saveas.exe

Asper

Maxiget Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application saveas.exe by Maxiget Limited has been detected as adware by 31 anti-malware scanners. The file has been seen being downloaded from files-download-59.com.
Publisher:
C Vital  (signed by Maxiget Limited)

Product:
Asper

Description:
LeaveLoadLoud

Version:
4, 10, 28, 0

MD5:
836f90f89fb689cb286ca6d33ced94f6

SHA-1:
5fbc835a85a88d642205e4d1941a88ef42c66d25

SHA-256:
e1cf82e58854d91c8c0d65fd0831dc48f240724d617f7c2caa21a5beee285986

Scanner detections:
31 / 68

Status:
Adware

Explanation:
This is a modified installer version of the software and bundles additional offers including adware.

Analysis date:
11/23/2024 2:46:50 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.540149
354

Agnitum Outpost
PUA.4Shared
7.1.1

AhnLab V3 Security
PUP/Win32.Downloader
2015.02.19

Avira AntiVirus
APPL/Downloader.Gen4
7.11.202.28

avast!
Win32:PUP-gen [PUP]
2014.9-160215

AVG
Generic
2017.0.2832

Baidu Antivirus
Adware.Win32.4Shared
4.0.3.16215

Bitdefender
Gen:Variant.Kazy.522321
1.0.20.230

Clam AntiVirus
Win.Adware.Purd
0.98/20118

Comodo Security
Application.Win32.4shared.GSP
20900

Dr.Web
Adware.Downware.1751, Adware.Downware.10005
9.0.1.046

Emsisoft Anti-Malware
Gen:Variant.Kazy.540149
8.16.02.15.03

ESET NOD32
Win32/4Shared.AI potentially unwanted application
10.7.0.302.0

F-Prot
W32/S-367fc245
v6.4.7.1.166

F-Secure
Gen:Variant.Kazy.540149
11.2016-15-02_2

G Data
Gen:Variant.Kazy.522321
16.2.24

IKARUS anti.virus
PUA.4Shared
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.191.14667

Kaspersky
not-a-virus:Downloader.Win32.4Shared
14.0.0.657

McAfee
4shared
5600.6488

MicroWorld eScan
Gen:Variant.Kazy.522321
17.0.0.138

NANO AntiVirus
Trojan.Win32.4Shared.dmovte
0.30.0.64812

Norman
Gen:Variant.Kazy.522321
11.20160215

nProtect
Adware.PURD
15.02.27.01

Panda Antivirus
Trj/Genetic.gen
16.02.15.03

Qihoo 360 Security
Malware.QVM07.Gen
1.0.0.1015

Reason Heuristics
PUP.New IT Limited.Maxiget (M)
16.2.15.15

Sophos
PUA 'Downloader'
5.15

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4150696
36694

Zillya! Antivirus
Backdoor.CPEX.Win32.30311
2.0.0.2076

File size:
56.6 KB (57,976 bytes)

Product version:
4, 10, 28, 0

Copyright:
Conical (c)

Trademarks:
TM2-15

Original file name:
lltmoping.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\saveas.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/11/2014 4:36:00 AM

Valid to:
8/14/2016 11:41:32 PM

Subject:
CN=Maxiget Limited, O=Maxiget Limited, L=Limassol, S=Cyprus, C=CY

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B83CBF523FA3B

File PE Metadata
Compilation timestamp:
3/10/2015 8:56:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:A9ZhcTYS3uUWXhdfLLCsOeMMhZVEJAUTN/sG9ZT6bhbgbUbNpCq/YbZ:UbauU8hNWsfEJxN/v6bhbgbUb7IbZ

Entry address:
0x5187

Entry point:
55, 8B, EC, 83, EC, 44, 56, FF, 15, 54, 60, 40, 00, 8B, F0, 8A, 06, 3C, 22, 74, 10, 3C, 20, 7E, 1E, 46, 80, 3E, 20, 7F, FA, EB, 16, 3C, 22, 74, 11, 46, 8A, 06, 84, C0, 75, F5, 3C, 22, 75, 07, EB, 04, 3C, 20, 7F, 07, 46, 8A, 06, 84, C0, 75, F5, 83, 65, E8, 00, 8D, 45, BC, 50, FF, 15, 30, 60, 40, 00, E8, 5B, 00, 00, 00, 68, 04, 80, 40, 00, 68, 00, 80, 40, 00, E8, 32, 00, 00, 00, F6, 45, E8, 01, 59, 59, 74, 06, 0F, B7, 45, EC, EB, 03, 6A, 0A, 58, 50, 56, 6A, 00, 6A, 00, FF, 15, 2C, 60, 40, 00, 50, E8, B7, FC...
 
[+]

Entropy:
5.3490

Developed / compiled with:
Microsoft Visual C++

Code size:
17 KB (17,408 bytes)

The file saveas.exe has been seen being distributed by the following URL.

Remove saveas.exe - Powered by Reason Core Security