14_avira_launcher.exe

Must have files

Old Tramolt

The application 14_avira_launcher.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.perisigmoiditisgashing.site and multiple other hosts.
Publisher:
Old Tramolt

Product:
Must have files

Description:
fast install

Version:
243.62.108.95

MD5:
4cbe598445ec3e93efdd7f6a3e01c98b

SHA-1:
ab49ee13ece79843c3443f34644919ac63ed9490

SHA-256:
fd6bea925a232181689e1789a47cb214a939b9553deb4fa2ed445acec8938e15

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
6/29/2025 12:10:45 AM UTC  (today)

Scan engine
Detection
Engine version

F-Secure
Application.Imonetize.2
5.15.96

Norman
Gen:Application.Imonetize.2
10.04.2016 15:29:17

Reason Heuristics
Adware.Bundler (M)
16.5.1.12

File size:
903 KB (924,672 bytes)

Product version:
243.62.108.95

Copyright:
LC 2015

Trademarks:
Kocl

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\14_avira_launcher.exe

File PE Metadata
Compilation timestamp:
5/1/2016 11:44:07 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:9skoXOQGlfk9hrGmnnXhScmLPca2Voks:9s9slfmhKanXMcmIa7k

Entry address:
0x5327

Entry point:
E8, AF, 56, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 2C, E8, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 2C, E8, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, A0, 00, 00, 00, C7, 06, 14, E8, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 44, 00, 00, 00, C7, 06, 14, E8, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1...
 
[+]

Entropy:
7.5409

Code size:
111 KB (113,664 bytes)

The file 14_avira_launcher.exe has been seen being distributed by the following 2 URLs.

Remove 14_avira_launcher.exe - Powered by Reason Core Security