xvidsetup.vers.1.3.1.7.exe

WindowsFormsApplication3

Payments Interactive, S.L.U.

This is part of the Tuguu DomaIQ , a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application xvidsetup.vers.1.3.1.7.exe by Payments Interactive, S.L.U has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft  (signed by Payments Interactive, S.L.U.)

Product:
WindowsFormsApplication3

Version:
1.0.0.0

MD5:
ef3b9445d82ae436624bc1f6e90e73f5

SHA-1:
fa335f2cadd9d7429a3f125db80f4c4b600135f4

SHA-256:
abbac54ec0207bc5c49484e11b3e49a232b565d4deee2b49acb2a1b12592ed42

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 9:10:40 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tuguu (M)
17.3.3.10

File size:
434.3 KB (444,680 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2011

Original file name:
WindowsFormsApplication3.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\xvidsetup.vers.1.3.1.7.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
3/30/2011 8:00:00 PM

Valid to:
3/30/2012 7:59:59 PM

Subject:
CN="Payments Interactive, S.L.U.", O="Payments Interactive, S.L.U.", STREET="Av. Barranco de las Torres, 10 of 4A", L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38670, C=ES

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
2E5F7A3E357CC8C4CD32DC48276257A4

File PE Metadata
Compilation timestamp:
5/18/2011 3:35:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x6CC1E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.7950

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
427.5 KB (437,760 bytes)

Remove xvidsetup.vers.1.3.1.7.exe - Powered by Reason Core Security