mitchell.on.demand.5.8.2._10924_i67359653_il345.exe

Windows Desktop Gadgets

A4 TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application mitchell.on.demand.5.8.2._10924_i67359653_il345.exe, “Windows Desktop Gadgets” by A4 TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Microsoft Corporation  (signed by A4 TOV)

Product:
Microsoft® Windows® Operating System

Description:
Windows Desktop Gadgets

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
07b5db1ad8e33fd9e9788189baa85bc9

SHA-1:
fc4bb6702d82de5afb0e17453a15e383bd7af9c4

SHA-256:
cf500fab5936de22a7886ce6e76d1e9ad079437c3dfa69efd2d89026b04e329d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/13/2024 12:09:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.3.9.2

File size:
2.2 MB (2,282,464 bytes)

Product version:
1.0.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
sidebar.EXE.MUI

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\mitchell.on.demand.5.8.2\mitchell.on.demand.5.8.2._10924_i67359653_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/17/2015 2:00:00 AM

Valid to:
9/17/2016 1:59:59 AM

Subject:
CN=A4 TOV, O=A4 TOV, STREET=Bud. 29 vul.Shchorsa, L=Kiev, S=Kiev, PostalCode=01010, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
27FB5DEC4CCFD4F3CF69A6B639C6AD4B

File PE Metadata
Compilation timestamp:
10/4/2015 10:52:44 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x28CB84

Entry point:
68, 03, CC, 72, A2, E8, 51, B1, FE, FF, 00, 00, 43, 6C, 6F, 73, 65, 53, 65, 72, 76, 69, 63, 65, 48, 61, 6E, 64, 6C, 65, 00, 21, 22, EC, 00, 75, 43, B2, 12, FD, 47, 36, 80, 13, FF, 90, 33, 4C, 12, FF, 09, 34, 74, ED, 02, 16, 13, BA, 12, FD, D5, AB, 9B, 13, FF, 5F, 8D, 52, ED, 02, 81, CB, 54, 12, FD, 73, F2, 2C, 13, FF, 58, 29, 15, ED, 02, 13, C7, F7, 12, FD, 67, 54, 6E, 13, FF, BE, 0B, 8C, ED, 02, 13, DC, B6, 36, 03, 92, 97, FD, 1F, B3, F7, 97, FF, 62, 52, 08, B0, 03, 5B, 69, 02, 65, A6, 05, 69, 00, 4C, 75...
 
[+]

Code size:
1.9 MB (2,013,696 bytes)