installer-silent.exe

The application installer-silent.exe has been detected as a potentially unwanted program by 26 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source.
MD5:
1961a3801bef7e4a6dce081210150224

SHA-1:
7a5c867dfb02a3a19fcad63e1c7dd7fc6377f663

SHA-256:
0c867610526a1e6aad6fd8dfb4cbcd6202d2d527d52735c3b513c1497a556aa1

Scanner detections:
26 / 68

Status:
Potentially unwanted

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/25/2024 4:10:21 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.NPG
864

Agnitum Outpost
Adware.CouponAmazing
7.1.1

avast!
BHO-ALY [Trj]
140908-2

AVG
Adware Generic5.ADMT
2014.0.4015

Bitdefender
Adware.Agent.NPG
1.0.20.1330

Bkav FE
HW32.Paked
1.3.0.4959

Clam AntiVirus
Win.Adware.Agent-6970
0.98/19419

Comodo Security
ApplicUnwnt
19597

Dr.Web
Trojan.MulDrop4.22900
9.0.1.05190

Emsisoft Anti-Malware
Adware.Agent.NPG
14.09.23

ESET NOD32
Win32/Adware.CouponAmazing.A application
7.0.302.0

Fortinet FortiGate
W32/Swisyn.CTSN!tr
9/23/2014

F-Secure
Gen:Variant.Adware.Kazy.269663
11.2014-23-09_3

G Data
Adware.Agent.NPG
14.9.24

IKARUS anti.virus
AdWare.Agent
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.183.13463

Kaspersky
not-a-virus:HEUR:AdWare.Win32.AdPeak
15.0.0.494

MicroWorld eScan
Adware.Agent.NPG
15.0.0.798

NANO AntiVirus
Trojan.Win32.MulDrop4.daodaa
0.28.2.62286

nProtect
Adware.Agent.NPG
14.09.23.01

Rising Antivirus
PE:Trojan.Win32.Generic.1464A64E!342140494
23.00.65.14921

Sophos
AdPeak
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-BHO-ALY
10342

Trend Micro House Call
TROJ_GEN.R08NC0PI514
7.2.266

Trend Micro
TROJ_GEN.R08NC0PI514
10.465.23

VIPRE Antivirus
Threat.4150696
33120

File size:
476.4 KB (487,825 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\installer-silent.exe

File PE Metadata
Compilation timestamp:
2/9/2013 1:59:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
12288:3h4kaSe2IXpgqgGkPHs5gaewt6lZpioZ8d7e7tZzSrnk:qSe2kf58wtYZAPdStUrnk

Entry address:
0x39B0

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 93, 46, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 3E, 43, 00, 00, 6A, 00, E8, A7, 46, 00, 00, A3, 88, 0C, 44, 00, 6A, 08, E8, 72, 28, 00, 00, A3, 38, 0D, 44, 00, 8D, 85, 90, FE, FF, FF, 6A, 00, 68, 60, 01, 00, 00, 50, 6A, 00, 68, A4, A2, 40, 00, E8, EC, 45, 00, 00, 83, EC, 0C, 68, A5, A2, 40, 00, 68, 68, 0D, 44, 00, E8, 92, 2A, 00, 00, 83, C4, 18, E8, FA, 42, 00, 00, 52, 52, 50, 68, 00, 30, 47, 00, E8, 7D, 2A, 00, 00, 57, 6A, 00, E8, 4D, 42, 00, 00, 83...
 
[+]

Entropy:
7.9044  (probably packed)

Code size:
28.5 KB (29,184 bytes)

Remove installer-silent.exe - Powered by Reason Core Security