sweetpcfix.exe

SweetPCFix

SweetIM Technologies Ltd

This is part of the Montera web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application sweetpcfix.exe by SweetIM Technologies has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from cdn.download.sweetpacks.com and multiple other hosts.
Publisher:
SweetPacks   (signed by SweetIM Technologies Ltd)

Product:
SweetPCFix

Version:
SweetPCFix

MD5:
117b4d878cc6e95c0f3481b3264d48da

SHA-1:
4186205a87371a8d76ea3bdd071fd6c2d505d6fd

SHA-256:
54578f018a501a48058b154a5f9f541ecaa2a13e38d62aa3383b3c7e1561189b

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/27/2024 3:25:46 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.SweetIM.K
188838

Reason Heuristics
PUP.SweetIM.K
14.8.7.19

VIPRE Antivirus
Sweetpacks/SweetIM
28128

File size:
3.3 MB (3,478,168 bytes)

Product version:
1.0

Copyright:
© SweetPacks

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\sweetpcfix.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/10/2011 1:00:00 AM

Valid to:
2/5/2014 12:59:59 AM

Subject:
CN=SweetIM Technologies Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SweetIM Technologies Ltd, L=Ra'anana, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E3BF2B52DA9EA7F1B539A7F018F4EC6

File PE Metadata
Compilation timestamp:
10/30/2010 10:54:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:oAb4oPPRLBdUFlZZmihDGCwbMeFwrCiUnA:oABRLB6lzfKLYCiwA

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file sweetpcfix.exe has been seen being distributed by the following 2 URLs.

Remove sweetpcfix.exe - Powered by Reason Core Security