grandtheftauto_downloader.exe

Required Installs

This is the InstallMetrix bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application grandtheftauto_downloader.exe by Required Installs has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the InstallMetrix Software installer.
Publisher:
Required Installs  (signed and verified)

MD5:
f4d3e46165f4b023beb76ab5a497743b

SHA-1:
778ee8715d759bbb9524e4b6ba4eb003571f2a6a

SHA-256:
34f2d1c786d499601ea066ca5e3f09e7038a65ff56e450044a858f506a1f02ac

Scanner detections:
17 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 4:46:26 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Strictor.83978
5669309

Avira AntiVirus
ADWARE/InstallMet.AF
8.3.1.6

Arcabit
Trojan.Adware.Strictor.D1480A
1.0.0.425

AVG
Generic
2016.0.3089

Bitdefender
Gen:Variant.Adware.Strictor.83978
1.0.20.775

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.InstallMetrix.LQL
22332

Dr.Web
Trojan.Domaiq.243
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.83978
10.0.0.5366

ESET NOD32
Win32/Adware.InstallMetrix.L application
7.0.302.0

F-Prot
W32/Strictor.AG.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Strictor
5.14.151

G Data
Gen:Variant.Adware.Strictor.83978
15.6.25

K7 AntiVirus
Adware
13.204.16137

MicroWorld eScan
Gen:Variant.Adware.Strictor.83978
16.0.0.465

NANO AntiVirus
Trojan.Script.Autoit.drhunc
0.30.24.1636

Norman
Gen:Variant.Adware.Strictor.83978
02.06.2015 14:23:46

File size:
1.1 MB (1,146,128 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software

Language:
English (United Kingdom)

Common path:
C:\users\{user}\downloads\grandtheftauto_downloader.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/30/2015 8:00:00 PM

Valid to:
3/30/2016 7:59:59 PM

Subject:
CN=Required Installs, OU=Required Installs, O=Required Installs, L=San Francisco, S=California, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
74914C51A08AB22D3452DC64C0635134

File PE Metadata
Compilation timestamp:
4/24/2015 6:59:12 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:Utb20pkaCqT5TBWgNQ7aeQ8P/tdmjcl/qe1FyF86Af:9Vg5tQ7aepP/tdmAjWO5f

Entry address:
0x25F74

Entry point:
E8, 6A, CE, 00, 00, E9, 7F, FE, FF, FF, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 70, A3, 4B, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03, 00...
 
[+]

Entropy:
7.0579

Code size:
557.5 KB (570,880 bytes)

Remove grandtheftauto_downloader.exe - Powered by Reason Core Security