installer.exe

The application installer.exe has been detected as a potentially unwanted program by 23 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source.
MD5:
e80af256647651242a7245024835f839

SHA-1:
5941b41bf84ead231215a447684481f61424fe95

SHA-256:
eab916dad725de39d68f74be9006ae815584b7663a6ee98c9f2c9a93791ac090

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 10:22:13 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.iBryte.CJ
5575765

Agnitum Outpost
PUA.Agent
7.1.1

AhnLab V3 Security
2015.05.29

Avira AntiVirus
ADWARE/iBryte.Gen7
8.3.1.6

avast!
Win32:GenMaliciousA-SEV [PUP]
2014.9-150528

AVG
Adware AdPlugin.DLC
2014.0.4311

Bitdefender
Adware.iBryte.CJ
1.0.20.740

Bkav FE
HW32.Packed
1.3.0.6379

Clam AntiVirus
Win.Adware.Ibryte-8505
0.98/20518

Dr.Web
Trojan.BrowseBan.979
9.0.1.05190

Emsisoft Anti-Malware
Adware.iBryte.CJ
10.0.0.5366

ESET NOD32
Win32/Adware.iBryte.CD application
7.0.302.0

F-Secure
Adware.iBryte.CJ
5.14.151

G Data
Adware.iBryte.CJ
15.5.25

K7 AntiVirus
Adware
13.204.16062

MicroWorld eScan
Adware.iBryte.CJ
16.0.0.444

nProtect
Adware.iBryte.CJ
15.05.28.01

Panda Antivirus
Trj/Genetic.gen
15.05.28.05

Reason Heuristics
Threat.Win.Reputation.IMP
15.5.28.13

Rising Antivirus
PE:Trojan.FakeIcon!1.64A5
23.00.65.15526

VIPRE Antivirus
Threat.4150696
40552

Zillya! Antivirus
Adware.iBryte.Win32.8616
2.0.0.2193

File size:
6.1 MB (6,395,992 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\installer.exe

File PE Metadata
Compilation timestamp:
5/7/2015 3:23:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:sHhrZnsg7ysGKvT3gU9JDCm2mFRer6pCagXg81pbD0NzbAXm:sHhrnvUUTTIr6pC3w812NYXm

Entry address:
0x9007

Entry point:
E8, B3, 33, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, C4, D0, 52, 00, FF, 15, 60, D0, 41, 00, 85, C0, 75, 18, 56, E8, 65, 34, 00, 00, 8B, F0, FF, 15, 5C, D0, 41, 00, 50, E8, 15, 34, 00, 00, 59, 89, 06, 5E, 5D, C3, 8B, C1, 83, 60, 04, 00, C7, 00, 68, 58, 52, 00, C6, 40, 08, 00, C3, 8B, FF, 55, 8B, EC, 8B, C1, 8B, 4D, 08, C7, 00, 68, 58, 52, 00, 8B, 09, 89, 48, 04, C6, 40, 08, 00, 5D, C2, 08, 00, 8B, 41, 04, 85, C0, 75, 05, B8, 70, 58, 52, 00, C3, 8B...
 
[+]

Code size:
108.5 KB (111,104 bytes)

Remove installer.exe - Powered by Reason Core Security