xvidsetup.exe

appbundler.com

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application xvidsetup.exe by appbundler.com has been detected as adware by 25 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from a.televisiontwister.com.
Publisher:
appbundler.com  (signed and verified)

Description:
Setup

Version:
3.0.113.1

MD5:
4e74390f8557565e162482ae0a67ec1b

SHA-1:
11e9e53462f9cc1febb451a21f9b776142b2ab1b

SHA-256:
dc364ccc3f7063341f49c2b7cb727c10360bd4adf1dbbf75fd3cf430f4ff4996

Scanner detections:
25 / 68

Status:
Adware

Analysis date:
4/24/2024 12:35:40 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.ScreenSaver
2012.12.29

Avira AntiVirus
TR/Graftor.Elzob.15338.1
7.11.55.4

avast!
Win32:Zango-AQ [PUP]
2014.9-141031

AVG
Generic5
2015.0.3304

Bitdefender
Gen:Variant.Adware.Graftor.30458
1.0.20.1520

Dr.Web
Adware.Hotbar.700
9.0.1.0304

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.30458
8.14.10.31.09

ESET NOD32
Win32/Adware.HotBar (variant)
8.7841

Fortinet FortiGate
Adware/Hotbar
10/31/2014

F-Prot
W32/HotBar.O.gen
v6.4.6.5.141

F-Secure
Gen:Variant.Adware.Graftor.30458
11.2014-31-10_6

G Data
Gen:Variant.Adware.Graftor.30458
14.10.22

IKARUS anti.virus
not-a-virus:AdWare.Win32
t3scan.1.1.122.0

K7 AntiVirus
Adware
13.155.8050

Kaspersky
not-a-virus:AdWare.Win32.ScreenSaver
14.0.0.3016

Malwarebytes
Adware.AdBundle
v2014.10.31.09

McAfee
Adware-HotBar.d
5600.6960

NANO AntiVirus
Trojan.Win32.Graftor.bbkjam
0.22.6.49175

Norman
W32/180Solutions.BSE
11.20141031

Quick Heal
Adware.Hotbar.B5
10.14.12.00

Reason Heuristics
PUP.Installer.appbundler.J
14.10.31.21

Rising Antivirus
Adware.Hotbar!481A
23.00.65.141029

Total Defense
Win32/Zango.Pinball.B[HOTBAR]
37.0.10227

Vba32 AntiVirus
AdWare.ScreenSaver.des
3.12.18.4

VIPRE Antivirus
Pinball Corporation.
14722

File size:
338.2 KB (346,288 bytes)

Product version:
3.0.113.1

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\xvidsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/10/2012 11:00:00 AM

Valid to:
1/10/2015 10:59:59 AM

Subject:
CN=appbundler.com, OU=Ops, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=appbundler.com, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
12E277DA6E659BFE14CD01F5A2AA95C5

File PE Metadata
Compilation timestamp:
12/20/2012 4:23:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:BA5wVdCy6wrbDY0rDqTWC4zEDzKuTrSbxc97ci7u32LvQYQzsDiQDQAxn:Bjyy64VrDqTWIzW+9Yf3+IYCstQAxn

Entry address:
0xBB480

Entry point:
60, BE, 00, A0, 46, 00, 8D, BE, 00, 70, F9, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8837

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
328 KB (335,872 bytes)

The file xvidsetup.exe has been seen being distributed by the following URL.

Remove xvidsetup.exe - Powered by Reason Core Security