5z3tkobx.qt3.exe

FastFreeInstall.com

This is the installer for Wajam, a potentially unwanted program that displays social media posts from the user's contacts in search results. The application 5z3tkobx.qt3.exe by FastFreeInstall.com has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Open Downloader Manager by Installer Technology Co which is a potentially unwanted software program. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from wajam-download.com and multiple other hosts.
Publisher:
FastFreeInstall.com  (signed and verified)

MD5:
969ddc4a3253043adc91a798c65e8ef9

SHA-1:
bc1e60eb67575ce960102e29a2d57ce4f0e4dd22

SHA-256:
e97cb67b1aa4260db27a15af3cd3bccf0a68c04ee8be1ef66d30ac55c1ec490e

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
1/11/2025 8:45:52 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Searcher.2673
9.0.1.0332

Malwarebytes
PUP.Optional.Wajam
v2014.11.28.09

McAfee
Artemis!969DDC4A3253
5600.6933

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.FastFreeInstall.L
14.11.28.9

Trend Micro House Call
TROJ_GEN.R047H05KR14
7.2.332

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.26.3

VIPRE Antivirus
Wajam
35204

Zillya! Antivirus
Trojan.Win32.1DB12147
2.0.0.1995

File size:
2.5 MB (2,660,600 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\5z3tkobx.qt3.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/30/2014 8:00:00 PM

Valid to:
7/31/2015 7:59:59 PM

Subject:
CN=FastFreeInstall.com, OU=Insta-Download.com, O=FastFreeInstall.com, STREET=4115 Boul Saint-Laurent, L=Montreal, S=Quebec, PostalCode=H2W 1Y7, C=CA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009915504505808BBF6AAC2C2CD2A8C3BE

File PE Metadata
Compilation timestamp:
12/5/2009 5:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:SSa1CQsGlX/e6cj1JH21eMUY85tIRd5vtd/m5lMqCSNyjeh:ssQsOGPj1N21ejYCqdFmzM9cseh

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Entropy:
7.9934

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file 5z3tkobx.qt3.exe has been discovered within the following program.

Open Downloader Manager  by Installer Technology Co
ODM is a download manager that plugs into various web browsers (IE, Chrome and Firefox). The installer is designed to bundle and offer various additional offers including toolbars and other potentially harmful programs.
opendownloadmanager.com
73% remove it
 
Powered by Should I Remove It?

The file 5z3tkobx.qt3.exe has been seen being distributed by the following 3 URLs.

Remove 5z3tkobx.qt3.exe - Powered by Reason Core Security