Allmyapps.exe

Allmyapps Desktop

Allmyapps

The application Allmyapps.exe by Allmyapps has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Allmyapps’.
Publisher:
Allmyapps SAS  (signed by Allmyapps)

Product:
Allmyapps Desktop

Version:
2.0.0.30

MD5:
ee0ddef09b34f43a74af248f5d27e264

SHA-1:
eec604994477a49f9f1be00951f27a1e986e7a12

SHA-256:
f7e6ab20a452cdc5d7dbf9f6ed9413121d81f3c4c29accbcd6b4e3d6db3fcb14

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 4:56:30 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.10.21.8

File size:
7 MB (7,392,120 bytes)

Product version:
2.0.0.30

Copyright:
Copyright (C) 2013

Original file name:
Allmyapps.exe

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\users\{user}\appdata\roaming\allmyapps\allmyapps.exe

Digital Signature
Signed by:

Authority:
Allmyapps

Valid from:
9/28/2010 5:56:10 AM

Valid to:
9/28/2011 5:56:10 AM

Subject:
E=contact@allmyapps.com, CN=api.allmyapps.com, O=Allmyapps, L=Paris, S=Some-State, C=FR

Issuer:
E=contact@allmyapps.com, CN=api.allmyapps.com, O=Allmyapps, L=Paris, S=Some-State, C=FR

Serial number:
00C2FB651E206DABD0

File PE Metadata
Compilation timestamp:
4/4/2014 7:57:54 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:fnVS1435tNTNksiYGUi5P0KfpM6oy6ac7MELkm+cB/XBgM1Vgj+HVKXfiPEWIZyq:fr35fXBethm5/MNrMd7vKi7iDTxt9

Entry address:
0x85C62

Entry point:
F7, D9, F6, DE, 87, D2, 02, FE, 81, C1, EE, EB, 0F, 00, 0D, E9, 1C, B4, 98, 81, E9, 3A, 57, 0F, 00, 8D, 3D, 17, D3, FB, 23, 29, C0, 69, F9, 96, C3, DC, 7E, E8, 0F, 00, 00, 00, 71, 08, 85, D7, 69, EF, BD, 39, F8, 26, 02, C9, 4E, 2B, C3, 5A, 74, 06, F7, C1, C4, BD, 08, AB, 04, D6, BE, 8D, C5, 00, 00, F7, C1, 63, DE, 5C, 4B, 81, F6, 82, 1F, 00, 00, F7, D8, 86, DC, 35, 2D, F8, 1A, 10, BE, EB, 0D, 00, 00, 3B, DF, 71, 07, 87, CD, 0F, CD, 0F, AF, C6, 81, F6, F1, 05, 00, 00, 8A, FD, F7, C1, 25, 11, AF, 9D, 81, E7...
 
[+]

Entropy:
7.1409

Code size:
618 KB (632,832 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Allmyapps

Command:
"C:\users\{user}\appdata\roaming\allmyapps\allmyapps.exe" startup


Remove Allmyapps.exe - Powered by Reason Core Security