forumersrv.exe

Forumer Toolbar

Montera Technologeis LTD

This is part of the Montera web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application forumersrv.exe by Montera Technologeis has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Innova Group  (signed by Montera Technologeis LTD)

Product:
Forumer Toolbar

Version:
1.8.19.0

MD5:
66f785e3ea38bc29695c3b8bb78706e4

SHA-1:
652760d7c1a32e57cd589702e9c4bd0f04dd8001

SHA-256:
14de89b9dfeac116c82232565d0cab98cb0eec155aa477b24a733683276a0112

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 10:06:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Montiera.Montera.Toolbar (M)
16.2.8.4

File size:
369.4 KB (378,264 bytes)

Product version:
1.8.19.0

Copyright:
(c) Innova Group All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States d'America)

Common path:
C:\Program Files\innova group\forumer\1.8.19.5\forumersrv.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/28/2012 2:00:00 AM

Valid to:
5/29/2013 1:59:59 AM

Subject:
CN=Montera Technologeis LTD, O=Montera Technologeis LTD, STREET="18, Amammi st", L=Even Yehuda, S=Hasharon, PostalCode=40500, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
361B49E5431DD304CA32589D28E4DD3C

File PE Metadata
Compilation timestamp:
5/8/2013 4:29:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:802ix7wpOgoc1n5vGU6NwEo6IKEPFXzlw9yvxKSwhpu9bJhwelPTMVe:12Y7wpOgocfvGU6tZINdxw9yvxqhpuPz

Entry address:
0x2A72B

Entry point:
E8, F2, 8A, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 10, 57, FF, 75, 10, 8D, 4D, F0, E8, E4, E0, FF, FF, 8B, 7D, 08, 85, FF, 75, 27, E8, 3D, 14, 00, 00, C7, 00, 16, 00, 00, 00, E8, 59, 17, 00, 00, 80, 7D, FC, 00, 74, 07, 8B, 45, F8, 83, 60, 70, FD, B8, FF, FF, FF, 7F, E9, A5, 00, 00, 00, 56, 8B, 75, 0C, 85, F6, 75, 24, E8, 0E, 14, 00, 00, C7, 00, 16, 00, 00, 00, E8, 2A, 17, 00, 00, 80, 7D, FC, 00, 74, 07, 8B, 45, F8, 83, 60, 70, FD, B8, FF, FF, FF, 7F, EB, 78, 53, 8B, 5D, F4, 83, 7B, 08, 00...
 
[+]

Entropy:
6.3417

Code size:
255.5 KB (261,632 bytes)

Remove forumersrv.exe - Powered by Reason Core Security