bubblewitchsaga_game_downloader.exe

File Validated

This is the InstallMetrix bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application bubblewitchsaga_game_downloader.exe by File Validated has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the InstallMetrix Software installer.
Publisher:
File Validated  (signed and verified)

MD5:
0c9d73e8bd9cee042ab576aa9fda58e3

SHA-1:
4f914e63a764f400b8bad0b81605074a20ef9f73

SHA-256:
57d23faad28cbcc38b50b6b49af42103535646eaa941664edaf0cd9265600940

Scanner detections:
12 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
1/13/2025 8:57:05 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Strictor.83978
5774816

AVG
Generic
2016.0.3111

Bitdefender
Gen:Variant.Adware.Strictor.83978
1.0.20.660

Dr.Web
Trojan.Domaiq.215
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.83978
10.0.0.5366

ESET NOD32
Win32/Adware.InstallMetrix.L application
7.0.302.0

F-Secure
Gen:Variant.Adware.Strictor
5.13.68

G Data
Gen:Variant.Adware.Strictor.83978
15.5.25

herdProtect (fuzzy)
2015.8.9.15

MicroWorld eScan
Gen:Variant.Adware.Strictor.83978
16.0.0.396

NANO AntiVirus
Trojan.Script.Autoit.drhunc
0.30.24.1357

Rising Antivirus
PE:Trojan.Win32.Injector.fw!1075357566
23.00.65.15510

File size:
1.1 MB (1,144,080 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\7bfmp0w1\bubblewitchsaga_game_downloader.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
2/26/2015 4:00:00 PM

Valid to:
2/27/2016 3:59:59 PM

Subject:
CN=File Validated, OU=File Validated, O=File Validated, L=San Francisco, S=California, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1C96D72469336B0857534EE1D7E9701D

File PE Metadata
Compilation timestamp:
4/15/2015 11:53:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:Ltb20pkaCqT5TBWgNQ7aBQ8P/tvmjcl/qe1Fyog46AU:IVg5tQ7aBpP/tvmAjWoP5U

Entry address:
0x25F74

Entry point:
E8, 6A, CE, 00, 00, E9, 7F, FE, FF, FF, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 70, A3, 4B, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03, 00...
 
[+]

Entropy:
7.0551

Code size:
557.5 KB (570,880 bytes)

Remove bubblewitchsaga_game_downloader.exe - Powered by Reason Core Security