kmspico v9 0 activador de windows y office.exe

Alexey Kurilenko

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application kmspico v9 0 activador de windows y office.exe by Alexey Kurilenko has been detected as adware by 24 anti-malware scanners. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is also typically executed from the user's temporary directory.
Publisher:
Alexey Kurilenko  (signed and verified)

MD5:
873cdc84657e43f53a5a8c02bc148a03

SHA-1:
e904a46d9228dc938ada9828415b68ced15475ed

SHA-256:
373236643f2505b52291948bd859b6d00ea2c43b65f886924fbbc6e5a2746778

Scanner detections:
24 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/19/2024 10:03:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.MultiPlug.GI
6324531

AhnLab V3 Security
PUP/Win32.MultiPlug
2015.03.29

Avira AntiVirus
PUA/Multiplug.aob
3.6.1.96

avast!
Win32:Agent-AUVV [Trj]
150320-0

AVG
Generic6
2016.0.3156

Bitdefender
Adware.MultiPlug.GI
1.0.20.435

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Crossrider1.22966
9.0.1.05190

Emsisoft Anti-Malware
Adware.MultiPlug.GI
9.0.0.4799

ESET NOD32
Win32/Adware.MultiPlug.FU (variant)
9.11392

F-Prot
W32/S-1f722880
v6.4.7.1.166

F-Secure
Adware.MultiPlug.GI
5.13.68

G Data
Adware.MultiPlug.GI
15.3.25

K7 AntiVirus
Unwanted-Program
13.202.15414

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

McAfee
Program.MultiPlug-FWS
16.8.708.2

MicroWorld eScan
Adware.MultiPlug.GI
16.0.0.261

NANO AntiVirus
Riskware.Win32.MultiPlug.dpgcmn
0.30.8.659

nProtect
Adware.MultiPlug.GI
15.03.27.01

Reason Heuristics
PUP.WebPick
15.3.28.21

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15326

Sophos
MultiPlug
4.98

Vba32 AntiVirus
SScope.Adware.MultiPlug
3.12.26.3

VIPRE Antivirus
Threat.4786450
38552

File size:
825.4 KB (845,176 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\temp\kmspico v9 0 activador de windows y office.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/17/2014 9:20:17 AM

Valid to:
6/17/2015 9:20:17 AM

Subject:
E=Alexey.kurilenko@hotmail.com, CN=Alexey Kurilenko, O=Alexey Kurilenko, C=RU

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
15D51642691B3EE20985639A8FE865DD

File PE Metadata
Compilation timestamp:
6/18/2013 2:06:04 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:nIFj19uXpa0oswo+AhgtGElDpC0XxarDM:nIFR9cpSo+nlVC0g8

Entry address:
0xB1A90

Entry point:
E8, 40, 13, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, A0, 4E, 4C, 00, E8, 4A, 18, 00, 00, E8, 0D, 15, 00, 00, 0F, B7, F0, 6A, 02, E8, D3, 12, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 82, 02, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
731 KB (748,544 bytes)