windows 7 loader - activator.exe

The application windows 7 loader - activator.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from download2110.mediafire.com and multiple other hosts.
MD5:
4946ab860f53565e156af66db864eb3b

SHA-1:
7546f3b00ccdcad43928113018cf6b2c27121f53

SHA-256:
d40b6f04cbc84bdce4f644b1d6dd9b721e2577057d1d1165d42392acf8e324ac

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/23/2024 4:00:31 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.OutBrowse
4.0.3.1464

Dr.Web
Adware.Downware.3973
9.0.1.0155

ESET NOD32
Win32/OutBrowse
8.9868

G Data
Win32.Trojan.Agent.5HY8II
14.6.24

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.3761

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Sophos
Generic PUA HN
4.98

Trend Micro House Call
TROJ_GEN.F47V0524
7.2.155

VIPRE Antivirus
Trojan.Win32.Generic
29752

File size:
1.1 MB (1,125,140 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/9/2012 3:19:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:w2O/GlJeMAX/ZqbaB8SnQMO1cydtFNXBlCQdayBAd8FMMcuVfVbVv:PAvGkQHFNRQ2WmMMcuVNhv

Entry address:
0xAC87

Entry point:
E8, E3, FE, FF, FF, 33, C0, 50, 50, 50, 50, E8, 9F, 30, 00, 00, C3, 56, 57, 8B, 7C, 24, 0C, 8B, F1, 8B, CF, 89, 3E, E8, 8F, AB, FF, FF, 89, 46, 08, 89, 56, 0C, 8B, 87, 24, 0C, 00, 00, 89, 46, 10, 5F, 8B, C6, 5E, C2, 04, 00, 8B, C1, 8B, 08, 8B, 50, 10, 3B, 91, 24, 0C, 00, 00, 75, 0D, 6A, 00, FF, 70, 0C, FF, 70, 08, E8, 0E, B1, FF, FF, C3, 56, 8B, F1, 8B, 06, 85, C0, 74, 07, 50, FF, 15, C4, 40, 41, 00, 83, 26, 00, 83, 66, 08, 00, 83, 66, 0C, 00, 5E, C3, 56, 8B, F1, 80, 7E, 04, 00, 75, 34, 68, F4, 44, 41, 00...
 
[+]

Code size:
73 KB (74,752 bytes)

The file windows 7 loader - activator.exe has been seen being distributed by the following 3 URLs.

Remove windows 7 loader - activator.exe - Powered by Reason Core Security