pro architect.exe

Cadsoft Downloader

Cadsoft Corporation

The application pro architect.exe by Cadsoft has been detected as adware by 35 anti-malware scanners. This setup program installs potentially unwanted software on the user's PC at the same time as the expected/marketing software, without adequate consent. The program is typically installed via a form of malvertising
Publisher:
Cadsoft Corporation  (signed and verified)

Product:
Cadsoft Downloader

Version:
1.0.0

MD5:
1cda21e4a78be2a5986b78b793f7ae33

SHA-1:
a7cef8360ddb677603d86949c239ce39d8ec9476

SHA-256:
3b5ee0291259eac84ec4ed5acced3b0d25e8d225a46e9986fc988ba4d6affda6

Scanner detections:
35 / 68

Status:
Adware

Analysis date:
11/27/2024 9:38:48 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.1042735
792

Agnitum Outpost
Trojan.Rogue
7.1.1

AhnLab V3 Security
PUP/Win32.Downloader
2013.09.13

Avira AntiVirus
Adware/Dealeem.B
7.11.102.44

avast!
Win32:Adware-gen [Adw]
2014.9-141205

AVG
Brat
2015.0.3270

Baidu Antivirus
Malware.Win32.SecurityDownloader
4.0.3.14125

Bitdefender
Adware.Generic.1042735
1.0.20.1695

Clam AntiVirus
WIN.Downloader.Agent-1281
0.98/21411

Comodo Security
Application.Win32.PCMega.L
19945

Dr.Web
Adware.Downware.376
9.0.1.05190

Emsisoft Anti-Malware
Adware.Generic.1042735
8.14.12.05.03

ESET NOD32
Win32/Adware.PCMega
8.10645

Fortinet FortiGate
Adware/DownloadWare
12/5/2014

F-Prot
W32/Adware.AKQE
4.6.5.141

F-Secure
Adware.Generic.1042735
11.2014-05-12_6

G Data
Adware.Generic.1042735
14.12.24

IKARUS anti.virus
SoftwareBundler
t3scan.2.0.127

K7 AntiVirus
Riskware
13.185.13853

Kaspersky
not-a-virus:Downloader.Win32.Agent
15.0.0.543

Malwarebytes
Adware.Bundler
v2014.12.05.03

McAfee
Downloader-FMJ
5600.6926

Microsoft Security Essentials
SoftwareBundler:Win32/Protlerdob
1.163.1557.0

NANO AntiVirus
Riskware.Win32.Agent.czmlms
0.28.6.62995

nProtect
Trojan/W32.Agent.1008582
13.09.12.03

Panda Antivirus
Trj/Dtcontx.C
14.12.05.03

Reason Heuristics
PUP.CadsoftCorporation
15.2.14.11

Rising Antivirus
PE:Adware.PCMega!6.327
23.00.65.141203

Sophos
Generic PUA JF
4.91

Trend Micro House Call
TROJ_SPNR.08CM13
7.2.339

Trend Micro
TROJ_SPNR.08CM13
10.465.05

Vba32 AntiVirus
AdWare.DownloadWare
3.12.24.2

VIPRE Antivirus
Trojan.Win32.Generic
21406

ViRobot
Backdoor.Win32.A.ZAccess.394869
2011.4.7.4223

Zillya! Antivirus
Downloader.Agent.Win32.223200
2.0.0.1972

File size:
1 MB (1,067,288 bytes)

Product version:
1.0.0

Copyright:
© Cadsoft Corporation

Original file name:
proarchitect.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/28/2012 1:19:37 PM

Valid to:
3/29/2013 1:19:37 PM

Subject:
E=support@cadsoft.com, CN=Cadsoft Corporation, O=Cadsoft Corporation, L=Guelph, S=ON, C=CA

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121832E553260C195EFF0851543EA5F4BD4

File PE Metadata
Compilation timestamp:
5/6/2009 10:38:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:Zx4Mi4+EaWyZDAbKh6tBoJU0DuF4jovaVGMwhJE/XBA:dcEaWjrjiA4jova8Mz/xA

Entry address:
0x8B902

Entry point:
E8, 2D, 79, 00, 00, E9, 16, FE, FF, FF, 8B, 44, 24, 04, 33, C9, 3B, 04, CD, 90, 46, 4D, 00, 74, 12, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0C, 6A, 0D, 58, C3, 8B, 04, CD, 94, 46, 4D, 00, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, C3, E8, 5E, 3D, 00, 00, 85, C0, 75, 06, B8, F8, 47, 4D, 00, C3, 83, C0, 08, C3, E8, 4B, 3D, 00, 00, 85, C0, 75, 06, B8, FC, 47, 4D, 00, C3, 83, C0, 0C, C3, 56, E8, E7, FF, FF, FF, 8B, 4C, 24, 08, 51, 89, 08, E8, 8D, FF, FF, FF, 59, 8B, F0...
 
[+]

Entropy:
6.3673

Code size:
684 KB (700,416 bytes)

Remove pro architect.exe - Powered by Reason Core Security