a6a0.exe

Stepan Rybin

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application a6a0.exe by Stepan Rybin has been detected as adware by 25 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Stepan Rybin  (signed and verified)

MD5:
ca22696f35d2c4f03702c1bf7af19ed6

SHA-1:
c3ab1c8979a11f90bb99e16b9c402e871e3df708

SHA-256:
56cdbbbbef421139f0c8fa402538f2b2756693bb7f7e9c58097827ad6291f54d

Scanner detections:
25 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/18/2024 8:42:29 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.MPLug.HH
6236936

Agnitum Outpost
PUA.MultiPlug
7.1.1

AhnLab V3 Security
PUP/Win32.MultiPlug
2015.04.01

avast!
Win32:Adware-gen [Adw]
150319-0

AVG
Generic6
2016.0.3153

Bitdefender
Adware.MPLug.HH
1.0.20.455

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.MultiPlug.YTRA
21608

Dr.Web
Trojan.Crossrider1.22656
9.0.1.05190

Emsisoft Anti-Malware
Adware.MPLug.HH
9.0.0.4799

ESET NOD32
Win32/Adware.MultiPlug.GF (variant)
9.11409

Fortinet FortiGate
Riskware/MultiPlug
4/1/2015

F-Secure
Adware.MPLug.HH
5.13.68

G Data
Adware.MPLug.HH
15.4.25

K7 AntiVirus
Trojan
13.202.15449

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

Malwarebytes
PUP.Optional.MultiPlug
v2015.04.01.06

McAfee
Program.MultiPlug-FXC
16.8.708.2

MicroWorld eScan
Adware.MPLug.HH
16.0.0.273

NANO AntiVirus
Riskware.Win32.MultiPlug.dpwbxy
0.30.8.659

nProtect
Adware.MPLug.HH
15.04.01.01

Reason Heuristics
PUP.Task.WebPick
15.4.1.6

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15330

Sophos
MultiPlug
4.98

Vba32 AntiVirus
suspected of Heur.Malware-Cryptor.Multiplug
3.12.26.3

File size:
471.2 KB (482,504 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\{86696e1f-7ef2-db52-8669-96e1f7efb87d}\a6a0.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
6/27/2014 3:37:40 AM

Valid to:
6/27/2015 3:37:40 AM

Subject:
E=rybin.step@yandex.ru, CN=Stepan Rybin, O=Stepan Rybin, C=UA

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
47154C2151E9EB8DFA42C2C9E45BFC6C

File PE Metadata
Compilation timestamp:
4/5/2013 6:47:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:CVcRM1eP/HPUUjHDxTmvGVg6OMpCcdN9m6KNU3Y0gXbJLnummBS/ZHC6mvqvivjz:sc4eP/P5LDNqCn9hSNf70o8iK

Entry address:
0x4527B

Entry point:
E8, CF, 1F, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, A0, 02, 45, 00, E8, DF, 24, 00, 00, E8, 9C, 21, 00, 00, 0F, B7, F0, 6A, 02, E8, 62, 1F, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 28, 02, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4310

Code size:
297 KB (304,128 bytes)

Scheduled Task
Task name:
{3A903E09-2060-458B-8188-BF97594A94A4}

Trigger:
Registration (Runs on registration)


Remove a6a0.exe - Powered by Reason Core Security