utorrent-v3.2_installer.exe

Meta Installer LLC

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application utorrent-v3.2_installer.exe by Meta Installer has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from download.metainstaller.com.
Publisher:
Meta Installer LLC  (signed and verified)

MD5:
18c663b4f95551467e33f70b72a2288c

SHA-1:
7c989021088c907dcb8b8645335ad523c3f340d3

SHA-256:
8561b91834ffc67e64796f34b99ee1c61d95973d1fdbcfda35fe50b6c1a070fc

Scanner detections:
3 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/19/2024 12:01:35 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.441
9.0.1.0290

Reason Heuristics
PUP.MetaInstaller.W
14.10.17.7

SUPERAntiSpyware
Heur.Agent/Gen-WhiteBox
10294

File size:
248.8 KB (254,728 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\utorrent-v3.2_installer.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/6/2012 6:17:45 AM

Valid to:
2/16/2013 7:59:09 PM

Subject:
CN=Meta Installer LLC, O=Meta Installer LLC, L=Wilmington, S=DE, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
043DEA1F43D249

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:We34TKhxkq41x+YJd8BUcVOkc4Wc40yU:fkqMxBd8jVOkcE

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file utorrent-v3.2_installer.exe has been seen being distributed by the following URL.

Remove utorrent-v3.2_installer.exe - Powered by Reason Core Security