mgpuntoscommesse.it.exe

Microgame S.p.A.

The application mgpuntoscommesse.it.exe by Microgame S.p.A has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Microgame S.p.A.  (signed and verified)

MD5:
ec8cc991d4910cc357cf1cd824832916

SHA-1:
3cf3fc9413fa1d4b78ce8a5535210b071334525d

SHA-256:
bd41c2958f0a1b1560ee72fda7d893e007f0860287bd1ccec73a008c6cbe5abb

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the Solimba installer to bundle adware offers.

Analysis date:
4/26/2024 8:19:34 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
WIN.Adware.Solimba-3
0.98/18155

Reason Heuristics
Threat.Win.Reputation.IMP
16.12.9.12

Vba32 AntiVirus
Downware.Morstar
3.12.24.3

File size:
15.5 MB (16,273,944 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\downloads\mgpuntoscommesse.it.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/1/2013 2:00:00 AM

Valid to:
10/15/2015 1:59:59 AM

Subject:
CN=Microgame S.p.A., OU=Web, O=Microgame S.p.A., L=Benevento, S=Benevento, C=IT

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5E41ECAF27EC48B8D67DB85F5945B728

File PE Metadata
Compilation timestamp:
8/30/2011 5:46:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.21

CTPH (ssdeep):
393216:iFtRWH+c4KIUJpOQ2AuJTNoR5XNBlrp7OsHt4ppaXYRLGlgL9LgSs0kcfP:Wk+c4K973ulkp9qppaXYRlLxgf0kcH

Entry address:
0x4131

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 33, 43, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 34, 43, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 34, 43, 00, 56, A3, F4, 17, 43, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8B, 3B, 00, 00, A3, 50, 18, 43, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A9, B2, 40, 00, FF, 15, AC, 34, 43, 00, 83, EC, 14, C7, 44, 24, 04, AA, B2, 40, 00, C7...
 
[+]

Code size:
33.5 KB (34,304 bytes)

Remove mgpuntoscommesse.it.exe - Powered by Reason Core Security