garmin nuvi 1340.exe

B-Softwares

The application garmin nuvi 1340.exe by B-Softwares has been detected as a potentially unwanted program by 5 anti-malware scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from dc543.4shared.com.
Publisher:
B-Softwares  (signed and verified)

MD5:
634ba7dadbd14add2cd679887d83abab

SHA-1:
0af2234a2b2f3cc87d7f3bb243b7e7b2940582c2

SHA-256:
f7202d529e7bf1e39461b1f1897868710413ff7cc4a0c2a15ad8507767c6a90b

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 1:04:00 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader
2015.0.3420

Dr.Web
Adware.Downware.393
9.0.1.0189

IKARUS anti.virus
Win32.AdWare
t3scan.2.0.127

NANO AntiVirus
Trojan.Win32.Downware2.bbtaan
0.26.0.53954

Trend Micro House Call
TROJ_GEN.F47V0701
7.2.189

File size:
474.1 KB (485,472 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\garmin nuvi 1340.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/20/2011 1:00:00 AM

Valid to:
12/20/2012 12:59:59 AM

Subject:
CN=B-Softwares, O=B-Softwares, STREET=32 pinglewood, L=brampton, S=ontario, PostalCode=l6p1e3, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6FBC41EAA1522F94B9C6E1654CE5E39A

File PE Metadata
Compilation timestamp:
6/29/2012 2:32:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
12288:S1cA2PzTm/k0u1sUlp6HBNBBL9VGXY/NMQESyRu:Ec9PzTak09cwhNBXVGXY/YSX

Entry address:
0x1110

Entry point:
55, 89, E5, 83, EC, 18, C7, 04, 24, 02, 00, 00, 00, FF, 15, 98, C5, 44, 00, E8, F8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 83, EC, 18, C7, 04, 24, 01, 00, 00, 00, FF, 15, 98, C5, 44, 00, E8, D8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 53, 83, EC, 14, 8B, 45, 08, 8B, 00, 8B, 00, 3D, 91, 00, 00, C0, 77, 3B, 3D, 8D, 00, 00, C0, 72, 4B, BB, 01, 00, 00, 00, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 08, 00, 00, 00, E8, D3, 3A, 01, 00, 83, F8, 01, 0F, 84, FF, 00, 00, 00, 85, C0...
 
[+]

Code size:
173 KB (177,152 bytes)

The file garmin nuvi 1340.exe has been seen being distributed by the following URL.

Remove garmin nuvi 1340.exe - Powered by Reason Core Security