vistaglazzsetup.exe

VistaGlazz

CodeGazer

The application vistaglazzsetup.exe, “VistaGlazz Installation ” by CodeGazer has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from lb.cdn.m6web.fr and multiple other hosts.
Publisher:
CodeGazer   (signed by CodeGazer)

Product:
VistaGlazz

Description:
VistaGlazz Installation

Version:
2.4

MD5:
9dce6a53f4cf6e3978241f5dc4e3c5e7

SHA-1:
ef0a4b4197b5f787397eae0c7a02d0fd001fce2d

SHA-256:
a16d12b5ba6dcf206bb5603b8c6744d2a30c89592c5ed9005306f10651ab1ade

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
5/10/2024 5:32:35 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallMonetizer.AF
8.9660

Reason Heuristics
PUP.InstallMonetizer.Bundle (M)
16.3.10.15

File size:
2 MB (2,140,952 bytes)

Product version:
2.4

Copyright:
© CodeGazer. All rights reserved.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\vistaglazzsetup.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/7/2011 9:00:00 AM

Valid to:
3/7/2012 8:59:59 AM

Subject:
CN=CodeGazer, O=CodeGazer, STREET=Melissekade 17, L=Utrecht, S=Utrecht, PostalCode=3544 CT, C=NL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00EEFDF64455BF2B64071BFE29C37DBB97

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:XawGFBmO9yH4bKFRxj8ZaB9OWBqOLrbs1n6aoARE7RMqbNsrSyTOm5:qVFBmIyH4KaEvBBsBWuE7jhseyTN5

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.7537

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file vistaglazzsetup.exe has been seen being distributed by the following 4 URLs.

http://lb.cdn.m6web.fr/d/c/a/df084feae1d04f066af2a651cf7d02e9/57d4377b/soft/.../vistaglazz_2-4_en_69258.exe

https://dw.uptodown.com/dwn/DpfPx-YKXV-n1uvFK_Os4-Du3-Niu9e0q1GXcu27hToIRrZL-1eh3YJY6ve90LEQMsPpO0P3RQFj-96UEcaqTTwgtUNSMzverdMS0bUYARwmpmdSNau1kC--O7FSlkhe/O9d4LeSQB5dy8p0lEiyxoiKjThstkCyUkvgKDFGJmxyq0ISYD1KJfOo_Rvy1Y9SXlrub1ExfZCxi1faHnXkGg7ZixI5G_fvd7icYwbA6svyJNQwMmGk6ZYiRvyxHubv3/.../

http://dw.uptodown.com/dwn/Kdfn-9nQk8tGi5ynkGDCIVKlqLMOBWPWQJ2OOTwXYyWXPNoftn43QJLLiPvDWa2G0CjbfFVjotlSqLyCKEjyG_uCLuPkU4XmE900nj26Q-698NLKWSRW_8lE5AU6rLmF/mHfNi8e_DSpdlJa7F3mFbAgJloE_lb_VyucFdozVr7w8oPXgC5MjgNzCwKZ0emA59Li-GAr7TkODCGxk2x29WbUs0CmPfSxYjuJqwwwKKaTPc8IWxSFlJiW4WaP_vU3z/.../

Remove vistaglazzsetup.exe - Powered by Reason Core Security