pazera_free_flv_to_avi_converter.exe

Pazera Free FLV to AVI Converter

Pazera Jacek

The application pazera_free_flv_to_avi_converter.exe, “Pazera Free FLV to AVI Converter Setup ” by Pazera Jacek has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.pcwelt.de and multiple other hosts.
Publisher:
Pazera Jacek   (signed by Pazera Jacek)

Product:
Pazera Free FLV to AVI Converter

Description:
Pazera Free FLV to AVI Converter Setup

MD5:
b7f203d4004ef4aa95b4ba8a68378076

SHA-1:
fbec55544ad175212dbfdcf9d792e18e71d9f46d

SHA-256:
0a8d896ed7d6b85facfc71db8cf9d85d312f32c1d4b2bd04b64a5686c33d89e3

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/25/2024 11:25:42 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallMonetizer.AF
8.9651

Reason Heuristics
PUP.InstallMonetizer.Bundle (M)
16.3.10.15

File size:
10.4 MB (10,885,600 bytes)

Product version:
1.7

Copyright:
Copyright © 2013 Jacek Pazera, http://pazera-software.com

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
4/23/2013 7:27:14 AM

Valid to:
4/23/2014 7:27:14 AM

Subject:
E=jacekpazera@wp.pl, CN=Jacek Pazera, O=Pazera Jacek, C=PL

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
5103818FAACDB8E172D504668A9D9521

File PE Metadata
Compilation timestamp:
10/9/2012 10:48:22 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:tFfA0yMQyQIz4ZPfo+FTYWQsROH2Tsw+G3GREY+A9KCVkapwUPWaAKEu:tFfNuyPqdTYiQHIsA1gtwU5

Entry address:
0xF3BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 64, ED, 40, 00, E8, E8, 71, FF, FF, 33, C0, 55, 68, 89, FA, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 45, FA, 40, 00, 64, FF, 32, 64, 89, 22, A1, 48, 3B, 41, 00, E8, BE, F7, FF, FF, E8, 65, F3, FF, FF, 8D, 55, EC, 33, C0, E8, F7, C3, FF, FF, 8B, 55, EC, B8, 4C, 66, 41, 00, E8, 6A, 58, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 4C, 66, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
59 KB (60,416 bytes)

The file pazera_free_flv_to_avi_converter.exe has been seen being distributed by the following 3 URLs.

http://www.pcwelt.de/download_file?bid=281942

Remove pazera_free_flv_to_avi_converter.exe - Powered by Reason Core Security