kmspico windows and office activator 10.0.5 alpha is here![latest].exe

Stepan Rybin

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application kmspico windows and office activator 10.0.5 alpha is here![latest].exe by Stepan Rybin has been detected as adware by 23 anti-malware scanners. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Stepan Rybin  (signed and verified)

MD5:
25fce0aa68d71067ed5db05f2cad06ac

SHA-1:
7049466f9b6bc5414ee0f9cba9d7ac2162bdb1ee

SHA-256:
c5071c7f94a453fc396bff160050dace0c4b4a5831a5a802d1dc6009a5b78293

Scanner detections:
23 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/26/2024 7:32:14 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.MPLug.HH
6324531

AhnLab V3 Security
PUP/Win32.MultiPlug
2015.03.29

Avira AntiVirus
PUA/MultiPlug.11245
3.6.1.96

avast!
Win32:Adware-gen [Adw]
150319-1

AVG
Generic6
2016.0.3156

Bitdefender
Adware.MPLug.HH
1.0.20.435

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.MultiPlug.YTRA
21575

Dr.Web
Trojan.Crossrider1.22656
9.0.1.05190

Emsisoft Anti-Malware
Adware.MPLug.HH
9.0.0.4799

ESET NOD32
Win32/Adware.MultiPlug.GD (variant)
9.11392

F-Secure
Adware.MPLug.HH
5.13.68

G Data
Adware.MPLug.HH
15.3.25

K7 AntiVirus
Trojan
13.202.15414

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

Malwarebytes
PUP.Optional.Unizeto
v2015.03.28.08

McAfee
MultiPlug-FXC
5600.6812

MicroWorld eScan
Adware.MPLug.HH
16.0.0.261

nProtect
Adware.MPLug.HH
15.03.27.01

Reason Heuristics
PUP.WebPick
15.3.28.20

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15326

Sophos
MultiPlug
4.98

Vba32 AntiVirus
suspected of Heur.Malware-Cryptor.Multiplug
3.12.26.3

File size:
476.7 KB (488,136 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\application data\{97d926fe-63bf-4234-97d9-926fe63b9bf9}\kmspico windows and office activator 10.0.5 alpha is here![latest].exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
6/27/2014 11:37:40 AM

Valid to:
6/27/2015 11:37:40 AM

Subject:
E=rybin.step@yandex.ru, CN=Stepan Rybin, O=Stepan Rybin, C=UA

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
47154C2151E9EB8DFA42C2C9E45BFC6C

File PE Metadata
Compilation timestamp:
10/29/2012 4:00:53 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:Z/nYRUOOD6Nd9yjzWRLggY6czaZMrSEb1sKrHpo67wa0Jp+xcOH2BEXKkjlOoYcc:5+UdDKd9yWRLtxMmK1Fr267s+xcOOkbG

Entry address:
0x467CB

Entry point:
E8, CF, 1F, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 70, 12, 45, 00, E8, DF, 24, 00, 00, E8, 9C, 21, 00, 00, 0F, B7, F0, 6A, 02, E8, 62, 1F, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 28, 02, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4408

Code size:
302.5 KB (309,760 bytes)