sopcast-3.5.0.exe

Meta Installer LLC

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application sopcast-3.5.0.exe by Meta Installer has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. According to Microsoft Security Essentials, the software bundles and installs the Lolliport adware program (in many cases without a user's knowledge). It usually gets on your PC as an installer for a free game or application. This software bundler installs other potentially unwanted software, including Adware:Win32/Lollipop, at the same time as other software.
Publisher:
Meta Installer LLC  (signed and verified)

MD5:
f3173a78315a94c4e9280374923e3135

SHA-1:
adc7adc005f8169f518960c0f2c32515a9193ced

SHA-256:
918e8ea013949d45aedd065b0284aa68ca18de1e9bd40305aca1d8efa02caddf

Scanner detections:
9 / 68

Status:
Adware

Explanation:
This software bundler installs other potentially unwanted software, including Adware:Win32/Lollipop during isntallation without a user's consent.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 10:21:20 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Bbylon
4.0.3.14730

Dr.Web
Adware.Downware.441
9.0.1.0211

ESET NOD32
Win32/Adware.Lollipop
8.9570

Fortinet FortiGate
W32/Toolbar.BABYLON
7/30/2014

herdProtect (fuzzy)
2014.9.10.6

Microsoft Security Essentials
SoftwareBundler:Win32/Lolliport
1.10401

Reason Heuristics
PUP.MetaInstaller.O
14.8.7.21

SUPERAntiSpyware
Adware.Lollipop/Variant
10453

VIPRE Antivirus
Lollipop
27596

File size:
270.6 KB (277,144 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\sopcast-3.5.0.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/6/2012 6:17:45 AM

Valid to:
2/16/2013 7:59:09 PM

Subject:
CN=Meta Installer LLC, O=Meta Installer LLC, L=Wilmington, S=DE, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
043DEA1F43D249

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:pe34p2CmjDVzjiNVQVboV69ld8BUcVOkc4Wc40yUw:5Cj1jaVQVboOld8jVOkcEw

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove sopcast-3.5.0.exe - Powered by Reason Core Security