xvidsetup.vers.1.3.1.6.exe

WindowsFormsApplication3

Payments Interactive, S.L.U.

This is part of the Tuguu DomaIQ , a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application xvidsetup.vers.1.3.1.6.exe by Payments Interactive, S.L.U has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft  (signed by Payments Interactive, S.L.U.)

Product:
WindowsFormsApplication3

Version:
1.0.0.0

MD5:
cc39559490fa4cb6e9c9a619efa3f882

SHA-1:
d32fa0251433b25375421db583c5aa204b9cc661

SHA-256:
8fe1503435ebbf8bae73aef5653f24402dafc2c020154286770c5de11019895c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/27/2024 12:28:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tuguu (M)
16.9.13.9

File size:
434.3 KB (444,680 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2011

Original file name:
WindowsFormsApplication3.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\xvidsetup.vers.1.3.1.6.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
3/30/2011 6:00:00 PM

Valid to:
3/30/2012 5:59:59 PM

Subject:
CN="Payments Interactive, S.L.U.", O="Payments Interactive, S.L.U.", STREET="Av. Barranco de las Torres, 10 of 4A", L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38670, C=ES

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
2E5F7A3E357CC8C4CD32DC48276257A4

File PE Metadata
Compilation timestamp:
5/18/2011 1:29:03 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:XMx9qqRnvJxMQ/4AiJkufotYPJfO1dsUBaS7GcAlXcTWxa:GqGR

Entry address:
0x6CC1E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.7949

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
427.5 KB (437,760 bytes)

Remove xvidsetup.vers.1.3.1.6.exe - Powered by Reason Core Security