7_avast_launcher.exe

Smart Inst

IDDQD

The application 7_avast_launcher.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.panningmanybanded.site.
Publisher:
IDDQD

Product:
Smart Inst

Description:
cmpnnt

Version:
124.61.146.227

MD5:
111114612c28ebaf960c1905018cb3d4

SHA-1:
a2f7f4e282c5077fd0fb1221ff817e63650bd0a5

SHA-256:
0e6db6408ee530a5c720293634eddce11aca1261e1e0b625c8629fb8f7c5362e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
6/29/2025 10:45:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallMonetizer.IDDQD.Installer.Meta (M)
16.5.17.20

File size:
957 KB (979,968 bytes)

Product version:
124.61.146.227

Copyright:
CL2016

Trademarks:
Trd Mark

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
5/8/2016 10:27:11 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:AB1/fYGs044RAdkAkZ21u3836kqhx2prmLDoQO20:ABZYGQ47ZUs8S2po8Q0

Entry address:
0x411F

Entry point:
E8, B9, 21, 00, 00, E9, 39, FE, FF, FF, E9, 75, 28, 00, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 7C, B5, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 7C, B5, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, A0, 00, 00, 00, C7, 06, 64, B5, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 44, 00, 00, 00, C7, 06, 64, B5, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56...
 
[+]

Code size:
98 KB (100,352 bytes)

The file 7_avast_launcher.exe has been seen being distributed by the following URL.

Remove 7_avast_launcher.exe - Powered by Reason Core Security