AppMonetizer Installer

Category: Adware and PUAs Protection available since:10 May 2013 02:13:54 (GMT)
Type: Adware Last Updated:06 Sep 2017 12:19:26 (GMT)

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of AppMonetizer Installer include:

Example 1

File Information

Size
322K
SHA-1
42172db8072676be297a0ea8d885ba5746899447
MD5
203b7d9d0c87ca1a980b03028cc55897
CRC-32
3369e531
File type
Windows executable
First seen
2015-01-08

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\AVD.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\inner.png
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\Offer5.zip
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\BlockNSurf.png
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\nsDialogs.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\blowfish.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\GetVersion.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\FirstResult.txt
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\manlib.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\nsisunz.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\Math.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\Offer2.zip
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\OfferScreen_140.html
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\nsCBHTML5.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\OfferScreen_348.html
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\OfferScreen_291.html
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\Offer4.zip
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\Offer3.zip
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\Offer1.zip
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\OfferScreen_434.html
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\registry.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\pdf.png
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\OfferScreen_437.html
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\serlib.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\refresh.png
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\SecondResult.txt
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\header.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\windows-logo.png
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\System.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso3.tmp\UserInfo.dll
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012015010920150110
    CacheRepair
    0x00000000
HTTP Requests
  • http://secure.fordcdnsecure.com/os/rm/OfferScreen_140.zip
  • http://secure.fordcdnsecure.com/os/rm/OfferScreen_291.zip
  • http://secure.fordcdnsecure.com/os/rm/OfferScreen_348.zip
  • http://secure.fordcdnsecure.com/os/rm/OfferScreen_434.zip
  • http://secure.fordcdnsecure.com/os/rm/OfferScreen_437.zip
DNS Requests
  • secure.fordcdnsecure.com
  • www.fwaterceast.com
  • www.stsunsetwest.com

Example 2

File Information

Size
1.3M
SHA-1
9871c4f1a57cb49bceb2da39ca332be44cc8e9a4
MD5
9f633a968d1b4550862e5ba78a04f455
CRC-32
322ac793
File type
Windows executable
First seen
2014-05-14

Runtime Analysis

Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\ESENT\Process\sample\DEBUG
    Trace Level

Example 3

File Information

File type
Windows executable

download Try Sophos products for free
Download now