sky_bubbles.exe

Alawar Install Manager

Alawar

The application sky_bubbles.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from download.jajagames.com.
Publisher:
Alawar

Product:
Alawar Install Manager

Version:
1.0

MD5:
febd913074a948d62af79365fe8bf5bb

SHA-1:
513ed26728f40ac6a8de73e91c1877d93e5cbbdc

SHA-256:
5c7d6ba69d20430ffc44627f92f34340cff0a44ee2a3eacd6fbf9de21c74c77d

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
11/23/2024 11:47:07 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Zugo.C.1
7.11.175.114

avast!
NSIS:Bundlore-B [Adw]
2014.9-141216

Baidu Antivirus
Trojan.Win32.Genome
4.0.3.141216

Bkav FE
W32.Clod67e.Trojan
1.3.0.4959

Dr.Web
Trojan.DownLoader10.23547
9.0.1.0350

ESET NOD32
Win32/Adware.Bundlore
8.10482

Fortinet FortiGate
Riskware/Bundlore
12/16/2014

K7 AntiVirus
Adware
13.183.13521

Kaspersky
Trojan-Downloader.Win32.Genome
14.0.0.2789

McAfee
Artemis!FEBD913074A9
5600.6915

NANO AntiVirus
Riskware.Text.Babylon.cwhyhv
0.28.2.62440

Quick Heal
TrojanDownloader.Genome.r5
12.14.14.00

Trend Micro House Call
ADW_AGENT
7.2.350

Trend Micro
ADW_AGENT
10.465.16

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Bundlore
33528

File size:
349.5 KB (357,928 bytes)

Copyright:
© Alawar (AlawarSkyBubbles_C81_AUTO)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\sky_bubbles.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:tspCpysdsO5niFX62O9IHYWCIM5OR2tejie+C0tqd/QpPIJ887pgSyiX+x+:UCvsgqqHI26jidC0tirJPpdZP

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9256

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file sky_bubbles.exe has been seen being distributed by the following URL.

Remove sky_bubbles.exe - Powered by Reason Core Security