avgac96.exe

SilentInstaller

The application avgac96.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from d1xd06pkl5614k.cloudfront.net.
Product:
SilentInstaller

Version:
1.0.0.1

MD5:
e186c70bad1f0471f3e259f0da5ca8f2

SHA-1:
85eff7c43c16d69c12278482fd048574e5c77f08

SHA-256:
8a11f9000b7653dca164740efe01efb9605d0fdfdefc2e3ed7b6bcd331584d4a

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
5/1/2024 7:55:41 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Kazy.712679
5750164

AhnLab V3 Security
PUP/Win32.OfferInstaller
2015.10.27

Avira AntiVirus
TR/Dropper.MSIL.Gen
8.3.2.2

Arcabit
Trojan.Adware.Kazy.DADFE7
1.0.0.585

avast!
Win32:Dropper-gen [Drp]
151024-0

AVG
Downloader
2016.0.2943

Baidu Antivirus
Adware.MSIL.Imali
4.0.3.151027

Bitdefender
Gen:Variant.Adware.Kazy.712679
1.0.20.1500

Emsisoft Anti-Malware
Gen:Variant.Adware.Kazy.712679
10.0.0.5366

ESET NOD32
MSIL/Adware.Imali.C application
7.0.302.0

Fortinet FortiGate
Adware/Imali
10/27/2015

F-Secure
Gen:Variant.Adware.Kazy
5.14.151

G Data
Gen:Variant.Adware.Kazy.712679
15.10.25

IKARUS anti.virus
AdWare.MSIL.Imali
t3scan.1.9.5.0

McAfee
Program.Artemis!E186C70BAD1F
18.0.204.0

MicroWorld eScan
Gen:Variant.Adware.Kazy.712679
16.0.0.900

Norman
Gen:Variant.Adware.Kazy.712679
22.10.2015 04:41:22

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.151025

SUPERAntiSpyware
Adware.Kazy/Variant
9544

File size:
333 KB (340,992 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © 2014

Original file name:
SilentInstaller_dotnet2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\avgac96.exe

File PE Metadata
Compilation timestamp:
10/26/2015 3:48:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:+vDYFZT8qbTR7SquD4L8vioH/X8i9DLnHWcefjVo8bS5VNQMuL:hZwgVxGq86oH/MKvnolgBo

Entry address:
0x5407E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8089

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
328.5 KB (336,384 bytes)

The file avgac96.exe has been seen being distributed by the following URL.

Remove avgac96.exe - Powered by Reason Core Security