playnowradio.exe

Play now radio

Pay By Ads LTD

The application playnowradio.exe has been detected as adware by 15 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered by a time event. This file is typically installed with the program Play Now Radio by Montiera Technologies Ltd. which is a potentially unwanted software program. While running, it connects to the Internet address NY1WV3659 on port 80 using the HTTP protocol.
Publisher:
Pay By Ads LTD

Product:
Play now radio

Version:
1.3.0.0

MD5:
d1f1afea4ff87da0cc5abb749ce7018c

SHA-1:
b3d349e8c5676d6256f6f43f419ba265cfb0cc02

SHA-256:
9acd9ac8054607dfec056837fe15ccd1beffa850af1c44e4d0504c432d5c95af

Scanner detections:
15 / 68

Status:
Adware

Analysis date:
4/18/2024 11:12:28 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11127314
750

Baidu Antivirus
Adware.Win32.Montiera
4.0.3.15116

Bitdefender
Trojan.Generic.11127314
1.0.20.80

Dr.Web
Adware.Downware.2873
9.0.1.016

Emsisoft Anti-Malware
Trojan.Generic.11127314
8.15.01.16.01

ESET NOD32
Win32/Toolbar.Montiera (variant)
9.10164

Fortinet FortiGate
Riskware/Toolbar_Montiera
1/16/2015

F-Secure
Trojan.Generic.11127314
11.2015-16-01_6

G Data
Trojan.Generic.11127314
15.1.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.181.12846

Malwarebytes
PUP.Optional.Montiera
v2015.01.16.01

MicroWorld eScan
Trojan.Generic.11127314
16.0.0.48

Reason Heuristics
PUP.Task.PayByAds
15.1.16.1

VIPRE Antivirus
Trojan.Win32.Generic
31686

File size:
374 KB (382,976 bytes)

Product version:
1.3.0.0

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\playnowradio\playnowradio\1.3.4.1\playnowradio.exe

File PE Metadata
Compilation timestamp:
2/2/2014 10:13:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:BlcLpExNWk/KrshLTVj8YVkJfG5BvpztiezqkNZVPbPt+D9LIAUv+OwfYhOsY:BlKKxNWkir8Fj8YVkJu5BhticJnVrt+v

Entry address:
0x30E26

Entry point:
E8, E8, 6E, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 10, 53, 8B, 5D, 08, 56, 85, DB, 74, 11, 83, 7D, 0C, 00, 76, 11, 85, DB, 75, 23, 33, C0, E9, BC, 00, 00, 00, 83, 7D, 0C, 00, 74, EF, E8, 8A, 18, 00, 00, 6A, 16, 5E, 89, 30, E8, 2E, 18, 00, 00, 8B, C6, E9, A0, 00, 00, 00, FF, 75, 0C, 53, E8, A9, D1, FF, FF, 59, 59, 3B, 45, 0C, 72, 05, C6, 03, 00, EB, D5, 57, FF, 75, 10, 8D, 4D, F0, E8, FD, CB, FF, FF, 80, 3B, 00, 8B, FB, 8B, F3, 74, 63, 8A, 0F, 8B, 55, F4, 0F, B6, C1, 03, C2, 8A, 50, 1D, F6...
 
[+]

Entropy:
6.3370

Code size:
261 KB (267,264 bytes)

Scheduled Task
Task name:
Play Now Radio

Trigger:
Time (Next runs on 09/01/2003 at 1:19 AM)

Action:
playnowradio.exe mycmd


The file playnowradio.exe has been discovered within the following program.

Play Now Radio  by Montiera Technologies Ltd.
This potentially unwanted ad-supported program will bundled a number of adware applications on install including: Criteo DealPly Revenue hits Matomy Jolly wallet Ac plus 50OnRed Superfish Offersbar Thinkthank
www.playnowradio.com
73% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to sage.parklogic.com  (69.39.236.56:80)

TCP (HTTP):
Connects to ec2-54-72-9-115.eu-west-1.compute.amazonaws.com  (54.72.9.115:80)

TCP (HTTP):
Connects to NY1WV3659  (204.145.82.27:80)

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.4.90:80)

Remove playnowradio.exe - Powered by Reason Core Security