kmsnano 24 perfect activator for widnows download__13150_i1607258421_il44821.exe

LLC DE PROEKT

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application kmsnano 24 perfect activator for widnows download__13150_i1607258421_il44821.exe by LLC DE PROEKT has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. It runs as a scheduled task under the Windows Task Scheduler. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
LLC DE PROEKT  (signed and verified)

MD5:
db79ab57d951a8980ad91b582699e027

SHA-1:
9be9acde0b4c01500aed298f6026e24e105ca6f5

SHA-256:
7e14f909a67ce1f97281c1f094c337c87317ac8e4f991237bc8afadfdcd822b7

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 7:19:40 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Amonetiz
2015.08.28

Avira AntiVirus
ADWARE/Amonetize.kpb
8.3.2.2

Arcabit
PUP.Adware.Amonetize.eal
1.0.0.425

AVG
Generic
2016.0.3001

Bkav FE
W32.HfsAdware
1.3.0.7133

ESET NOD32
Win32/Amonetize.HM potentially unwanted (variant)
9.12164

F-Prot
W32/Amonetize.X.gen
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.2017031

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
14.0.0.1501

Malwarebytes
v2015.08.30.08

NANO AntiVirus
Riskware.Win32.Amonetize.dvccyq
0.30.24.3283

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Amonetize.DEPROEKT.Bundler (M)
15.8.30.20

Vba32 AntiVirus
Signed-AdWare.Amonetize
3.12.26.4

VIPRE Antivirus
Amonetize
43270

File size:
723 KB (740,368 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Amonetize Downloader

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/6/2015 2:00:00 AM

Valid to:
5/6/2016 1:59:59 AM

Subject:
CN=LLC DE PROEKT, O=LLC DE PROEKT, STREET="str. Petropavlovska, 3", L=Simferopol, S=AR Krym, PostalCode=95000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2D675A924C3DAB51C8060B92453C4912

File PE Metadata
Compilation timestamp:
8/28/2015 9:11:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:qrOVrIAAX3wW6nUG/m90kY15FmqCr7G4HBbCrFIa9kGyMVFKfwx8:2OdsXg/n5/EY1bc+EbCBIEDdVFkv

Entry address:
0x11729

Entry point:
E8, 02, 49, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, A1, 04, 5E, 43, 00, 85, C0, 75, 1D, E8, 18, 23, 00, 00, 6A, 1E, E8, 6E, 23, 00, 00, 68, FF, 00, 00, 00, E8, 67, 28, 00, 00, A1, 04, 5E, 43, 00, 59, 59, 8B, 4D, 08, 85, C9, 75, 01, 41, 51, 6A, 00, 50, FF, 15, 6C, 90, 42, 00, 5D, C3, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 77, 6F, 53, 57, A1, 04, 5E, 43, 00, 85, C0, 75, 1D, E8, D0, 22, 00, 00, 6A, 1E, E8, 26, 23, 00, 00, 68, FF, 00, 00, 00, E8, 1F, 28, 00, 00, A1, 04, 5E, 43, 00, 59, 59, 85, F6, 74, 04, 8B...
 
[+]

Entropy:
7.6653

Code size:
160 KB (163,840 bytes)

Scheduled Task
Task name:
{5D41C45C-3F67-4053-B797-D575C6620294}

Trigger:
Registration (Runs on registration)