freedownloadmanager.exe

Windows Internet Explorer

High Tech Marketing SL

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application freedownloadmanager.exe, “Archivo autoextractor de archivos CAB de Win32” by High Tech Marketing SL has been detected as adware by 2 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from tus-descargas.com.
Publisher:
Microsoft Corporation  (signed by High Tech Marketing SL)

Product:
Windows® Internet Explorer

Description:
Archivo autoextractor de archivos CAB de Win32

Version:
9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)

MD5:
86d87f8386a6e33279c769c2032284d7

SHA-1:
16e1a2880099512141e1a5a06f5b338d5239f0c0

SHA-256:
398127688a64b4a5977eaad2bd833c6a37459468a2427b64ed41a820063271dd

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
11/27/2024 3:30:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Montiera.HighTechMarketing (M)
15.8.13.14

Trend Micro House Call
TROJ_GEN.F47V1004
7.2.225

File size:
5.1 MB (5,306,712 bytes)

Product version:
9.00.8112.16421

Copyright:
© Microsoft Corporation. Reservados todos los derechos.

Original file name:
WEXTRACT.EXE .MUI

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\users\{user}\downloads\freedownloadmanager.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/3/2012 8:00:00 PM

Valid to:
9/4/2013 7:59:59 PM

Subject:
CN=High Tech Marketing SL, O=High Tech Marketing SL, L=Huesca, S=Huesca, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6EB1401795602AF167EEDEC95628B32C

File PE Metadata
Compilation timestamp:
3/8/2011 8:46:37 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:AkpF/9wSfCKooQB9OiaSX2scthXI2y12ycMdIkApEz07:ppF7CKJoTwXI202gxApEi

Entry address:
0x6B42

Entry point:
E8, 5D, 07, 00, 00, E9, 4D, FD, FF, FF, CC, CC, CC, CC, CC, 3B, 0D, C4, C2, 00, 01, 75, 03, C2, 00, 00, E9, D9, 07, 00, 00, CC, CC, CC, CC, CC, FF, 25, 7C, 12, 00, 01, CC, CC, CC, CC, CC, CC, FF, 25, 78, 12, 00, 01, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 81, EC, D0, 02, 00, 00, A1, C4, C2, 00, 01, 33, C5, 89, 45, FC, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC, FD, FF, FF, 66, 8C, 95, F8, FD, FF, FF, 66, 8C, 8D, EC, FD...
 
[+]

Code size:
43.5 KB (44,544 bytes)

The file freedownloadmanager.exe has been seen being distributed by the following URL.

Remove freedownloadmanager.exe - Powered by Reason Core Security