e9bed.exe

The application e9bed.exe has been detected as a potentially unwanted program by 29 anti-malware scanners. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
MD5:
7729b229310792ccbbffac19179be13b

SHA-1:
5365f12c79bbba28a36fc82d47cb506c0384342f

SHA-256:
fd7d290e7a1216ca991ee0a7e205fbc3e8c22dc467f11743c3ae4e476ef60b88

Scanner detections:
29 / 68

Status:
Potentially unwanted

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/24/2024 11:41:56 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.CrossRider.DP
5719594

Agnitum Outpost
PUA.Toolbar.CrossRider
7.1.1

AhnLab V3 Security
PUP/Win32.CrossRider
2015.09.28

Avira AntiVirus
TR/ATRAPS.Gen4
8.3.2.2

Arcabit
Adware.CrossRider.DP
1.0.0.567

avast!
Win32:Crossrider-DV [PUP]
150913-1

AVG
Win32/DH{gRKBEyAiJQE2V04}
2016.0.2973

Bitdefender
Adware.CrossRider.DP
1.0.20.1350

Comodo Security
Application.Win32.CrossRider.AKP
23313

Dr.Web
Trojan.DownLoader16.37904
9.0.1.05190

Emsisoft Anti-Malware
Adware.CrossRider.DP
10.0.0.5366

ESET NOD32
Win32/Toolbar.CrossRider.BX potentially unwanted application
7.0.302.0

F-Prot
W32/S-d4447518
v6.4.7.1.166

F-Secure
Adware.CrossRider.DP
5.14.151

G Data
Adware.CrossRider.DP
15.9.25

K7 AntiVirus
Adware
13.210.17344

Kaspersky
not-a-virus:HEUR:AdWare.Win32.CrossRider
15.0.0.543

Malwarebytes
PUP.Optional.CrossRider
v2015.09.27.10

MicroWorld eScan
Adware.CrossRider.DP
16.0.0.810

Norman
Adware.CrossRider.DP
04.08.2015 10:30:46

nProtect
Adware.CrossRider.DP
15.09.25.01

Panda Antivirus
Trj/Genetic.gen
15.09.27.10

Quick Heal
PUA.Adwapper.02118
9.15.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
15.10.4.18

Rising Antivirus
PE:Malware.RDM.00!5.6[F1]
23.00.65.15925

Sophos
Generic PUA EH (PUA)
4.98

SUPERAntiSpyware
Adware.Crossrider/Variant
9603

VIPRE Antivirus
Threat.4150696
43798

Zillya! Antivirus
Downloader.Toolbar.Win32.203
2.0.0.2417

File size:
212 KB (217,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\e9bed.exe

File PE Metadata
Compilation timestamp:
9/19/2015 3:08:03 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:qNFq5hWzhxkoVQWJlkJ2QcpIW0Nt+sCwr8vs1C8/ehoraNUXMgoLWTUC4:qTqCQKlkHjx4vs1C8/ehoraNUXIq

Entry address:
0x12614

Entry point:
E8, CD, 69, 00, 00, E9, 7F, FE, FF, FF, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 54, 26, 33, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 58, 11, 33, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 54, 26, 33, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03, 00...
 
[+]

Code size:
150.5 KB (154,112 bytes)

Remove e9bed.exe - Powered by Reason Core Security