paEzSetp.DLL

FilmFanatic Easy Installer

Mindspark Interactive Network

This library is part of the Mindspark toolbar which uses the Ask.com search property to install a web browser extension and modify the browser's search, home and new tab features in order to redirect web searches to the IAC property. The module paEzSetp.DLL by Mindspark Interactive Network has been detected as a potentially unwanted program by 13 anti-malware scanners.
Publisher:
FilmFanatic  (signed by Mindspark Interactive Network)

Product:
FilmFanatic Easy Installer

Version:
1, 2, 8, 4

MD5:
494a38ace46380f6307aa51a8afdca71

SHA-1:
342cc6bdcd134b74a27d4a0dbf9ec8344a17e912

SHA-256:
c8a16bcf095599ab4df2b6fb9183779458f37915fc213f28f0d72c01938d1fe3

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Part of the MyWebSearch/Mindspark/Ask web browser extension and toolbar.

Analysis date:
4/18/2024 3:18:07 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.MyWebSearch
7.1.1

avast!
Win32:FunWeb-J [PUP]
2014.9-140822

AVG
Skodna.Generic
2015.0.3374

Baidu Antivirus
PUA.Win32.MyWebSearch
4.0.3.14822

Comodo Security
ApplicUnwnt.Win32.AdWare.FunWeb.DA
16692

Dr.Web
9.0.1.0234

ESET NOD32
Win32/Toolbar.MyWebSearch (variant)
8.8640

Fortinet FortiGate
W32/Toolbar_MyWebSearch.Q
8/22/2014

NANO AntiVirus
Riskware.Win32.WebSearch.ddutde
0.28.2.61519

Panda Antivirus
Adware/WebSearch
14.08.22.10

Reason Heuristics
PUP.Installer.MindsparkInteractiveNetwork.I
14.8.22.22

SUPERAntiSpyware
Trojan.Agent/Gen-MyWebSearch
10405

VIPRE Antivirus
20086

File size:
246 KB (251,944 bytes)

Product version:
1, 2, 8, 4

Copyright:
Copyright © 2003, 2004, 2005, 2006, 2007, 2008, 2009, 2010, 2011, 2012

Original file name:
paEzSetp.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\filmfanaticei\installr\1.bin\paezsetp.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/9/2012 7:00:00 PM

Valid to:
5/6/2015 6:59:59 PM

Subject:
CN=Mindspark Interactive Network, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mindspark Interactive Network, L=White Plains, S=NewYork, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
098417F7EA6406EC7B320590E17A65B7

File PE Metadata
Compilation timestamp:
12/5/2012 12:01:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:C/agkxGqd/zRtXHHYZ1RiH95YJk+1QL6qqApWiJm/:CoGqVifiH97KGm/

Entry address:
0xDF26

Entry point:
FF, 74, 24, 0C, FF, 74, 24, 0C, FF, 74, 24, 0C, E8, E2, 31, FF, FF, C2, 0C, 00, FF, 15, 6C, 61, 01, 10, 33, C0, C3, A1, 10, E0, 01, 10, 56, 85, C0, 75, 13, FF, 74, 24, 08, 50, FF, 35, B0, DF, 01, 10, FF, 15, 1C, 61, 01, 10, 5E, C3, 8B, 0D, 14, E0, 01, 10, 8B, 15, 0C, E0, 01, 10, FF, 05, 14, E0, 01, 10, 23, D1, 8B, 34, 90, 8B, 44, 24, 08, 83, C0, 08, 50, 6A, 00, 56, FF, 15, 1C, 61, 01, 10, 85, C0, 74, 07, 89, 30, 83, C0, 08, 5E, C3, 33, C0, 5E, C3, 8B, 44, 24, 04, 0F, AF, 44, 24, 08, 50, E8, 9D, FF, FF, FF...
 
[+]

Entropy:
6.2380

Code size:
84 KB (86,016 bytes)

Remove paEzSetp.DLL - Powered by Reason Core Security