32/S-eef9a8e7
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.MPlug
11.2015-09-04_5

G Data
Win32.Adware.Multiplug.AL
15.4.25

K7 AntiVirus
Unwanted-Program
13.202.15449

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

Malwarebytes
PUP.Optional.MultiPlug
v2015.04.09.03

McAfee
Multiplug-FXE
5600.6809

MicroWorld eScan
Gen:Variant.Adware.MPlug.33
16.0.0.297

NANO AntiVirus
Riskware.Win32.MultiPlug.dqdzdr
0.30.10.952

Panda Antivirus
Generic Suspicious
15.04.09.03

Reason Heuristics
PUP.WebPick
15.4.1.8

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15330

Sophos
MultiPlug
4.98

Vba32 AntiVirus
suspected of Heur.Malware-Cryptor.Multiplug
3.12.26.3

File size:
452.7 KB (463,560 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\69a0.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
6/27/2014 11:37:40 AM

Valid to:
6/27/2015 11:37:40 AM

Subject:
E=rybin.step@yandex.ru, CN=Stepan Rybin, O=Stepan Rybin, C=UA

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
47154C2151E9EB8DFA42C2C9E45BFC6C

File PE Metadata
Compilation timestamp:
7/27/2013 4:47:36 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:KoLV4KW1qUw/1mZZpxUbr6eH2GkWCFTmcE:K/JwNmZZpxorWm7

Entry address:
0x409EB

Entry point:
E8, E6, 12, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 50, B2, 44, 00, E8, EF, 17, 00, 00, E8, B3, 14, 00, 00, 0F, B7, F0, 6A, 02, E8, 79, 12, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 28, 02, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
279 KB (285,696 bytes)

Remove 69a0.exe - Powered by Reason Core Security