multiplyroi_cheat-engine.exe

Groovecom

The application multiplyroi_cheat-engine.exe by Groovecom has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from files4.mirror6.net and multiple other hosts.
Publisher:
Groovecom  (signed and verified)

MD5:
cf09b6200954cedfab2aad17e4a3487a

SHA-1:
47a0c7383d716159727487ab54007af35b2139ab

SHA-256:
4bd0885a23fee5986a8c6c800604d815c2b5eb2c005edf847bbc3dc4d0cff22e

Scanner detections:
17 / 68

Status:
Adware

Analysis date:
4/26/2024 12:53:45 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.I
861

Avira AntiVirus
APPL/Downloader.Gen
7.11.174.236

avast!
Adware-OH [Adw]
2014.9-140926

AVG
Generic
2015.0.3339

Bitdefender
Application.Bundler.I
1.0.20.1345

Clam AntiVirus
Win.Adware.Agent-6650
0.98/19305

Dr.Web
Adware.Downware.2220
9.0.1.0269

Emsisoft Anti-Malware
Application.Bundler
14.09.26

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
8.7.0.302.0

F-Secure
Adware:W32/WebInstallBundle
11.2014-26-09_6

G Data
Application.Bundler
14.9.24

herdProtect (fuzzy)
2014.12.8.19

MicroWorld eScan
Application.Bundler.I
15.0.0.807

NANO AntiVirus
Riskware.Win32.Downware.crgjbr
0.28.2.61721

Reason Heuristics
PUP.Groovecom.Y
14.9.27.0

Sophos
Download Admin
4.98

VIPRE Antivirus
Threat.4783369
32210

File size:
609.1 KB (623,712 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\multiplyroi_cheat-engine.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/25/2014 6:00:00 PM

Valid to:
2/25/2017 5:59:59 PM

Subject:
CN=Groovecom, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Groovecom, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0C8ED38817030CF19BE6EE39708627BA

File PE Metadata
Compilation timestamp:
6/22/2012 1:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:MrdiMybLCUVSG+u46LDu/eoABSafzNsZGwEL:M+bLcG+Ivu9ABrLWZpU

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.9692

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file multiplyroi_cheat-engine.exe has been seen being distributed by the following 3 URLs.

Remove multiplyroi_cheat-engine.exe - Powered by Reason Core Security