14_avast_launcher.exe

Smart Inst

Fst Teaf

The application 14_avast_launcher.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. It runs as a scheduled task under the Windows Task Scheduler triggered by a time event. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Fst Teaf

Product:
Smart Inst

Description:
tiny install

Version:
142.196.86.123

MD5:
d7f7c39eb6be9f37b9cd9e1d2f790fec

SHA-1:
2b64707cbae6ba0d2d9973d764e9f047e914cf0b

SHA-256:
aee4c70ff8c3b005faa8ec9cf22b9e8fa7b42ffdea3690508fb14082d55b1a59

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
6/28/2025 11:45:32 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Gen:Application.Imonetize
11.5.0.6191

F-Secure
Application.Imonetize.2
5.15.96

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize
15.0.0.562

Norman
Gen:Application.Imonetize.2
10.04.2016 15:29:17

File size:
860 KB (880,640 bytes)

Product version:
142.196.86.123

Copyright:
CR 2015

Trademarks:
Trd Mark

Original file name:
sstup.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
4/30/2016 3:58:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:BiggKwmGvHU3FugN07iiqDW1ld8vb4ZfojqtcWutocgNV863/nUJ8KMzfddiU254:BOmBuq0Gklev8ZfItocgNq0fGv5lJ

Entry address:
0x4A11

Entry point:
E8, 86, 26, 00, 00, E9, 75, FE, FF, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, 83, 66, 04, 00, C7, 06, 2C, C4, 40, 00, C6, 46, 08, 00, FF, 30, E8, C9, 00, 00, 00, 8B, C6, 5E, 5D, C2, 04, 00, FF, 15, 88, C0, 40, 00, E9, 21, 3B, 00, 00, 55, 8B, EC, 8B, 45, 08, C7, 01, 2C, C4, 40, 00, 8B, 00, 89, 41, 04, C6, 41, 08, 00, 8B, C1, 5D, C2, 08, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, 83, 66, 04, 00, C7, 06, 2C, C4, 40, 00, C6, 46, 08, 00, E8, 1D, 00, 00, 00, 8B, C6, 5E, 5D, C2, 04, 00, FF, 15, 28, C0, 40, 00, E9, C3...
 
[+]

Code size:
44 KB (45,056 bytes)

Scheduled Task
Task name:
{6D0C7169-D753-4362-84B3-72ED850B9640}

Trigger:
Time


The file 14_avast_launcher.exe has been seen being distributed by the following 2 URLs.

Remove 14_avast_launcher.exe - Powered by Reason Core Security