protectium_23_12-5a4bb8c6.exe

PINWID LTD

The application protectium_23_12-5a4bb8c6.exe by PINWID has been detected as adware by 21 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
PINWID LTD  (signed and verified)

Version:
1.0.0.0

MD5:
e52ee32d4b8f282cdb337261560e3d72

SHA-1:
2bdc435d31cad6bb8bb741649a7f273d41d02a9c

SHA-256:
c6491a6fefde3efdd2b9e4677f3e938d91200af845bf8d016acde964e9992947

Scanner detections:
21 / 68

Status:
Adware

Analysis date:
4/25/2024 1:31:20 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Smartbar.V
753

Agnitum Outpost
Trojan.DR.Agent
7.1.1

Avira AntiVirus
Adware/OfferBLVD.936480
7.11.200.132

avast!
Win32:Adware-gen [Adw]
2014.9-150113

AVG
Dropper.Generic9
2016.0.3231

Baidu Antivirus
Adware.Win32.OfferBLVD
4.0.3.15113

Bitdefender
Adware.Smartbar.V
1.0.20.65

Emsisoft Anti-Malware
Adware.Smartbar.V
8.15.01.13.11

F-Secure
Adware.Smartbar.V
11.2015-13-01_3

G Data
Adware.Smartbar
15.1.24

IKARUS anti.virus
not-a-virus:AdWare.OfferBLVD
t3scan.1.8.6.0

Kaspersky
not-a-virus:AdWare.Win32.OfferBLVD
14.0.0.2648

McAfee
Artemis!E52EE32D4B8F
5600.6887

MicroWorld eScan
Adware.Smartbar.V
16.0.0.39

nProtect
Adware.Smartbar.V
15.01.12.01

Panda Antivirus
Generic Suspicious
15.01.13.11

Quick Heal
AdWare.OfferBLVD.r5 (Not a Virus)
1.15.14.00

Reason Heuristics
PUP.PINWID.Z
15.1.13.11

Trend Micro House Call
TROJ_GEN.R04AC0EAC15
7.2.13

Trend Micro
TROJ_GEN.R04AC0EAC15
10.465.13

Vba32 AntiVirus
AdWare.OfferBLVD
3.12.26.3

File size:
914.5 KB (936,480 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (C) 2014

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\protectium_23_12-5a4bb8c6.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/4/2014 10:00:00 PM

Valid to:
2/5/2015 9:59:59 PM

Subject:
CN=PINWID LTD, O=PINWID LTD, STREET=14 Shenkar Arie, L=HERZLIYA, S=NA, PostalCode=46733, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D9AC9FC9A1B1E8FD63013E3CCE7B0578

File PE Metadata
Compilation timestamp:
11/24/2014 6:06:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:3XSOgdzvoZ2GPNKLp39CG/x/+suoPIobwzqZXs8Kevcg1vMwdghA6oGRqdaHH3rz:3CbrowG1KVQsxWsvDbw98HVMUGIdbcz

Entry address:
0xB4AA

Entry point:
E8, 56, 6C, 00, 00, E9, 89, FE, FF, FF, FF, 35, 90, 31, 42, 4F, FF, 15, 88, A0, 41, 4F, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 6E, 3E, 00, 00, 6A, 01, 6A, 00, E8, 62, 2E, 00, 00, 83, C4, 0C, E9, 27, 2E, 00, 00, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41...
 
[+]

Code size:
100 KB (102,400 bytes)

Remove protectium_23_12-5a4bb8c6.exe - Powered by Reason Core Security