xvidsetup.exe

appbundler.com

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application xvidsetup.exe by appbundler.com has been detected as adware by 34 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from org.flixsee.net.
Publisher:
appbundler.com  (signed and verified)

Description:
Setup

Version:
3.0.58.1

MD5:
07cc30826f17ceffc47b8334c7b58982

SHA-1:
ef867bafbdfd404f5b3728edf1abff3a8f7f3f51

SHA-256:
05d3ecd33452936417c4d79c5fac74f628de26a7dddb4ed9ae3cb6a1e5b31435

Scanner detections:
34 / 68

Status:
Adware

Analysis date:
5/22/2024 11:32:51 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.HotBar
7.1.1

AhnLab V3 Security
Adware/Win32.ScreenSaver
2013.01.11

Avira AntiVirus
TR/Banach.A
7.11.56.52

avast!
Win32:Zango-AQ [PUP]
2014.9-140619

AVG
Generic5
2015.0.3438

Bitdefender
Gen:Variant.Adware.Graftor.Elzob.8765
1.0.20.850

Comodo Security
ApplicUnwnt.Win32.AdWare.ScreenSaver.DI
14862

Dr.Web
Adware.Hotbar.700
9.0.1.0170

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.Elzob.8765
8.14.06.19.11

ESET NOD32
Win32/Adware.HotBar (variant)
8.7880

Fortinet FortiGate
Adware/Hotbar
6/19/2014

F-Prot
W32/HotBar.O.gen
v6.4.6.5.141

F-Secure
Gen:Variant.Adware.Graftor.Elzob.8765
11.2014-19-06_5

G Data
Gen:Variant.Adware.Graftor.Elzob.8765
14.6.22

IKARUS anti.virus
not-a-virus:AdWare.Win32.ScreenSaver
t3scan.1.3.5.0

K7 AntiVirus
Adware
13.158.8098

Kaspersky
not-a-virus:AdWare.Win32.ScreenSaver
14.0.0.3685

Malwarebytes
Adware.Agent
v2014.06.19.11

McAfee
Adware-HotBar.d
5600.7094

Microsoft Security Essentials
Adware:Win32/Hotbar
1.163.1557.0

MicroWorld eScan
Gen:Variant.Adware.Graftor.Elzob.8765
15.0.0.510

NANO AntiVirus
Trojan.Win32.Hotbar.mtyyh
0.22.6.49175

Norman
W32/180Solutions.BSE
11.20140619

Panda Antivirus
Generic Malware
14.06.19.11

Quick Heal
Adware.Hotbar.B5
6.14.12.00

Reason Heuristics
PUP.Installer.appbundler.J
14.8.7.21

Rising Antivirus
Trojan.Win32.Generic.12BC7C9E
23.00.65.14617

Sophos
ClickPotato Installer
4.84

SUPERAntiSpyware
Adware.Zango
10533

Total Defense
Win32/Zango.Pinball.B[HOTBAR]
37.0.10242

Trend Micro House Call
ADW_HOTBAR
7.2.170

Trend Micro
ADW_HOTBAR
10.465.19

Vba32 AntiVirus
AdWare.ScreenSaver.e
3.12.18.4

VIPRE Antivirus
Pinball Corporation.
14954

File size:
305.2 KB (312,496 bytes)

Product version:
3.0.58.1

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\xvidsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/21/2010 7:00:00 PM

Valid to:
12/21/2012 6:59:59 PM

Subject:
CN=appbundler.com, OU=Ops, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=appbundler.com, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
05E671753CF9BB1D76A8C55652892720

File PE Metadata
Compilation timestamp:
3/20/2012 4:36:34 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:KSdjG69XkMui7MnzqJCtwXjTYpS6wsAChuOLx3Izip9+ngHVvsn:bRJzui7MMCXS6wsVwOLxwy+noUn

Entry address:
0xB30B0

Entry point:
60, BE, 00, A0, 46, 00, 8D, BE, 00, 70, F9, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8912

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
296 KB (303,104 bytes)

The file xvidsetup.exe has been seen being distributed by the following URL.

Remove xvidsetup.exe - Powered by Reason Core Security