9c9be450-dbba-446a-b8fd-64899387a96b.exe

The application 9c9be450-dbba-446a-b8fd-64899387a96b.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. This file is typically installed with the program Homepager which is a potentially unwanted software program. The file has been seen being downloaded from nano-xrule.ru and multiple other hosts.
Version:
1.0.0.0

MD5:
ac11f064deedf17f86ee96ed60e98fb6

SHA-1:
895944ed82726eebc5f5df4d977608e21d8f93fa

SHA-256:
edafabd5670c0866be01c96668d1845e4a8529833d1e4d58cd2466e7753895dd

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
5/17/2024 12:48:27 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Dropper-gen [Drp]
150602-1

Dr.Web
Trojan.Zadved.151
9.0.1.05190

ESET NOD32
Win32/InstallMonstr.CV potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/InstallMonstr
6/30/2015

G Data
Win32.Application.Agent.HHHMJ1
15.7.25

McAfee
Artemis!AC11F064DEED
5600.6693

Trend Micro
TROJ_GEN.R0EAC0OGC15
10.465.25

VIPRE Antivirus
Trojan.Win32.Generic
42264

File size:
5.7 MB (5,944,586 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\9c9be450-dbba-446a-b8fd-64899387a96b.exe

File PE Metadata
Compilation timestamp:
6/29/2015 4:54:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:rraxphLXlwSIn/pklwnfj3xmPuzXOztTNTZgjjN4:r+fhKClwn73xJXG0e

Entry address:
0x507B10

Entry point:
55, 8B, EC, 83, C4, EC, 33, C0, 89, 45, EC, B8, FC, 94, 8F, 00, E8, EB, 73, B0, FF, 33, C0, 55, 68, 97, 7B, 90, 00, 64, FF, 30, 64, 89, 20, 8B, 0D, C0, 62, 92, 00, A1, E8, 69, 92, 00, 8B, 00, 8B, 15, 20, 69, 8F, 00, E8, F9, CD, CE, FF, 8D, 55, EC, B8, 01, 00, 00, 00, E8, DC, F0, AF, FF, 8B, 45, EC, BA, B0, 7B, 90, 00, E8, FB, 32, B0, FF, 74, 0E, A1, C0, 62, 92, 00, 8B, 00, E8, E1, 01, FF, FF, EB, 0C, A1, C0, 62, 92, 00, 8B, 00, E8, EB, 05, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, 68, 9E, 7B, 90, 00, 8D, 45...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
5 MB (5,270,528 bytes)

The file 9c9be450-dbba-446a-b8fd-64899387a96b.exe has been discovered within the following program.

Homepager  by Homepager
About 57% of users remove it
 
Powered by Should I Remove It?

The file 9c9be450-dbba-446a-b8fd-64899387a96b.exe has been seen being distributed by the following 4 URLs.

http://nano-xrule.ru/.../h-0975049a3a9ff137c00dae7dac843671.exe

Remove 9c9be450-dbba-446a-b8fd-64899387a96b.exe - Powered by Reason Core Security