profile viewer - 5.exe

Facebook Profile Viewer installer

rinim

The application profile viewer - 5.exe, “Deploy Facebook Profile Viewer browsers extension” by rinim has been detected as a potentially unwanted program by 30 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from project-dont-download.googlecode.com.
Publisher:
rinim  (signed and verified)

Product:
Facebook Profile Viewer installer

Description:
Deploy Facebook Profile Viewer browsers extension

Version:
1.3.4

MD5:
814837294bc34f288e31637bab955e6c

SHA-1:
d0626e5dc296904360400dc529a6ca57fa7e81ef

SHA-256:
de7e13991bbbe84c6470c070d675ceff1f07b3ff3c545ca53b33ebbc1790b9c9

Scanner detections:
30 / 68

Status:
Potentially unwanted

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage).

Analysis date:
4/26/2024 10:26:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.9021806
563

Agnitum Outpost
Riskware.ScrambleWrapper
7.1.1

Avira AntiVirus
ADWARE/CrossRider.Gen2
7.11.215.206

AVG
Clicker
2016.0.3041

Baidu Antivirus
Trojan.JS.Clicker
4.0.3.15722

Bitdefender
Trojan.Generic.9021806
1.0.20.1015

Comodo Security
Heur.Suspicious
21360

Dr.Web
Trojan.AVKill.30538
9.0.1.0203

Emsisoft Anti-Malware
Trojan.Generic.9021806
8.15.07.22.06

ESET NOD32
Win32/TrojanDropper.Delf.OGG (variant)
9.11297

Fortinet FortiGate
W32/Agent.ABOE!tr
7/22/2015

F-Secure
Trojan.Generic.9021806
11.2015-22-07_4

G Data
Trojan.Generic.9021806
15.7.25

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.8.6.0

K7 AntiVirus
Riskware
13.200.15211

Kaspersky
Trojan-Clicker.JS.Agent
14.0.0.1699

Malwarebytes
Spyware.Password
v2015.07.22.06

McAfee
Trojan-FCJF!814837294BC3
5600.6697

Microsoft Security Essentials
Trojan:Win32/Carfekab.gen!A
1.1.11400.0

MicroWorld eScan
Trojan.Generic.9021806
16.0.0.609

NANO AntiVirus
Riskware.Win32.CrossRider.dgyruv
0.30.0.296

Norman
Suspicious_Gen2.VPYZG
11.20150722

nProtect
Trojan.Generic.9021806
15.03.10.01

Panda Antivirus
Trj/CI.A
15.07.22.06

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Sophos
Troj/Agent-ABOE
4.98

Trend Micro House Call
TROJ_GEN.R047C0CC815
7.2.203

Trend Micro
TROJ_GEN.R047C0CC815
10.465.22

VIPRE Antivirus
Trojan.Win32.Clicker
38292

Zillya! Antivirus
Trojan.Agent.Win32.474172
2.0.0.2093

File size:
4.3 MB (4,522,176 bytes)

Product version:
1.3.4

Copyright:
Facebook Inc.

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\profile viewer - 5.exe

Digital Signature
Signed by:

Authority:
rinim

Valid from:
1/1/2013 3:00:00 AM

Valid to:
1/1/2019 3:00:00 AM

Subject:
CN=rinim

Issuer:
CN=rinim

Serial number:
3D9394A4D3EC5E8A45B5171E76F8199A

File PE Metadata
Compilation timestamp:
3/29/2013 11:03:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:U7Ar71MSDvsSgwDJWFPRF4V5sUheW1TxBq/j3g:U7MMSDv/jgL65sUhr57q/jQ

Entry address:
0x1F3A0

Entry point:
55, 8B, EC, 81, C4, D0, FE, FF, FF, 53, 56, 57, 33, C0, 89, 45, D0, 89, 45, EC, 89, 45, D8, 89, 45, D4, B8, 54, EC, 41, 00, E8, 30, 77, FE, FF, 33, C0, 55, 68, 2D, F5, 41, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, B9, F4, 41, 00, 64, FF, 30, 64, 89, 20, B8, 44, F5, 41, 00, E8, 72, D0, FF, FF, B8, 74, F5, 41, 00, E8, 68, D0, FF, FF, B8, A4, F5, 41, 00, E8, 5E, D0, FF, FF, 8D, 45, EC, 50, 8D, 45, D8, E8, 16, B0, FF, FF, 8B, 45, D8, 89, 45, DC, C6, 45, E0, 0B, 8D, 55, D4, B8, 04, 00, 00, 00, E8, 1F, B6, FF...
 
[+]

Entropy:
7.9714

Developed / compiled with:
Microsoft Visual C++

Code size:
121.5 KB (124,416 bytes)

The file profile viewer - 5.exe has been seen being distributed by the following URL.

Remove profile viewer - 5.exe - Powered by Reason Core Security