9_avast_launcher.exe

Mega Boost

Cortez Com

The application 9_avast_launcher.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.panningmanybanded.site and multiple other hosts.
Publisher:
Cortez Com

Product:
Mega Boost

Description:
smart install

Version:
24.42.111.51

MD5:
361f878bc68430c7ac94166bc0bb495d

SHA-1:
256c0fc929f92644281636b323bf1854b6ea54e2

SHA-256:
7896d59e64570d4ad3471ccb5ebfdb6dd53dde4cfba0f953209f62de75d351e6

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
5/12/2025 8:13:53 AM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Gen:Variant.Symmi.60918
11.5.0.6191

ESET NOD32
Win32/Amonetize.SE potentially unwanted application
8.0.319.0

F-Secure
Variant.Razy.42339
5.15.96

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize
15.0.0.562

Norman
Gen:Variant.Razy.42339
10.04.2016 15:29:17

Reason Heuristics
Adware.InstallMonetizer.CortezCo.Installer.Meta (M)
16.5.6.17

File size:
766.5 KB (784,896 bytes)

Product version:
24.42.111.51

Copyright:
Rights 2000

Trademarks:
SW Good M

Original file name:
build.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
5/6/2016 6:07:05 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:WlpW0Veel1cBdTZHuh+CfsblSiOSI2oNV+OYE9xalCJP7Elp:SMefINz8iFI2oNVjYmxalCIlp

Entry address:
0xD2CB

Entry point:
E8, 7A, 30, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 50, 31, C0, 89, D8, EB, 03, EB, 00, B8, 90, 90, EB, 03, B8, 83, F8, 58, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 40, FC, 41, 00, FF, 15, 80, 80, 41, 00, 85, C0, 75, 18, 56, E8, 24, 25, 00, 00, 8B, F0, FF, 15, 14, 80, 41, 00, 50, E8, D4, 24, 00, 00, 59, 89, 06, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 53, 56, 8B, 75, 08, 8B, 46, 0C, 8B, C8, 80, E1, 03, 33, DB, 80, F9, 02, 75, 40, A9, 08, 01, 00, 00, 74, 39, 8B, 46, 08, 57, 8B, 3E, 2B, F8, 85, FF...
 
[+]

Code size:
92.5 KB (94,720 bytes)

The file 9_avast_launcher.exe has been seen being distributed by the following 2 URLs.

Remove 9_avast_launcher.exe - Powered by Reason Core Security