the adventures of elmo in grouchland 1999 dvdrip xvid-xdr.exe

Stepan Rybin

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application the adventures of elmo in grouchland 1999 dvdrip xvid-xdr.exe by Stepan Rybin has been detected as adware by 17 anti-malware scanners. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Stepan Rybin  (signed and verified)

MD5:
6d09d218ec9602844c736278ba5935bd

SHA-1:
2177f4f558464d2c0262235ee5c3ac5d3a133c4a

SHA-256:
65d15617ed2475208883b2cf66266a556f88bacc5a515123d1ab8487362d22bf

Scanner detections:
17 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/25/2024 9:53:03 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.MultiPlug
2015.04.02

Avira AntiVirus
PUA/MultiPlug.11245
3.6.1.96

avast!
Win32:MultiPlug-TP [PUP]
150319-1

AVG
Generic
2016.0.3152

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.MultiPlug.YTRA
21613

Dr.Web
Trojan.Crossrider1.22656
9.0.1.05190

ESET NOD32
Win32/Adware.MultiPlug.GX (variant)
9.11411

Fortinet FortiGate
Riskware/MultiPlug
4/1/2015

G Data
Win32.Adware.Multiplug.AL
15.4.25

K7 AntiVirus
Unwanted-Program
13.202.15452

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

McAfee
Multiplug-FXE
5600.6808

Reason Heuristics
PUP.WebPick
15.4.1.12

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15330

Sophos
MultiPlug
4.98

Vba32 AntiVirus
suspected of Heur.Malware-Cryptor.Multiplug
3.12.26.3

File size:
452.7 KB (463,560 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\{84c65de6-3fd5-f632-84c6-65de63fd7798}\the adventures of elmo in grouchland 1999 dvdrip xvid-xdr.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
6/27/2014 1:37:40 AM

Valid to:
6/27/2015 1:37:40 AM

Subject:
E=rybin.step@yandex.ru, CN=Stepan Rybin, O=Stepan Rybin, C=UA

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
47154C2151E9EB8DFA42C2C9E45BFC6C

File PE Metadata
Compilation timestamp:
9/30/2012 2:58:02 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:WSpdX9Nv/c7HDn9DzUwcLUIw9Xu+dtj6E7RrihMfeYe73rzrKbCSowdRMxfIQ90/:lnHs9DdP9z6B+fg7nI7w+X

Entry address:
0x40B0B

Entry point:
E8, E6, 12, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 20, B2, 44, 00, E8, EF, 17, 00, 00, E8, B3, 14, 00, 00, 0F, B7, F0, 6A, 02, E8, 79, 12, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 28, 02, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.3939

Code size:
279 KB (285,696 bytes)