block_youtube_adssetup_v1.0.1.5045_firstoffer.exe

PC-Gizmos LTD

The application block_youtube_adssetup_v1.0.1.5045_firstoffer.exe by PC-Gizmos has been detected as a potentially unwanted program by 9 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
PC-Gizmos LTD  (signed and verified)

MD5:
10054f77577f81deef0bfaef4e017004

SHA-1:
97efcc98bcd6432e25a07bf34414555fb138174f

SHA-256:
60adabb7dcae5c6f06067af490649c0356a6a23ad7bd645c4d8cf1316942dc82

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 2:44:25 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
2015.11.25

Avira AntiVirus
PUA/InstallCore.Gen
8.3.2.4

ESET NOD32
Win32/InstallCore.AZ potentially unwanted (variant)
9.12619

F-Prot
W32/InstallCore.W.gen
v6.4.7.1.166

K7 AntiVirus
Adware
13.212.17959

McAfee
Artemis!10054F77577F
5600.6570

Qihoo 360 Security
Win32/Virus.Adware.406
1.0.0.1077

Reason Heuristics
PUP.PCGizmos.Installer (M)
15.11.26.8

Sophos
Generic PUA JH (PUA)
4.98

File size:
1.1 MB (1,147,968 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\block_youtube_adssetup_v1.0.1.5045_firstoffer.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/16/2012 8:00:00 PM

Valid to:
5/17/2013 7:59:59 PM

Subject:
CN=PC-Gizmos LTD, OU=Web, O=PC-Gizmos LTD, STREET=1 Azrieli Center, STREET=19 floor, STREET=C/O BAS Law, L=Tel Aviv, S=Israel, PostalCode=67021, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008ED22FA36113DA901306BF9F7C731477

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:3IW1YITJCz9w0kU1793GsJYhEWrj+xkiL6uaLIjgwL+T0gQNnVg:ZTJCJwxU1792sJYhEWrjq1wPEq

Entry address:
0xD5B80

Entry point:
55, 8B, EC, 83, C4, F0, B8, E0, C9, 40, 00, E8, 9F, EC, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5943

Developed / compiled with:
Microsoft Visual C++

Code size:
866 KB (886,784 bytes)