msb58e.exe

Yordan Damyanov

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application msb58e.exe by Yordan Damyanov has been detected as adware by 4 anti-malware scanners. This file is typically installed with the program ARhome by Vonteera LLC which is a potentially unwanted software program. It is also typically executed from the user's temporary directory.
Publisher:
Yordan Damyanov  (signed and verified)

MD5:
52396265fb3d989bb8381103528e390d

SHA-1:
188b13667d94781859a35b700510392e2b9f64ff

SHA-256:
b80e1296805a891ecbdd39849f2c3b98fb5081b767a0cdbf15508568f4bd1acb

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
4/25/2024 1:31:47 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.Vonteera
2014.08.28

Bitdefender
Gen:Variant.Graftor.149936
1.0.20.1205

IKARUS anti.virus
PUA.Vonteera
t3scan.1.7.5.0

Reason Heuristics
PUP.YordanDamyanov.G
14.8.29.2

File size:
1.4 MB (1,512,896 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\msb58e.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/7/2013 3:00:00 AM

Valid to:
10/8/2015 2:59:59 AM

Subject:
CN=Yordan Damyanov, O=Yordan Damyanov, STREET=19 Dobri Voinikov Str, L=Sofia, S=Sofia, PostalCode=1000, C=BG

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FEEF0D77D0AC7E55D4E7707B384AC901

File PE Metadata
Compilation timestamp:
8/25/2014 8:45:09 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:tjWEQi3c0k2EjVkVJgeN9l0sKdCey+nRf2KMbwMPddZTWv7GOv5WcqMTeiF:tjWEQik8T1SC2nRf2TwWdWTJYcQ8

Entry address:
0xC104

Entry point:
E8, A6, 52, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 1A, 12, 00, 00, 3B, 0D, 50, 76, 42, 00, 75, 02, F3, C3, E9, 22, 53, 00, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, FF, 15, 0C, E1, 41, 00, 85, C0, 75, 08, FF, 15, 74, E0, 41, 00, EB, 02, 33, C0, 85, C0, 74, 0C, 50, E8, AB, 3D, 00, 00, 59, 83, C8, FF, 5D, C3, 33, C0, 5D, C3, 6A, 0C, 68, 68, 49, 42, 00, E8, 5C, 50, 00, 00, 33, FF, 89, 7D, E4, 33, C0, 8B, 5D, 08, 3B, DF, 0F, 95, C0, 3B, C7, 75, 14, E8, 57, 3D, 00, 00, C7, 00, 16, 00, 00, 00, E8, 3F...
 
[+]

Entropy:
7.8413  (probably packed)

Code size:
116 KB (118,784 bytes)

The file msb58e.exe has been discovered within the following program.

ARhome  by Vonteera LLC
ARhome is a potentially unwanted web browser extension that is ad-supported and will display various popup and banner ads as well as modify the user's web browser search and home page settings.
www.adnetwork100.info
82% remove it
 
Powered by Should I Remove It?

Remove msb58e.exe - Powered by Reason Core Security