alot-appbar-installer.exe

Barra de aplicaciones de ALOT

Alot.com

The application alot-appbar-installer.exe, “Configuración de la Barra de aplicaciones de ALOT” by Alot.com has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from files.alotimg.com.
Publisher:
ALOT  (signed by Alot.com)

Product:
Barra de aplicaciones de ALOT

Description:
Configuración de la Barra de aplicaciones de ALOT

Version:
1.3.4000.0

MD5:
526f0292e8009e5bab4be68448df4944

SHA-1:
154114d3ca3d3f1119ea6eb983fb8e55e08d2631

SHA-256:
c2fd24fc39c55eda6e617482f5e1cd2864e1dbfa4f1a51219f2fe23baf60ed4d

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
4/16/2024 3:08:59 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Threat.Undefined
9.0.1.043

ESET NOD32
Win32/Toolbar.Alot potentially unwanted application
10.7.0.302.0

K7 AntiVirus
Unwanted-Program
13.183.13584

Kaspersky
not-a-virus:WebToolbar.Win32.Agent
14.0.0.674

Reason Heuristics
PUP.Alot.Installer (M)
16.2.12.5

Rising Antivirus
PE:Trojan.Win32.Generic.160C1783!369891203
23.00.65.16210

Sophos
PUA 'Alot Toolbar' (of type Adware)
5.15

Trend Micro House Call
TROJ_GE.D1ECB54C
7.2.43

Trend Micro
ADW_BHO
10.465.12

Zillya! Antivirus
Adware.Agent.Win32.56600
2.0.0.2211

File size:
1.1 MB (1,189,512 bytes)

Copyright:
(c) 2010 ALOT.com

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\alot-appbar-installer.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/13/2010 7:00:00 PM

Valid to:
6/20/2013 6:59:59 PM

Subject:
CN=Alot.com, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Alot.com, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0EBE0040F9558F86569F54286EF65398

File PE Metadata
Compilation timestamp:
9/9/2009 8:23:23 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:LmJtprM4lfGl15b3mVCrtj1l88Q+CmN44m9G08Tb7Lw6zQpp0dMwwCc/oDZIV:LkMyEz3mstj1ZQ+Cm+4ml6zQpmS1OeV

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file alot-appbar-installer.exe has been seen being distributed by the following URL.

Remove alot-appbar-installer.exe - Powered by Reason Core Security