android_root.exe

Proinstall Applications SRL

The application android_root.exe by Proinstall Applications SRL has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from dw.cbsi.com.
Publisher:
Proinstall Applications SRL  (signed and verified)

MD5:
fc37df226685b6aa3118d03ee4ba4664

SHA-1:
78f1fbd83e1360090d353855c0ab1a1d49de45f7

SHA-256:
569af77d51adf2d0df00f52bca05f3f48600be762d5bcd0d3f93ae1ac8f34bc8

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
5/10/2024 5:04:20 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3124

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Downware.9446
9.0.1.0119

NANO AntiVirus
Riskware.Nsis.Downware.dqgtsy
0.30.24.1357

Reason Heuristics
Threat.Installer.ProinstallApplicationsSRL
15.4.29.17

VIPRE Antivirus
Threat.5066599
39676

File size:
226.4 KB (231,808 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Authority:
DigiCert Inc

Valid from:
12/23/2014 12:00:00 AM

Valid to:
2/12/2016 12:00:00 PM

Subject:
CN=Proinstall Applications SRL, O=Proinstall Applications SRL, L=Bucuresti, S=Bucuresti, C=RO, PostalCode=030964, STREET="Bd Decebal Nr 25-29,", STREET="Etaj 9, Camera A Sectorul 3", SERIALNUMBER=33860761, OID.1.3.6.1.4.1.311.60.2.1.3=RO, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06E792CC425AE44EC57995906CBC9226

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:sQIURTXJrIHVY2BNjcjcLJmC2IvDK1FrWYyn:ssuVYe3df2I+1FrWtn

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.0471

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file android_root.exe has been seen being distributed by the following URL.

Remove android_root.exe - Powered by Reason Core Security