install_mario_forever.exe

Softendo Freeware Games

The application install_mario_forever.exe by Softendo Freeware Games has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
Softendo Freeware Games  (signed and verified)

MD5:
1a296072d9a85295f1a2d0ad8de06020

SHA-1:
1a50534e4559ae8c83eba918451b88521f6eabd1

SHA-256:
7eb29e1768ce98804174ef0ebb553d57d0dd40195f7c037fecede926ea3c6771

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/24/2024 3:49:27 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
OpenCandy
2016.0.3097

ESET NOD32
Win32/OpenCandy potentially unsafe
9.11321

G Data
Win32.Adware.OpenCandy
15.5.25

K7 AntiVirus
Unwanted-Program
13.200.15262

Malwarebytes
PUP.Optional.OpenCandy
v2015.05.26.05

McAfee
Artemis!1A296072D9A8
5600.6753

VIPRE Antivirus
Opencandy
38424

File size:
21.9 MB (22,915,456 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
8/24/2012 11:22:24 AM

Valid to:
8/24/2013 11:22:24 AM

Subject:
E=softendo@gmail.com, CN=Michał GDANIEC, O=Softendo Freeware Games, C=PL

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
28F77DDA713DA2EE949CBB5863CF152F

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:TEpTc1jE35eLZw2DGHF+LygOzznWJ0+FqeutqGDNBhOAQXoQKM6QYRzQCliXOjhH:TEpTQzL8++gOzznYJsXNfOAQF5MOCcOh

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Remove install_mario_forever.exe - Powered by Reason Core Security