wajam_install.exe

technologiesaintdenis.com

The application wajam_install.exe by technologiesaintdenis.com has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Open Downloader Manager by Installer Technology Co which is a potentially unwanted software program. The file has been seen being downloaded from plateau-technologies.com and multiple other hosts.
Publisher:
technologiesaintdenis.com  (signed and verified)

MD5:
eaf9d498ef570c9cb8438e94014a853a

SHA-1:
51ab2379c9a9d995d2501d3c20b8afebe8630da2

SHA-256:
fbffdcc6aafeb38b1a2515ceb8d70fbe218936d2f50923de3ab830f89b4d06a3

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
11/1/2024 3:34:24 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Searcher.2792
9.0.1.0108

NANO AntiVirus
Trojan.Nsis.Wajam.dqgtqq
0.30.16.1110

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Trend Micro House Call
Suspicious_GEN.F47V0416
7.2.108

Zillya! Antivirus
Trojan.Win32.1DB12147
2.0.0.2141

File size:
2.2 MB (2,357,680 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\1\wajam_install.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
2/9/2015 12:00:00 AM

Valid to:
2/9/2016 11:59:59 PM

Subject:
CN=technologiesaintdenis.com, OU=Software Development, O=technologiesaintdenis.com, L=Montreal, S=Quebec, C=CA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5C8520910142CFB327393EC3AF836FDB

File PE Metadata
Compilation timestamp:
12/5/2009 10:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:effOsNwgmTRndJD1+obUXBr8yaGzxJUoUXM+NH:wfsR/1JbUXBrKGkvMu

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Entropy:
7.9929

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file wajam_install.exe has been discovered within the following program.

Open Downloader Manager  by Installer Technology Co
ODM is a download manager that plugs into various web browsers (IE, Chrome and Firefox). The installer is designed to bundle and offer various additional offers including toolbars and other potentially harmful programs.
opendownloadmanager.com
73% remove it
 
Powered by Should I Remove It?

The file wajam_install.exe has been seen being distributed by the following 4 URLs.

Remove wajam_install.exe - Powered by Reason Core Security