windowsupdatekb12695__7428_il24488.exe

Smart Inst

SPRT

The application windowsupdatekb12695__7428_il24488.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
SPRT

Product:
Smart Inst

Description:
smart install

Version:
199.197.173.80

MD5:
3835dc5d3f4920fa65fac4d56ad06ac8

SHA-1:
255ce9b2335b5ee1c0a82eb949aea728d98a5fea

SHA-256:
bf0c26de48b9fb593ece76eb987cc3d43a957d1ed5419a4a8a2486f15af916b4

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
6/29/2025 12:20:37 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Amonetize.SPRT.Installer.Meta (M)
16.4.28.11

File size:
693 KB (709,632 bytes)

Product version:
199.197.173.80

Copyright:
Rights 2000

Trademarks:
Pepcyc

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\windowsupdatekb12695__7428_il24488.exe

File PE Metadata
Compilation timestamp:
4/28/2016 6:15:00 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:6cA/FMkgQTz1BK60HfZdwCKN1ItSFTpi+FeXDsIfq3XFD3sKlC7V7Vmv3:QFMkpThBK60HfZi9EtSFssIfyJ80av03

Entry address:
0xC4F4

Entry point:
E8, 10, 36, 00, 00, E9, 7F, FE, FF, FF, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 40, FB, 41, 00, FF, 15, 28, 30, 41, 00, 85, C0, 75, 18, 56, E8, CA, 1C, 00, 00, 8B, F0, FF, 15, 24, 30, 41, 00, 50, E8, CF, 1C, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, 83, 66, 04, 00, C7, 06, AC, 7D...
 
[+]

Code size:
72 KB (73,728 bytes)

The file windowsupdatekb12695__7428_il24488.exe has been seen being distributed by the following URL.

Remove windowsupdatekb12695__7428_il24488.exe - Powered by Reason Core Security