aer.exe

TODO:

Setup

The application aer.exe has been detected as a potentially unwanted program by 12 anti-malware scanners.
Publisher:
Setup

Product:
TODO: <Product name>

Description:
Setup

Version:
1.0.0.1

MD5:
78644cf6b8fc9451e2fcc44274ea7708

SHA-1:
d8aeb588b115c658bb4ed4e5abc336b9503cde27

SHA-256:
cdbf03c791e33dc7110d8a08ffd1312aa1213672109cc9046a75e06fa1aae2fa

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 10:51:47 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Preloader
14.09.01

AVG
Generic_r
2015.0.3365

Baidu Antivirus
Adware.Win32.MegaSearch
4.0.3.1491

ESET NOD32
Win32/AdWare.MultiPlug.K.gen (variant)
8.9542

Kaspersky
not-a-virus:AdWare.Win32.MegaSearch
14.0.0.3320

Malwarebytes
PUP.Optional.MultiPlug.A
v2014.09.01.12

McAfee
PUP-FFY!78644CF6B8FC
5600.7021

Panda Antivirus
Trj/Genetic.gen
14.09.01.12

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.1.0

Sophos
MultiPlug
4.98

Trend Micro House Call
TROJ_GEN.R08NB04CC14
7.2.244

VIPRE Antivirus
MegaSearch Toolbar
27366

File size:
484 KB (495,616 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2013

Original file name:
crxdrop.dll

File type:
Executable application (Win32 EXE)

Language:
Hebrew (Israel)

Common path:
C:\ProgramData\saaferweba\aer.exe

File PE Metadata
Compilation timestamp:
2/2/2014 5:52:07 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:h4ITzqAe9yDeYcjNzv5iUVVh8rQkzmwCLqD0PSC/7N7H3CklBR/oLD:1nHDENbzVhoQkrCLqD0qON3T1oLD

Entry address:
0x3E1B0

Entry point:
E8, EA, 4F, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, A0, F7, 45, 00, E8, FA, 2B, 00, 00, E8, C3, 36, 00, 00, 0F, B7, F0, 6A, 02, E8, 7D, 4F, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 5E, 49, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.1334

Code size:
318.5 KB (326,144 bytes)

Remove aer.exe - Powered by Reason Core Security