alot-appbar-installer.exe

Barra de aplicaciones de ALOT

Alot.com

The application alot-appbar-installer.exe, “Configuración de la Barra de aplicaciones de ALOT” by Alot.com has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from files.alotimg.com.
Publisher:
ALOT  (signed by Alot.com)

Product:
Barra de aplicaciones de ALOT

Description:
Configuración de la Barra de aplicaciones de ALOT

Version:
1.2.2000.2

MD5:
5eade5e6400767556f99ffcaedeefa03

SHA-1:
78660f590a0f83f63465223955f812129409edd3

SHA-256:
635112a57215b5e9f5d219399717a41bd5211fc51836b33948eca9eda9c4d4db

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
4/23/2024 10:40:46 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Threat.Undefined
9.0.1.045

ESET NOD32
Win32/Toolbar.Alot potentially unwanted application
10.7.0.302.0

K7 AntiVirus
Unwanted-Program
13.183.13584

Kaspersky
not-a-virus:WebToolbar.Win32.Agent
14.0.0.665

Reason Heuristics
PUP.Alot.Installer (M)
16.2.14.0

Rising Antivirus
PE:Trojan.Win32.Generic.160C1783!369891203
23.00.65.16212

Sophos
PUA 'Alot Toolbar' (of type Adware)
5.15

Trend Micro House Call
TROJ_GE.D1ECB54C
7.2.45

Trend Micro
ADW_BHO
10.465.14

Zillya! Antivirus
Adware.Agent.Win32.56600
2.0.0.2211

File size:
1.1 MB (1,120,592 bytes)

Copyright:
(c) 2010 ALOT.com

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\alot-appbar-installer.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/13/2010 7:00:00 PM

Valid to:
6/20/2013 6:59:59 PM

Subject:
CN=Alot.com, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Alot.com, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0EBE0040F9558F86569F54286EF65398

File PE Metadata
Compilation timestamp:
9/9/2009 8:23:23 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:omJb3omvDiVCCx5q/Q8D1UlIDrP310nBrnOIM14nNoOb:ov1C2J8D1KIDrP38rOIMqnNoOb

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.9709

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file alot-appbar-installer.exe has been seen being distributed by the following URL.

Remove alot-appbar-installer.exe - Powered by Reason Core Security