wajam_install.exe

Wajam

Super Downloads

The file is part of Wajam, a web browser extension that injects social search integration into various search portals such as Google. The application wajam_install.exe by Super Downloads has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.wajam-download.com.
Publisher:
Super Downloads  (signed and verified)

Product:
Wajam

Version:
2.13

MD5:
185d2ab479129085be9337e6758a9da9

SHA-1:
28c3f03834272efca640224ba6c86ba26829bf13

SHA-256:
8a7c8896e26bc8dd63cfdd33db92d36ba75135e1262e21a3dca74e692bb1c030

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
12/24/2024 2:16:55 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
AdInject.Wajam
2015.0.3554

Dr.Web
Adware.Searcher.2467
9.0.1.054

ESET NOD32
Win32/Wajam
8.9461

Malwarebytes
PUP.Optional.Wajam
v2014.02.23.11

McAfee
Artemis!185D2AB47912
5600.7210

NANO AntiVirus
Trojan.Win32.Obfuscate.ctkvqm
0.28.0.57630

Reason Heuristics
PUP.SuperDownloads.N
14.2.23.23

Trend Micro House Call
TROJ_GEN.F47V0221
7.2.54

VIPRE Antivirus
Wajam
26782

XVirus List
Win.Detected
2.3.31

File size:
1015.5 KB (1,039,912 bytes)

Copyright:
© Wajam. All right reserved.

Trademarks:
Wajam – Great minds search alike.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\wajam_install.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/11/2013 4:00:00 PM

Valid to:
12/11/2016 3:59:59 PM

Subject:
CN=Super Downloads, O=Super Downloads, STREET="4115, boul. St-Laurent", L=Montreal, S=Quebec, PostalCode=H2W 1Y7, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EDE829ED1E6AB7C7A9D6279BB970B503

File PE Metadata
Compilation timestamp:
12/5/2009 2:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:LnXsw7NsWFcgy/Zmck+oLhW5BZD6LKoKEjbinR9DkBMhzV2h19ftn0YHaC4HHrpr:Lnc6NsWObYc135rDBcbOL5mft0tivY

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Entropy:
7.9902

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file wajam_install.exe has been seen being distributed by the following URL.

Remove wajam_install.exe - Powered by Reason Core Security