ssdl70680.exe

0.9.2.0

AVSoftware EOOD

The software installer uses the StartInstall.com download manager which bundles additional adware offers (toolbars and utilities such as the SafeSearch toolbar) during setup. The application ssdl70680.exe, “SafeSearch Setup ” by AVSoftware EOOD has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. It is also typically executed from the user's temporary directory.
Publisher:
AVSoftware   (signed by AVSoftware EOOD)

Product:
0.9.2.0

Description:
SafeSearch Setup

Version:
0.9.2.0

MD5:
ec11a8d6073ac38b46edb12857ed2a49

SHA-1:
c41c1039e123654928232d57a1e2463d1bde252d

SHA-256:
74a7b3f6ec5b3f7b63b2639cf39e47d16b97e58a6efec4993f0b47d8ee0215fb

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 10:18:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AVSoftware EOOD.AVSoftwareEOOD.Installer (M)
16.2.10.22

File size:
3 MB (3,143,600 bytes)

Product version:
0.9.2.0

Copyright:
Copyright 2011-2012, AVSoftware LLC

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\ssdl70680.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/4/2013 7:00:00 PM

Valid to:
6/3/2016 7:59:59 PM

Subject:
CN=AVSoftware EOOD, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AVSoftware EOOD, L=Sofia, S=Sofia, C=BG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0EB840FECC84AE6DCA7A92109E2314ED

File PE Metadata
Compilation timestamp:
7/9/2012 9:41:29 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:t2gIKFsiAcA/kulr1XJqz1SfGYoVkjA0yjgl0sAMdbfowoGiNOx6U3+VeOvA:8rKFCcADR1XASeYoVkjA1MdLoLGLx6UP

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B8, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 56, EC, FF, FF, E8, FD, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, E8, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, D6, 41, 00, B2, 01...
 
[+]

Entropy:
7.9840

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

Remove ssdl70680.exe - Powered by Reason Core Security