{blocked}.exe

Installation de Pass Finder

PassRevelator

The application {blocked}.exe by PassRevelator has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider.
Publisher:
Pass Revelator  (signed by PassRevelator)

Product:
Installation de Pass Finder

Version:
1.0.0.0

MD5:
48a90de5df6d59c2e8a6da34b2a10df9

SHA-1:
16fbbcc4d555be09085aa2f5de2362f7b5e661a2

SHA-256:
7c8706fed3cf98ddff8d3d1830f2dcf1b1871d8dd706c84c68ed729d32e8b4a5

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
4/26/2024 6:05:09 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Bbylon
4.0.3.1667

Comodo Security
UnclassifiedMalware
23080

ESET NOD32
Win32/Hoax.ArchSMS.ADT
10.12147

NANO AntiVirus
Trojan.Win32.Babylon.csuksh
0.30.24.3079

Qihoo 360 Security
Win32/Trojan.Hoax.ac5
1.0.0.1015

Trend Micro House Call
TROJ_SPNV.03JL13
7.2.159

Trend Micro
TROJ_SPNV.03JL13
10.465.07

VIPRE Antivirus
Trojan.Win32.Generic
43188

File size:
2.3 MB (2,419,968 bytes)

Product version:
1.0.0.0

Copyright:
Pass Revelator

Original file name:
Pass_Finder_Installation

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\pass_finder_installation \pass_finder_installation.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/29/2012 12:00:00 AM

Valid to:
10/29/2013 11:59:59 PM

Subject:
CN=PassRevelator, O=PassRevelator, STREET=1204 rue des Luats, L=Pannes, S=Totostate, PostalCode=45700, C=FR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DB90474AEADA7B3B5C99227DB0ED9622

File PE Metadata
Compilation timestamp:
6/19/1992 10:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:FghXolANVdo6Lai21TArTfobiG2uBLdignZ+LG4PxtU7:FgilAN7NLaIrTfk2uWNLGgg

Entry address:
0x204FB0

Entry point:
60, BE, 00, 90, 56, 00, 8D, BE, 00, 80, E9, FF, C7, 87, A4, 90, 1A, 00, 2F, 61, CC, 5C, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 4B, 2B, 20, 00, 57, 83, C3, 04, 53, 68, AA, BF, 09, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9...
 
[+]

Code size:
628 KB (643,072 bytes)

Remove {blocked}.exe - Powered by Reason Core Security