2mty30sunj.exe

Telecharger-Installer.com

The application 2mty30sunj.exe by Telecharger-Installer.com has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Open Downloader Manager by Installer Technology Co which is a potentially unwanted software program. The file has been seen being downloaded from plateau-technologies.com and multiple other hosts.
Publisher:
Telecharger-Installer.com  (signed and verified)

MD5:
c415b7da17df54cbb52534731ed5d9a0

SHA-1:
dc39ba0bddecb1b662c0f4c1abc52866fe151d39

SHA-256:
c590dd529cd94a39131a1de4a91d67374e70742db6b6b4795e52a57886bb690e

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 11:32:00 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

NANO AntiVirus
Trojan.Nsis.Wajam.dqgtqq
0.30.24.1357

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Wajam.TelechargerInstaller (M)
16.1.29.9

Rising Antivirus
PE:Trojan.FakeIcon!1.64A5
23.00.65.15501

Trend Micro House Call
Suspici.2FFA4896
7.2.123

Zillya! Antivirus
Trojan.Win32.1DB12147
2.0.0.2164

File size:
2.2 MB (2,334,432 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\7ap0tmnjy3\2mty30sunj.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/2/2015 4:00:00 PM

Valid to:
3/2/2016 3:59:59 PM

Subject:
CN=Telecharger-Installer.com, O=Telecharger-Installer.com, L=Montreal, S=Quebec, C=CA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
7335FA39D2E08EA7D1858638FB64A705

File PE Metadata
Compilation timestamp:
12/5/2009 2:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:0sdfypO+Sq+d1gyA9D2H+NqOiaECTHfB7X/gClGWvFRL:1dfyxSJBA9D2eNFixUdgOGWvLL

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Entropy:
7.9929

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file 2mty30sunj.exe has been discovered within the following program.

Open Downloader Manager  by Installer Technology Co
ODM is a download manager that plugs into various web browsers (IE, Chrome and Firefox). The installer is designed to bundle and offer various additional offers including toolbars and other potentially harmful programs.
opendownloadmanager.com
73% remove it
 
Powered by Should I Remove It?

The file 2mty30sunj.exe has been seen being distributed by the following 3 URLs.

Remove 2mty30sunj.exe - Powered by Reason Core Security