playnowradio.exe

Play now radio

Pay By Ads LTD

The application playnowradio.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered by a time event. This file is typically installed with the program Play Now Radio by Montiera Technologies Ltd. which is a potentially unwanted software program. While running, it connects to the Internet address cds17.gru.llnw.net on port 80 using the HTTP protocol.
Publisher:
Pay By Ads LTD

Product:
Play now radio

Version:
1.3.0.0

MD5:
ca31ad6f6cc1aedd0196ff174b22bf5e

SHA-1:
2af09e40d1b97d9a32d257612e797902a389440c

SHA-256:
2a27d94f41e4526e104a38facddfe1f48b97871b4e3d144581ab929d511048e4

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
2/23/2014 2:48:25 AM UTC  (six months ago)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Montiera
4.0.3.14222

ESET NOD32
Win32/Toolbar.Montiera (variant)
8.9455

Malwarebytes
PUP.Optional.Montiera
v2014.02.22.09

Trend Micro House Call
TROJ_GEN.F47V0219
7.2.53

File size:
387 KB (396,288 bytes)

Product version:
1.3.0.0

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\user\appdata\roaming\playnowradio\playnowradio\1.3.4.8\playnowradio.exe

File PE Metadata
Compilation timestamp:
2/17/2014 4:35:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:Ma7w6EM9PSCOq8ZWhunGizJ69Z1HDzW6cxlA:REHCdM

Entry address:
0x32B56

Entry point:
E8, E8, 6E, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 10, 53, 8B, 5D, 08, 56, 85, DB, 74, 11, 83, 7D, 0C, 00, 76, 11, 85, DB, 75, 23, 33, C0, E9, BC, 00, 00, 00, 83, 7D, 0C, 00, 74, EF, E8, 8A, 18, 00, 00, 6A, 16, 5E, 89, 30, E8, 2E, 18, 00, 00, 8B, C6, E9, A0, 00, 00, 00, FF, 75, 0C, 53, E8, A9, D1, FF, FF, 59, 59, 3B, 45, 0C, 72, 05, C6, 03, 00, EB, D5, 57, FF, 75, 10, 8D, 4D, F0, E8, FD, CB, FF, FF, 80, 3B, 00, 8B, FB, 8B, F3, 74, 63, 8A, 0F, 8B, 55, F4, 0F, B6, C1, 03, C2, 8A, 50, 1D, F6...
 
[+]

Code size:
269 KB (275,456 bytes)

Scheduled Task
Task name:
$dMM6KqyKu+JyN+{$

Trigger:
Time (Next runs on 22/02/2014 at 23:54)

Action:
playnowradio.exe mycmd


The file playnowradio.exe has been discovered within the following program.

Play Now Radio  by Montiera Technologies Ltd.
This potentially unwanted ad-supported program will bundled a number of adware applications on install including: Criteo DealPly Revenue hits Matomy Jolly wallet Ac plus 50OnRed Superfish Offersbar Thinkthank
www.playnowradio.com
73% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to yv-in-f95.1e100.net  (74.125.21.95:80)

TCP (HTTP):
Connects to ny1wv3280.xglobe.net  (204.145.82.20:80)

TCP (HTTP):
Connects to mpr2.ngd.vip.gq1.yahoo.com  (216.39.55.13:80)

TCP (HTTP):
Connects to mpr1.ngd.vip.ch1.yahoo.com  (217.163.21.34:80)

TCP (HTTP SSL):
Connects to https-95-140-239-0.par.llnw.net  (95.140.239.0:443)

TCP (HTTP):
Connects to float.1292.bm-impbus.prod.fra1.adnexus.net  (37.252.170.41:80)

TCP (HTTP):
Connects to float.1171.bm-impbus.prod.sin1.adnexus.net  (68.67.176.3:80)

TCP (HTTP SSL):
Connects to edge-star-shv-06-ams2.facebook.com  (31.13.64.65:443)

TCP (HTTP):
Connects to cds313.par.llnw.net  (87.248.223.223:80)

TCP (HTTP):
Connects to cds19.hkg.llnw.net  (203.77.189.18:80)

TCP (HTTP):
Connects to cds184.par.llnw.net  (87.248.223.20:80)

TCP (HTTP):
Connects to cds17.gru.llnw.net  (69.164.44.151:80)

TCP (HTTP):
Connects to cds11.gru.llnw.net  (69.164.44.145:80)

TCP (HTTP):
Connects to cdn-208-111-148-6.sjc.llnw.net  (208.111.148.6:80)

There are 4 known variations of playnowradio.exe by Pay By Ads LTD.

1 / 68      (inconclusive)
playnowradio.exe  1.3.0.0  (9d2b7801bc5e97fb29dbc3b26cfc09cb3e334c50)

0 / 68
playnowradio.exe  1.3.0.0  (b3d349e8c5676d6256f6f43f419ba265cfb0cc02)

4 / 68      (PUP)
playnowradio.exe  1.3.0.0  (74ca0b34c48d8842c55e225f3c361e7259935017)

0 / 68
playnowradio.exe  1.3.0.0  (60f113f79513bde957da19388a38a93eb2d795bd)

4 / 68      (PUP)
adworld.exe  (7cc04257a8806b2efdb392f12ddee2d673edbd16)

Detection Incidence by Country