awh8d90.tmp

Smart Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The file awh8d90.tmp by Smart Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory.
Publisher:
Smart Apps  (signed and verified)

MD5:
9c97d386e6e4eb30b33ebf23c7c7d44b

SHA-1:
1e2669edcf72338e695269ee5a2ebafdcf719d54

SHA-256:
2a7cfb890c6ae24b27f1e20f50b20c16f81bb84601b3ffaee77372ffb2ee32f9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 7:54:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.50OnRed.SmartApps.Installer (M)
16.2.15.9

File size:
1.1 MB (1,102,568 bytes)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\appdata\local\temp\awh8d90.tmp

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/25/2013 1:00:00 AM

Valid to:
3/26/2014 12:59:59 AM

Subject:
CN=Smart Apps, O=Smart Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7CAFCF7841E5BDDF79F61691D678D0EC

File PE Metadata
Compilation timestamp:
2/19/2012 4:01:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
24576:ztMCWws/oPzqwsoqV3y7Lw9TUSiMKdoV0w1ZcjmhZ35MV9wjDe:zGX/ebk3y7LXnbw1O27vjDe

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Code size:
34.5 KB (35,328 bytes)

Remove awh8d90.tmp - Powered by Reason Core Security