xvidsetup.exe

appbundler.com

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application xvidsetup.exe by appbundler.com has been detected as adware by 37 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from origin-ics.clickpotato.tv.
Publisher:
appbundler.com  (signed and verified)

Description:
Setup

Version:
3.0.15.0

MD5:
62435f4daf893fcf27aa2227529505cd

SHA-1:
e0e0c9e7dc13f37027085824e44d2e332fd7d396

SHA-256:
ecf4f293582bdf99172c2b35d2c91fa8107456c9749d925feabb4976c7d8ceae

Scanner detections:
37 / 68

Status:
Adware

Analysis date:
5/7/2024 10:03:16 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.384325
793

Agnitum Outpost
Adware.Zango.Gen.4
7.1.1

AhnLab V3 Security
Adware/Win32.ScreenSaver
2014.12.04

Avira AntiVirus
Adware/Hotbar.zwi
7.11.30.172

avast!
Win32:Zango-AQ [PUP]
141130-1

AVG
Adware Skodna.Generic_r.Y
2014.0.4189

Bitdefender
Application.Generic.384325
1.0.20.1685

Bkav FE
W32.OnGamesARESAA.Trojan
1.3.0.6267

Clam AntiVirus
WIN.Adware.Screensaver-7
0.98/19722

Comodo Security
ApplicUnwnt.Win32.AdWare.ScreenSaver.DI
20277

Dr.Web
Adware.Hotbar.700
9.0.1.05190

Emsisoft Anti-Malware
Application.Generic.384325
9.0.0.4668

ESET NOD32
Win32/Adware.HotBar.N application
7.0.302.0

Fortinet FortiGate
Adware/Hotbar
12/3/2014

F-Prot
W32/HotBar.O.gen
4.6.5.141

F-Secure
Application.Generic.384325
11.2014-03-12_4

G Data
Application.Generic.384325
14.12.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.5.0

K7 AntiVirus
Adware
13.186.14225

Kaspersky
not-a-virus:AdWare.Win32.ScreenSaver
15.0.0.543

Malwarebytes
Adware.Agent
v2014.12.03.11

McAfee
Adware-HotBar.d
5600.6927

Microsoft Security Essentials
Threat.Undefined
1.189.1270.0

MicroWorld eScan
Application.Generic.384325
15.0.0.1011

NANO AntiVirus
Trojan.Win32.DownLoader3.eqivg
0.28.6.63850

Norman
180Solutions.BSE
11.20141203

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Quick Heal
Adware.Hotbar.AZ5
12.14.14.00

Reason Heuristics
PUP.Installer.appbundler.J
14.12.3.23

Rising Antivirus
PE:Adware.HotBar!1.6AAD
23.00.65.141201

Sophos
ClickPotato Installer
4.98

SUPERAntiSpyware
Adware.Zango
10199

Total Defense
Win32/Zango.Pinball.B[HOTBAR]
37.0.11313

Trend Micro House Call
TROJ_PAM_0000020120.T3
7.2.337

Vba32 AntiVirus
Signed-Adware.Hotbar
3.12.26.3

VIPRE Antivirus
Threat.4672643
35224

Zillya! Antivirus
Adware.HotBar.Win32.400
2.0.0.1998

File size:
244.2 KB (250,032 bytes)

Product version:
3.0.15.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\xvidsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/21/2010 7:00:00 PM

Valid to:
12/21/2012 6:59:59 PM

Subject:
CN=appbundler.com, OU=Ops, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=appbundler.com, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
05E671753CF9BB1D76A8C55652892720

File PE Metadata
Compilation timestamp:
11/4/2011 10:25:39 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:7GEsbu08azUYDIJTHGSG24Iu2LLpqB49+VcCY/5nrFtN5YY:qtbu5azUYMRHo27LL1q8+VcL/5nsY

Entry address:
0x8DC50

Entry point:
60, BE, 00, 40, 45, 00, 8D, BE, 00, D0, FA, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8824

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
232 KB (237,568 bytes)

The file xvidsetup.exe has been seen being distributed by the following URL.

Remove xvidsetup.exe - Powered by Reason Core Security