antinetcut3win7.exe

AntiNetCut3

Tools4Free

The application antinetcut3win7.exe, “This installer database contains the logic and data required to install AntiNetCut3.” has been detected as a potentially unwanted program by 2 anti-malware scanners. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from f51.y8top.net and multiple other hosts.
Publisher:
Tools4Free

Product:
AntiNetCut3

Description:
This installer database contains the logic and data required to install AntiNetCut3.

Version:
1.0.0

MD5:
c23660287e4f5e9b7cc8dfa15f55c1f1

SHA-1:
3b42feb4b3573a348727445d954c75ac83f1d34e

SHA-256:
37d4e036d2ae5517ef53be0b116e6c80b602f8eae81f98dda0edc341e2a5c567

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/20/2024 3:38:39 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallMonetizer.AQ
8.9383

Reason Heuristics
PUP.InstallMonetizer.Bundle (M)
16.3.10.15

File size:
2.6 MB (2,754,805 bytes)

Product version:
1.0.0

Copyright:
Copyright (C) Tools4Free

Original file name:
AntiNetCut3-Win7.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
4/4/2011 3:59:22 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:obeDB+eG3J7ngDYIA1AAJoMHfTMgoyMfIp3cGeh+9c4ZSO4Dok64WYl+k7NO/QWt:meDBrGZ6YIA1AAJfoyMfIp3cGeh+9c4r

Entry address:
0x2745E

Entry point:
E8, AF, 8C, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 10, 53, 56, FF, 75, 10, 8D, 4D, F0, E8, 89, FA, FF, FF, 8B, 5D, 08, 33, F6, 3B, DE, 75, 2F, E8, 5B, 26, 00, 00, 56, 56, 56, 56, 56, C7, 00, 16, 00, 00, 00, E8, E3, 25, 00, 00, 83, C4, 14, 80, 7D, FC, 00, 74, 07, 8B, 45, F8, 83, 60, 70, FD, B8, FF, FF, FF, 7F, E9, C0, 00, 00, 00, 57, 8B, 7D, 0C, 3B, FE, 75, 2F, E8, 24, 26, 00, 00, 56, 56, 56, 56, 56, C7, 00, 16, 00, 00, 00, E8, AC, 25, 00, 00, 83, C4, 14, 80, 7D, FC, 00, 74, 07, 8B, 45, F8...
 
[+]

Entropy:
7.0652

Code size:
217 KB (222,208 bytes)

The file antinetcut3win7.exe has been seen being distributed by the following 4 URLs.

http://f51.y8top.net/2107tmp/cf/soft/2013/8/ba/.../anti-netcut_30.exe

Remove antinetcut3win7.exe - Powered by Reason Core Security