pkmadv.exe

Download Helper

New IT Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application pkmadv.exe by New IT Limited has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the New IT Desktop Setup installer.
Publisher:
New IT Limited  (signed and verified)

Product:
Download Helper

Version:
2, 3, 4, 0

MD5:
92405bcd929590ea8bf18e25a90b4444

SHA-1:
0c359d41c59698ed1901e141cba23ecafd623556

SHA-256:
3e066ed8ffdbcb5152b24578431f83a1e5804394adacd12b9634746df0827b06

Scanner detections:
22 / 68

Status:
Adware

Explanation:
May bundle various unwanted software without adequate user consent.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/23/2024 10:49:01 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.4Shared
7.1.1

AhnLab V3 Security
Adware/Win32.Downloader
14.07.18

Avira AntiVirus
APPL/Downloader.Gen6
7.11.144.106

avast!
Win32:FourShared-D [PUP]
2014.9-140420

AVG
MultiBundle
2015.0.3499

Comodo Security
Application.Win32.4Shared.G
18135

Dr.Web
Trojan.StartPage.54023
9.0.1.0110

ESET NOD32
Win32/4Shared (variant)
8.9701

Fortinet FortiGate
Riskware/4Shared
4/20/2014

F-Prot
W32/4Shared.C2.gen
v6.4.7.1.166

G Data
Win32.Trojan-Downloader.Agent.BA
14.4.24

IKARUS anti.virus
Downloader.Win32.Agent
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.176.11806

Malwarebytes
PUP.Optional.4Shared
v2014.04.20.07

McAfee
PUP-FEP!92405BCD9295
5600.7155

NANO AntiVirus
Trojan.Win32.StartPage.cqwdoj
0.28.0.59288

Reason Heuristics
PUP.NewITLimited.G
14.4.19.21

Rising Antivirus
PE:PUF.4Shared!1.9C25
23.00.65.14418

Sophos
4Share Downloader
4.98

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28420

File size:
1.3 MB (1,331,568 bytes)

Product version:
2, 3, 4, 0

Copyright:
Copyright (C) 2013

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pkmadv.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/16/2012 12:16:05 PM

Valid to:
11/16/2013 10:30:34 AM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B2A165690BBAA

File PE Metadata
Compilation timestamp:
5/31/2013 10:41:24 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:zgFvyVFyuvGRWI0Gnl3UVP3zY8HEwpzxz0DLacT06K:zQqVFyKa3eP3zVHEwpdz0DucT5K

Entry address:
0xD376

Entry point:
E8, B2, 45, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 14, 34, 42, 00, 33, C5, 89, 45, FC, F6, 05, E4, 33, 42, 00, 01, 56, 74, 08, 6A, 0A, E8, 43, 35, 00, 00, 59, E8, 6C, 46, 00, 00, 85, C0, 74, 08, 6A, 16, E8, 6E, 46, 00, 00, 59, F6, 05, E4, 33, 42, 00, 02, 0F, 84, CA, 00, 00, 00, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC, FD, FF, FF, 66, 8C, 95, F8, FD, FF, FF, 66, 8C, 8D, EC, FD, FF...
 
[+]

Entropy:
7.6063

Code size:
106.5 KB (109,056 bytes)

Remove pkmadv.exe - Powered by Reason Core Security