kmspico v8 7 activator for windows and_10924_i13118491_il345.exe

Runner Utility

BERSHNET LLC

The application kmspico v8 7 activator for windows and_10924_i13118491_il345.exe by BERSHNET has been detected as adware by 23 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Dummy, Ltd.  (signed by BERSHNET LLC)

Product:
Runner Utility

Version:
1.0.0.187

MD5:
674853ccdbd3949c7dd7d769a65525ac

SHA-1:
d7a5a1f6c985ce53bf5310b91ffccd36250045f6

SHA-256:
d005356effd85a20f287ada017a09ec4fa0641d17385c56ee3a46af6d1f71dae

Scanner detections:
23 / 68

Status:
Adware

Analysis date:
4/19/2024 7:56:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Jatif.320
617

AhnLab V3 Security
PUP/Win32.LoadMoney
2015.05.29

Avira AntiVirus
ADWARE/Amonetize.Gen7
8.3.1.6

avast!
Win32:Amonetize-JO [PUP]
2014.9-150528

AVG
Generic
2016.0.3095

Bitdefender
Gen:Variant.Application.Jatif.320
1.0.20.740

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.LoadMoney.IARS
22258

Dr.Web
Trojan.Amonetize
9.0.1.0148

ESET NOD32
Win32/Amonetize.DW potentially unwanted (variant)
9.11700

F-Prot
W32/S-53544127
v6.4.7.1.166

F-Secure
Gen:Variant.Application.Jatif
11.2015-28-05_5

G Data
Gen:Variant.Application.Jatif.320
15.5.25

K7 AntiVirus
Unwanted-Program
13.204.16062

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.1971

Malwarebytes
PUP.Optional.Amonetize
v2015.05.28.05

MicroWorld eScan
Gen:Variant.Application.Jatif.320
16.0.0.444

Panda Antivirus
Trj/Genetic.gen
15.05.28.05

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1015

Quick Heal
PUA.Bershnetll.Gen
5.15.14.00

Reason Heuristics
PUP.BERSHNET
15.5.28.13

Sophos
Amonetize
4.98

VIPRE Antivirus
Amonetize
40632

File size:
1.5 MB (1,539,088 bytes)

Product version:
1.0.0.187

Copyright:
Copyright (C) 2013

Original file name:
runner.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\kmspico v8 7 activator for windows and_10924_i13118491_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/6/2015 8:00:00 AM

Valid to:
2/7/2016 7:59:59 AM

Subject:
CN=BERSHNET LLC, O=BERSHNET LLC, STREET="st. 600-richya b.66, of.10", L=Vinnitsya, S=Vinnitskaya, PostalCode=21027, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E2D6C6F8DDF832E09DCF766B299AD2A9

File PE Metadata
Compilation timestamp:
5/29/2015 1:03:08 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:i7C5qEHmOQiZ/g/q/HuMkm/PhmeWO5Delg083LkaubPX4p5YvrcKxPc+Vk:i7C5PHmFDq/TFhSUDex8vubPX4p5+xP0

Entry address:
0x282D12

Entry point:
60, E8, 80, 65, 08, 00, 67, D9, 54, FD, 72, 7C, 0C, FE, B5, 1B, D6, 48, CE, 64, E2, 60, A6, 25, 3F, 9D, A8, 74, 7F, E3, AA, 52, 87, 5B, 15, B0, 44, EB, 99, 4C, 90, 52, 13, FB, 4D, 4D, 73, DC, AE, 20, 54, CA, 7F, 3E, A8, 2E, 5D, 83, 05, BF, DC, 1A, AC, 36, C1, 3B, B8, 57, 1A, 81, FC, D3, E0, 8E, A0, 26, 31, BD, 0A, F6, 89, 01, 9B, 55, 70, 66, FC, 72, 2E, BE, 50, 11, FF, C1, 71, 07, B5, 1E, 4F, 91, C6, FF, B4, C2, A4, BF, C9, 5A, A0, 85, 8D, 92, F1, E3, A8, 36, B0, 1E, D3, 59, EC, 91, B4, 64, B2, A8, 5A, 51...
 
[+]

Entropy:
7.9945

Packer / compiler:
ASPack v1.08.04

Code size:
187.5 KB (192,000 bytes)