installer7__7934_il13539.exe

The application installer7__7934_il13539.exe has been detected as a potentially unwanted program by 27 anti-malware scanners. This is a setup program which is used to install the application. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from v4download.com.
Version:
1.1.5.90

MD5:
9bf694eb44cd08e3aeca2e49eff357e3

SHA-1:
9f85f47bc7a103460cea08e5f348fb62df3f4218

SHA-256:
007a79dbb81bace8805b707f5da5ebcc38279a1b664e93a3b0ba7ab9d0b420bd

Scanner detections:
27 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 4:22:46 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Kazy.556217
278

Agnitum Outpost
PUA.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Amonetiz
2015.04.10

avast!
Win32:Adware-gen [Adw]
2014.9-160502

Baidu Antivirus
PUA.Win32.Amonetize
4.0.3.1652

Bitdefender
Gen:Variant.Adware.Kazy.556217
1.0.20.615

Bkav FE
HW32.Packed
1.3.0.6379

Comodo Security
Virus.Win32.Virut.CE
21713

Emsisoft Anti-Malware
Gen:Variant.Adware.Kazy.556217
8.16.05.02.05

ESET NOD32
Win32/Amonetize.EA potentially unwanted (variant)
10.11453

Fortinet FortiGate
Adware/Generic
5/2/2016

F-Prot
W32/Amonetize.D.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Kazy
11.2016-02-05_2

G Data
Gen:Variant.Adware.Kazy.556217
16.5.25

K7 AntiVirus
Trojan
13.202.15549

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Generic
14.0.0.274

Malwarebytes
PUP.Optional.Amonetize
v2016.05.02.05

McAfee
Artemis!9BF694EB44CD
5600.6412

MicroWorld eScan
Gen:Variant.Adware.Kazy.556217
17.0.0.369

NANO AntiVirus
Riskware.Win32.Amonetize.dpcwni
0.30.10.952

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
5.16.14.00

Reason Heuristics
Adware.Amonetize.ET (M)
16.5.2.5

Sophos
Generic PUA JP
4.98

Trend Micro House Call
TROJ_GEN.R02KC0ECB15
7.2.123

Trend Micro
TROJ_GEN.R02KC0ECB15
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic
39214

File size:
648.5 KB (664,064 bytes)

Product version:
1.1.5.90

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\installer7__7934_il13539.exe

File PE Metadata
Compilation timestamp:
3/3/2015 12:01:10 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:0dogXcq5OPCRhzWerD3bs7vfgMiH2vJtIFinUqwi8erio11C7V7+m8F:0do7COPAWevQTLYAoInUo5rio/aIpF

Entry address:
0x1382CC

Entry point:
60, 9C, C7, 44, 24, 20, 5C, 40, 2C, A6, 9C, 88, 4C, 24, 04, C7, 44, 24, 20, FE, DA, B1, FC, 60, C6, 04, 24, F0, 8D, 64, 24, 40, E9, 74, 1D, 00, 00, E9, 79, 29, FF, FF, E8, F1, DF, FE, FF, 1E, E8, 5F, F7, C5, 06, C2, 34, 5F, A3, 7D, 09, 4E, 98, B0, CC, 7C, FC, 0A, E3, 65, 3F, 78, BA, E8, C4, 27, C0, 0E, 8A, 6C, 9B, D9, CC, FE, DC, CA, 0A, 08, 6E, E7, FA, BE, 62, 4B, 2A, 64, 03, 0F, BC, FC, 1E, F9, 11, 35, 04, 53, 8F, 51, FD, 8B, 1D, FA, 18, C9, 0B, 63, 60, 38, 31, 57, 2A, D8, E4, AD, E7, F9, 19, E8, 64, AE...
 
[+]

Code size:
352.5 KB (360,960 bytes)

The file installer7__7934_il13539.exe has been seen being distributed by the following URL.

Remove installer7__7934_il13539.exe - Powered by Reason Core Security