{blocked}.exe

Aero Glass Configurator

Virtual Customs

The program is a setup application that uses the Inno Setup installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from download1353.mediafire.com and multiple other hosts.
Publisher:
Virtual Customs

Product:
Aero Glass Configurator

Version:
0.3.0.0

MD5:
66a3aa65df6a670761f771c216d47c8e

SHA-1:
e5991eb2321f55d5f6236caf2d48fbed2f993104

SHA-256:
ed77cacc12c983e9864026b6df6f4a7035f0b3865727c31aeb01ab912825cc50

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 6:55:02 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
VBS/Downloader.Agent
2015.0.3397

File size:
926.6 KB (948,805 bytes)

Product version:
0.3.0.0

Copyright:
Copyright © 2013 Mr GRiM

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:qQiGpOGHhHKEJocACSym5VqNptabmv6kYXn+WZMVVC0vT+TUva7ou9OKpNszdt:qQiUzQn1CSqz1pq+6caUvupNszn

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file {blocked}.exe has been seen being distributed by the following 2 URLs.

Scan {blocked}.exe - Powered by Reason Core Security