flvblaster.exe

appbundler.com

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application flvblaster.exe by appbundler.com has been detected as adware by 33 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
appbundler.com  (signed and verified)

Description:
Setup

Version:
3.0.113.1

MD5:
ce1a1e8c27dc3c4e703300fc5070b7c6

SHA-1:
66bd57673595d9b6bc35a933eb7830d52355ad15

SHA-256:
e2a8c633799b60bb9b12204fe7eb2cefb3076f7af13773432bf52a344348acac

Scanner detections:
33 / 68

Status:
Adware

Analysis date:
4/26/2024 7:52:52 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.380224
1018

Agnitum Outpost
PUA.GOffer
7.1.1

AhnLab V3 Security
Adware/Win32.ScreenSaver
14.04.23

Avira AntiVirus
Adware/Hotbar.aok
7.11.144.202

avast!
Win32:Zango-AQ [PUP]
2014.9-140423

AVG
Skodna.Generic_r
2015.0.3496

Bitdefender
Adware.Generic.380224
1.0.20.565

Comodo Security
ApplicUnwnt.Win32.AdWare.ScreenSaver.DI
18153

Dr.Web
Adware.Hotbar.700
9.0.1.0113

Emsisoft Anti-Malware
Adware.Generic.380224
8.14.04.23.06

ESET NOD32
Win32/Adware.HotBar (variant)
8.9710

Fortinet FortiGate
Adware/Hotbar
4/23/2014

F-Prot
W32/HotBar.O.gen
v6.4.7.1.166

F-Secure
Adware.Generic.380224
11.2014-23-04_4

G Data
Adware.Generic.380224
14.4.24

IKARUS anti.virus
not-a-virus:AdWare.Win32.ScreenSaver
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.176.11847

Kaspersky
not-a-virus:AdWare.Win32.ScreenSaver
14.0.0.3974

Malwarebytes
Adware.AdBundle
v2014.04.23.06

McAfee
Adware-HotBar.d
5600.7152

Microsoft Security Essentials
Adware:Win32/Hotbar
1.10502

MicroWorld eScan
Adware.Generic.380224
15.0.0.339

NANO AntiVirus
Trojan.Win32.Click2.brloqf
0.28.0.59492

Norman
180Solutions.BSE
11.20140423

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Quick Heal
Adware.Hotbar.B5
4.14.12.00

Reason Heuristics
PUP.Installer.appbundler.K
14.8.7.21

Rising Antivirus
PE:Adware.HotBar!1.6AAD
23.00.65.14421

Sophos
Generic PUA DA
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-HotBar
10648

Total Defense
Win32/Zango.Pinball.B[HOTBAR]
37.0.10894

Vba32 AntiVirus
AdWare.ScreenSaver
3.12.26.0

VIPRE Antivirus
Pinball Corporation.
28526

File size:
339.2 KB (347,312 bytes)

Product version:
3.0.113.1

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\flvblaster.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/10/2012 1:00:00 AM

Valid to:
1/10/2015 12:59:59 AM

Subject:
CN=appbundler.com, OU=Ops, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=appbundler.com, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
12E277DA6E659BFE14CD01F5A2AA95C5

File PE Metadata
Compilation timestamp:
12/19/2012 6:23:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:sBA5wVdCy6wrbDY0rDqTWC4zEDzKuTrSbxc97cqEYScrsAHw1DozbiAOKxxO9:qjyy64VrDqTWIzW+9YBkrsAQ1Dozb1Ol

Entry address:
0xBC840

Entry point:
60, BE, 00, B0, 46, 00, 8D, BE, 00, 60, F9, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
328 KB (335,872 bytes)

Remove flvblaster.exe - Powered by Reason Core Security