xvidsetup.exe

appbundler.com

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application xvidsetup.exe by appbundler.com has been detected as adware by 29 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from install.blamcity.com.
Publisher:
appbundler.com  (signed and verified)

Description:
Setup

Version:
3.0.113.3

MD5:
d6e9024a6b7324b9fbcd0c6ea0239dc8

SHA-1:
3a200964e4df6a2f4a0f7a3b265084ef7f10ae80

Scanner detections:
29 / 68

Status:
Adware

Analysis date:
4/25/2024 6:58:28 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.ScreenSaver
7.1.1

AhnLab V3 Security
Adware/Win32.ScreenSaver
2013.04.29

Avira AntiVirus
Adware/Bundledz.K
7.11.74.182

avast!
Win32:Zango-AQ [PUP]
2014.9-140608

AVG
Generic5
2015.0.3450

Bitdefender
Gen:Variant.Adware.Graftor.30458
1.0.20.795

Comodo Security
ApplicUnwnt.Win32.AdWare.ScreenSaver.DI
16091

Dr.Web
Adware.Hotbar.700
9.0.1.0159

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.30458
8.14.06.08.11

ESET NOD32
Win32/Adware.HotBar (variant)
8.8275

Fortinet FortiGate
Adware/Hotbar
6/8/2014

F-Prot
W32/HotBar.O.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor.30458
11.2014-08-06_1

G Data
Gen:Variant.Adware.Graftor.30458
14.6.22

IKARUS anti.virus
not-a-virus:AdWare.Win32
t3scan.2.0.0.0

K7 AntiVirus
Adware
13.166.8590

Kaspersky
HEUR:not-a-virus:AdWare.Win32.ScreenSaver
14.0.0.3743

Malwarebytes
Adware.AdBundle
v2014.06.08.11

McAfee
Adware-HotBar.d
5600.7106

Microsoft Security Essentials
Adware:Win32/Hotbar
1.163.1557.0

MicroWorld eScan
Gen:Variant.Adware.Graftor.30458
15.0.0.477

NANO AntiVirus
Trojan.Win32.Graftor.bbkjam
0.24.0.52214

Norman
180Solutions.BSE
11.20140608

Quick Heal
Adware.Hotbar.B5
6.14.12.00

Reason Heuristics
PUP.Installer.appbundler.J
14.8.7.21

Sophos
Mal/Generic-S
4.88

Total Defense
Win32/Zango.Pinball.B[HOTBAR]
37.0.10396

Vba32 AntiVirus
AdWare.ScreenSaver
3.12.20.2

VIPRE Antivirus
Pinball Corporation.
17260

File size:
341.7 KB (349,872 bytes)

Product version:
3.0.113.3

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\xvidsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/9/2012 9:00:00 PM

Valid to:
1/9/2015 8:59:59 PM

Subject:
CN=appbundler.com, OU=Ops, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=appbundler.com, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
12E277DA6E659BFE14CD01F5A2AA95C5

File PE Metadata
Compilation timestamp:
2/22/2013 2:21:16 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:ffZ/nwzIhoZib9i0ju9BKVoEZUWTNbvcEniY2YaxWS/jyFzYpRTYksG:ffpPOZiBiq3zxTNbvccB6jRRTYksG

Entry address:
0xBC2E0

Entry point:
60, BE, 00, A0, 46, 00, 8D, BE, 00, 70, F9, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8830

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
332 KB (339,968 bytes)

The file xvidsetup.exe has been seen being distributed by the following URL.

Remove xvidsetup.exe - Powered by Reason Core Security