6_nod32_launcher.exe

mlru

Finful

The application 6_nod32_launcher.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from www.markersoffredefy.site and multiple other hosts.
Publisher:
Finful

Product:
mlru

Description:
fast install

Version:
60.79.88.87

MD5:
162075ce5f6e2732984bdbd00ebb3b7e

SHA-1:
1544081c7a595196bcdb90446f0208db4bec26d3

SHA-256:
e17ea6297c8629a9062223490894d304f0d20bd67019adfe4d8e4d00095b77bc

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
6/29/2025 11:34:44 AM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Gen:Application.Imonetize
11.5.0.6191

F-Secure
Application.Imonetize.2
5.15.96

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize
15.0.0.562

Norman
Gen:Application.Imonetize.2
10.04.2016 15:29:17

File size:
1.1 MB (1,184,256 bytes)

Product version:
60.79.88.87

Copyright:
CR 2015

Trademarks:
Pepcyc

Original file name:
file.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\6_nod32_launcher.exe

File PE Metadata
Compilation timestamp:
5/4/2016 9:44:34 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:ChT0NpNE0SoRIqWbqsNy8mImD8pBXhScmLPca2VokB:20HPRu+L8PpBXMcmIa7k

Entry address:
0x508E

Entry point:
E8, 93, 36, 00, 00, E9, 71, FE, FF, FF, 8B, FF, EB, 08, E8, F0, FF, FF, FF, EB, 00, B8, 90, 90, EB, 04, C3, B8, 83, F8, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 08, F6, 40, 00, FF, 15, 1C, B0, 40, 00, 85, C0, 75, 18, 56, E8, E6, 23, 00, 00, 8B, F0, FF, 15, 18, B0, 40, 00, 50, E8, 96, 23, 00, 00, 59, 89, 06, 5E, 5D, C3, C7, 01, E8, B4, 40, 00, E9, 31, 14, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, E8, B4, 40, 00, E8, 1E, 14, 00, 00, F6, 45, 08, 01, 74, 07, 56, E8, 73, ED, FF, FF...
 
[+]

Code size:
38 KB (38,912 bytes)

The file 6_nod32_launcher.exe has been seen being distributed by the following 2 URLs.

Remove 6_nod32_launcher.exe - Powered by Reason Core Security