windows 7 _ loader v.2.2.3 activation by daz--may 2013.zip.exe

Stepan Rybin

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application windows 7 _ loader v.2.2.3 activation by daz--may 2013.zip.exe by Stepan Rybin has been detected as adware by 24 anti-malware scanners. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Stepan Rybin  (signed and verified)

MD5:
5f0d411df56c7d3f586e118f4ae72aa3

SHA-1:
99aa60dd5830f65208283ac6497dc247caab544d

SHA-256:
39f996925e221dfb01ba287423ab36591a4cc6485684d34de21d546b4a21cf93

Scanner detections:
24 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/26/2024 9:54:57 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.MPLug.HH
6266345

AhnLab V3 Security
PUP/Win32.MultiPlug
2015.03.30

avast!
Win32:Adware-gen [Adw]
150319-0

AVG
Generic6
2016.0.3154

Bitdefender
Adware.MPLug.HH
1.0.20.450

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.MultiPlug.YTRA
21588

Dr.Web
Trojan.Crossrider1.22656
9.0.1.05190

Emsisoft Anti-Malware
Adware.MPLug.HH
9.0.0.4799

ESET NOD32
Win32/Adware.MultiPlug.GD (variant)
9.11398

Fortinet FortiGate
Riskware/MultiPlug
3/31/2015

F-Prot
W32/S-40157abe
v6.4.7.1.166

F-Secure
Adware.MPLug.HH
5.13.68

G Data
Adware.MPLug.HH
15.3.25

K7 AntiVirus
Trojan
13.202.15424

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

Malwarebytes
PUP.Optional.Unizeto
v2015.03.31.02

McAfee
Program.MultiPlug-FXC
16.8.708.2

MicroWorld eScan
Adware.MPLug.HH
16.0.0.270

nProtect
Adware.MPLug.HH
15.03.30.01

Reason Heuristics
PUP.WebPick
15.3.31.2

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15329

Sophos
MultiPlug
4.98

Vba32 AntiVirus
suspected of Heur.Malware-Cryptor.Multiplug
3.12.26.3

File size:
472.7 KB (484,040 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\{106032f4-807b-3de9-1060-032f4807cbd2}\windows 7 _ loader v.2.2.3 activation by daz--may 2013.zip.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
6/27/2014 4:37:40 PM

Valid to:
6/27/2015 4:37:40 PM

Subject:
E=rybin.step@yandex.ru, CN=Stepan Rybin, O=Stepan Rybin, C=UA

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
47154C2151E9EB8DFA42C2C9E45BFC6C

File PE Metadata
Compilation timestamp:
9/12/2013 8:02:44 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:hWD7XK/IJAXI/2YTUOerVfni/k3EYyBEBTkn6TAdAhSnPxWh/s0:MSIJhyr1SkUODTAmhS8U0

Entry address:
0x4579B

Entry point:
E8, CF, 1F, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 90, 01, 45, 00, E8, DF, 24, 00, 00, E8, 9C, 21, 00, 00, 0F, B7, F0, 6A, 02, E8, 62, 1F, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 28, 02, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4309

Code size:
298.5 KB (305,664 bytes)