start.exe

CWBButtonDemo Application

DOUBLE OPT MEDIA PARTNERS LLC

The application start.exe by DOUBLE OPT MEDIA PARTNERS has been detected as adware by 6 anti-malware scanners.
Publisher:
DOUBLE OPT MEDIA PARTNERS LLC  (signed and verified)

Product:
CWBButtonDemo Application

Description:
PreInstaller

Version:
1, 0, 0, 1

MD5:
58e95485360d2bfae4b11a195dbc9615

SHA-1:
030d32b538b2e6ac62ad73423c94acf3e74fbc67

SHA-256:
8d860f927836fcf44e7d262df471e4ed2901c83c6f6c4e594f2b30677b99f60e

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
12/25/2024 12:57:16 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-150324

Baidu Antivirus
Trojan.Win32.Inject
4.0.3.141212

Dr.Web
Trojan.DownLoader11.45909
9.0.1.05190

Kaspersky
Trojan.Win32.Inject
15.0.0.543

Panda Antivirus
Generic Suspicious
14.12.12.11

Reason Heuristics
PUP.Installer.DoubleOpt Media
15.1.26.11

File size:
809.4 KB (828,848 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2000

Original file name:
CWBButtonDemo.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\worldwide web research\start.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
10/9/2014 6:00:00 PM

Valid to:
12/12/2017 5:00:00 AM

Subject:
CN=DOUBLE OPT MEDIA PARTNERS LLC, O=DOUBLE OPT MEDIA PARTNERS LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0289DEB63998EB06A29C8E7F34C73E75

File PE Metadata
Compilation timestamp:
11/7/2014 7:58:07 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:pl3U8twkffiyYB9q6b+0o4Aq7D894Lqvrn4UVE4FeibfphxUpd4:DmyYB9q6b+0NpLqvrnFBBUpd4

Entry address:
0x4A4A8

Entry point:
E8, FD, E6, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 90, 44, 49, 00, E8, C2, 0D, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 38, ED, 49, 00, 77, 22, 6A, 04, E8, 00, E9, 00, 00, 59, 83, 65, FC, 00, 56, E8, 62, F6, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, CE, 0D, 00, 00, C3, 6A, 04, E8, E3, E7, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 83, 3D, CC, D9, 49, 00, 00, 75, 18, E8, 33, DC, 00, 00, 6A, 1E, E8, 5B, DA, 00, 00, 68, FF, 00, 00, 00, E8, 53, 3F, 00, 00, 59, 59, A1...
 
[+]

Entropy:
6.9296

Code size:
485.5 KB (497,152 bytes)

Remove start.exe - Powered by Reason Core Security