doubletwistsetup.exe

doubleTwist Corporation

The application doubletwistsetup.exe by doubleTwist has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
doubleTwist Corporation  (signed and verified)

MD5:
e5bc0f3baa7f19bff4121f4a7389dece

SHA-1:
3a326dbde85f3e29e139bed97f10b15322cbb825

SHA-256:
b73f6b57d24f1977b4173e9aea7bc24271d6311f9f0fcae1ce2be6d6d85d601f

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
12/26/2024 12:25:12 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
8.6973

Fortinet FortiGate
Adware/OpenCandy
7/8/2014

McAfee
Adware-OpenCandy.dll
5600.7075

Reason Heuristics
PUP.Installer.doubleTwistCorporation.Q
14.7.10.2

Trend Micro House Call
ADW_OPENCANDY
7.2.189

Trend Micro
ADW_OPENCANDY
10.465.08

File size:
1.2 MB (1,297,880 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\doubletwistsetup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/22/2011 12:18:55 PM

Valid to:
2/23/2012 12:18:54 PM

Subject:
CN=doubleTwist Corporation, O=doubleTwist Corporation, L=San Francisco, S=CA, C=US

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012E4E904F9E

File PE Metadata
Compilation timestamp:
9/9/2009 9:23:23 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:imJf0O671i2pESg49SDH84yaevHYdhaIipR+LgLAKT:iZfdpESL9SDH8nbHYdhMR+Ur

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.3314

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

Remove doubletwistsetup.exe - Powered by Reason Core Security