xvidsetup.exe

appbundler.com

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application xvidsetup.exe by appbundler.com has been detected as adware by 33 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from a.juiceknowledge.com.
Publisher:
appbundler.com  (signed and verified)

Description:
Setup

Version:
3.0.112.6

MD5:
3bedc9551b762222bb3ba0578c8e0c87

SHA-1:
ca3d3c9651ab3141545551fddb0c3b6ded575b1e

SHA-256:
53454f5bd7c18889f6d976616958ca4ed0f81dd1f8c14eac76b9aba268c3a81c

Scanner detections:
33 / 68

Status:
Adware

Analysis date:
4/27/2024 2:38:51 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Hotbar.14
916

Agnitum Outpost
PUA.GOffer
7.1.1

AhnLab V3 Security
Adware/Win32.ScreenSaver
2014.08.03

Avira AntiVirus
ADWARE/Adware.Gen
7.11.30.172

avast!
Win32:Zango-AQ [PUP]
140617-1

AVG
Adware Skodna.Generic_r.EI
2014.0.3986

Bitdefender
Gen:Variant.Adware.Hotbar.14
1.0.20.1070

Clam AntiVirus
WIN.Adware.Screensaver-7
0.98/19246

Comodo Security
ApplicUnwnt.Win32.AdWare.ScreenSaver.DI
19058

Dr.Web
Adware.Hotbar.700
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Hotbar.14
8.14.08.02.01

ESET NOD32
Win32/Adware.HotBar.P application
7.0.302.0

Fortinet FortiGate
Adware/Hotbar
8/2/2014

F-Prot
W32/HotBar.O.gen
4.6.5.141

F-Secure
Gen:Variant.Adware.Hotbar.14
11.2014-02-08_7

G Data
Gen:Variant.Adware.Hotbar.14
14.8.24

IKARUS anti.virus
AdWare.ScreenSaver
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.182.12926

Kaspersky
not-a-virus:AdWare.Win32.ScreenSaver
15.0.0.494

Malwarebytes
Adware.AdBundle
v2014.08.02.01

McAfee
Adware-HotBar.d
5600.7050

Microsoft Security Essentials
Threat.Undefined
1.179.1903.0

MicroWorld eScan
Gen:Variant.Adware.Hotbar.14
15.0.0.642

NANO AntiVirus
Trojan.Win32.Banach.cjfqdq
0.28.2.61148

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Quick Heal
Adware.Hotbar.B5
8.14.14.00

Reason Heuristics
PUP.Installer.appbundler.J
14.8.7.21

Rising Antivirus
PE:Adware.HotBar!1.6AAD
23.00.65.14731

Sophos
Generic PUA DA
4.98

SUPERAntiSpyware
Adware.Hotbar
10446

Total Defense
Win32/Zango.Pinball.B[HOTBAR]
37.0.11095

Vba32 AntiVirus
AdWare.ScreenSaver
3.12.26.3

VIPRE Antivirus
Threat.4672643
31208

File size:
329.2 KB (337,072 bytes)

Product version:
3.0.112.6

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\xvidsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/22/2010 1:00:00 AM

Valid to:
12/22/2012 12:59:59 AM

Subject:
CN=appbundler.com, OU=Ops, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=appbundler.com, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
05E671753CF9BB1D76A8C55652892720

File PE Metadata
Compilation timestamp:
12/1/2012 12:40:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:iS+QH6yN8wfRe3q+2ZYbO2PY/eQanlrUFsNpGBdhgByA9283m2e:sE6y66e3N272PYXZimHg81x

Entry address:
0xB9070

Entry point:
60, BE, 00, A0, 46, 00, 8D, BE, 00, 70, F9, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
320 KB (327,680 bytes)

The file xvidsetup.exe has been seen being distributed by the following URL.

Remove xvidsetup.exe - Powered by Reason Core Security