uploadingdesktop.exe

The application uploadingdesktop.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from uploading.com and multiple other hosts.
MD5:
fa24ba7aaa192ec0c1a6f3b820940ff0

SHA-1:
9fdff827d82e3baf3d9b0edeb2d273eafe3b7e79

SHA-256:
412929f5c1454b2ee0d4651610265a25b3e864ef2a68883ff84031601ab5b301

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
11/24/2024 1:51:40 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Conduit
4.0.3.14831

Bkav FE
W32.Clod682.Trojan
1.3.0.4959

Comodo Security
TrojWare.Win32.Agent.uebz
17987

Dr.Web
Adware.Conduit.6
9.0.1.0243

ESET NOD32
8.9587

K7 AntiVirus
Trojan
13.176.11540

Malwarebytes
PUP.Optional.Conduit
v2014.08.31.06

McAfee
Artemis!FA24BA7AAA19
5600.7022

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
23.00.65.14829

VIPRE Antivirus
Conduit
27718

File size:
1.1 MB (1,113,814 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\uploadingdesktop.exe

File PE Metadata
Compilation timestamp:
2/24/2012 8:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:YEqLwjAYgWdqzlR7xB9ESfjB+YDLDsyWMkHEdG5:HgWCxBmSfjB1L4L3KG5

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file uploadingdesktop.exe has been seen being distributed by the following 3 URLs.

Remove uploadingdesktop.exe - Powered by Reason Core Security