installer_proshow_gold_5_0_3310_italian.exe

The application installer_proshow_gold_5_0_3310_italian.exe has been detected as a potentially unwanted program by 17 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from domseo.com.edgesuite.net and multiple other hosts.
MD5:
24f0fc18af89f8aa7490f18c2f3177c8

SHA-1:
ab8c5e40996e2bdc8d0ac88b61c480cf77f304b4

SHA-256:
366b4d7d7e48cc16564cfbe98942660341894b6d27127cda11ee4cdb49597690

Scanner detections:
17 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Analysis date:
4/19/2024 11:59:22 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Adware/Win32.FakeUtill
2014.08.10

AVG
Adware Generic_r
2015.0.3356

Baidu Antivirus
PUA.Win32.Vittalia
4.0.3.1499

Comodo Security
TrojWare.Win32.Agent.IEXT
19137

Dr.Web
Trojan.DownLoader11.22336
9.0.1.0252

ESET NOD32
Win32/Vittalia.M potentially unwanted application
8.7.0.302.0

Fortinet FortiGate
Riskware/Vittalia
9/9/2014

K7 AntiVirus
Trojan
13.183.13086

Malwarebytes
PUP.Optional.Vittalia
v2014.09.09.05

McAfee
Artemis!26CACBFFB6F8
5600.7012

NANO AntiVirus
Trojan.Win32.DownLoader11.ddsqax
0.28.2.61349

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.9.17

Rising Antivirus
PE:Trojan.Win32.Generic.171B31F9!387658233
23.00.65.14907

Sophos
Vittalia
4.98

Trend Micro House Call
Suspicious_GEN.F47V0810
7.2.252

VIPRE Antivirus
Threat.4782551
31208

File size:
4.2 MB (4,359,960 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\installer_proshow_gold_5_0_3310_italian.exe

File PE Metadata
Compilation timestamp:
2/28/2014 11:01:44 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:B/wBRswmv+TIAH6YBaL7dq6fV9GPzDve8+LtAL2v1OSQV1rDEJjN1obHC5WxaWtD:NwBRswbIQ6ddJ9f/LHOTDEBVy

Entry address:
0x2B6BC

Entry point:
E8, EC, 97, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 78, E4, 44, 00, E8, DE, 53, 00, 00, E8, F4, 44, 00, 00, 0F, B7, F0, 6A, 02, E8, 7F, 97, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 44, 78, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
257.5 KB (263,680 bytes)

The file installer_proshow_gold_5_0_3310_italian.exe has been seen being distributed by the following 2 URLs.

Remove installer_proshow_gold_5_0_3310_italian.exe - Powered by Reason Core Security