winx dvd ripper platinum 6.9.1 build 20120912 serial [timetravel]_10924_i41180923_il345.exe

Runner Utility

BERSHNET LLC

The application winx dvd ripper platinum 6.9.1 build 20120912 serial [timetravel]_10924_i41180923_il345.exe by BERSHNET has been detected as adware by 17 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Dummy, Ltd.  (signed by BERSHNET LLC)

Product:
Runner Utility

Version:
1.0.0.187

MD5:
c64a50ec6530f5e43de0d9acab1cbd65

SHA-1:
48aa20a6eb90dc9ecfb17f79b1ee6cf6de9fdce5

SHA-256:
1a17c9c94b84dbe0f3705a00af34782890d3d5ff19cc663fa628f5e5276c3613

Scanner detections:
17 / 68

Status:
Adware

Analysis date:
4/26/2024 7:57:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Mikey.8247
6762526

Avira AntiVirus
ADWARE/Adware.Gen7
7.11.214.38

AVG
Win32/Heur
2014.0.4253

Bitdefender
Gen:Variant.Adware.Mikey.8247
1.0.20.325

Comodo Security
Application.Win32.LoadMoney.IARS
21309

Emsisoft Anti-Malware
Gen:Variant.Adware.Mikey.8247
9.0.0.4799

ESET NOD32
Win32/Amonetize.DW potentially unwanted application
7.0.302.0

F-Prot
W32/S-40484255
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Mikey
5.13.68

G Data
Gen:Variant.Adware.Mikey.8247
15.3.25

K7 AntiVirus
Unwanted-Program
13.200.15178

Kaspersky
not-a-virus:Downloader.Win32.Agent
15.0.0.543

Malwarebytes
PUP.Optional.Bershnet
v2015.03.06.02

MicroWorld eScan
Gen:Variant.Adware.Mikey.8247
16.0.0.195

Panda Antivirus
Trj/Genetic.gen
15.03.06.02

Reason Heuristics
PUP.BERSHNET
15.3.6.2

VIPRE Antivirus
Threat.4785227
37788

File size:
1.5 MB (1,539,600 bytes)

Product version:
1.0.0.187

Copyright:
Copyright (C) 2013

Original file name:
runner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\winx dvd ripper platinum 6.9.1 build 20120912 serial [timetravel]_10924_i41180923_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/5/2015 7:00:00 PM

Valid to:
2/6/2016 6:59:59 PM

Subject:
CN=BERSHNET LLC, O=BERSHNET LLC, STREET="st. 600-richya b.66, of.10", L=Vinnitsya, S=Vinnitskaya, PostalCode=21027, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E2D6C6F8DDF832E09DCF766B299AD2A9

File PE Metadata
Compilation timestamp:
3/5/2015 4:53:06 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:zy1R8pRgzHffYXaIBehEQgfx5DO4AxgkGC9u9QzQor2JddXk1iDC+jszWSbquV1:zy1Rlrf4a8O4YKaCu3rMVC+jszWSbND

Entry address:
0x3E37BE

Entry point:
9C, 66, C7, 04, 24, 34, 78, C7, 04, 24, 1A, BF, 7E, B6, E8, 69, FD, FE, FF, 0E, 90, 41, 98, 26, 43, F2, 7D, 96, 77, 6C, FE, 42, C4, 18, C7, 9F, DF, C8, 0F, F8, 09, 76, 80, A9, F8, 96, BB, 2F, B5, BE, ED, F6, 39, 1A, 41, BD, 6F, AE, 78, 27, 12, 55, D4, F7, 2E, 47, 7A, 99, 2C, F2, 29, C4, 4B, F8, D2, 05, 8E, C3, F5, 90, D4, 90, BF, D8, FF, 18, 3F, E6, C8, 8E, AF, 5F, C0, 24, D7, 13, F7, 95, 4D, 56, 3A, 82, 79, 60, DF, 02, 3D, B1, 6A, 31, D0, 1D, B2, 5A, BF, 5E, 87, 7A, D6, 54, FF, 80, F4, DA, 3E, FA, 55, 16...
 
[+]

Entropy:
7.9946  (probably packed)

Code size:
187.5 KB (192,000 bytes)