wajam_install.exe

Wajam

Super Downloads

The file is part of Wajam, a web browser extension that injects social search integration into various search portals such as Google. The application wajam_install.exe by Super Downloads has been detected as adware by 8 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.wajam-download.com.
Publisher:
Super Downloads  (signed and verified)

Product:
Wajam

Version:
2.11

MD5:
66c6b3319ef49cceac1a4231b88d3ce4

SHA-1:
829af6c7f1e418751c9a7e0fbe3e76883a785c1c

SHA-256:
1e5036f2e8009f6957f2230d87132438b66982d07bd873aca8eb612167e4e135

Scanner detections:
8 / 68

Status:
Adware

Analysis date:
12/24/2024 2:12:54 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
AdInject.Wajam
2015.0.3562

Dr.Web
Adware.Searcher.2467
9.0.1.046

ESET NOD32
Win32/Wajam
8.9429

Malwarebytes
PUP.Optional.Wajam
v2014.02.15.06

NANO AntiVirus
Trojan.Win32.Obfuscate.ctkvqm
0.28.0.57630

Reason Heuristics
PUP.SuperDownloads.N
14.2.15.18

Trend Micro House Call
TROJ_GE.21F04DFD
7.2.46

VIPRE Antivirus
Wajam
26504

File size:
1012.4 KB (1,036,720 bytes)

Copyright:
© Wajam. All right reserved.

Trademarks:
Wajam – Great minds search alike.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\wajam_install.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/12/2013 1:00:00 AM

Valid to:
12/12/2016 12:59:59 AM

Subject:
CN=Super Downloads, O=Super Downloads, STREET="4115, boul. St-Laurent", L=Montreal, S=Quebec, PostalCode=H2W 1Y7, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EDE829ED1E6AB7C7A9D6279BB970B503

File PE Metadata
Compilation timestamp:
12/5/2009 11:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:jRztjuAbA4y899rj9LOf2ss6Glu1b5SbU26iZ9pRL5AWTlLS:jJf19ZFOfR8gSn6iZHRS

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Entropy:
7.9901  (probably packed)

Code size:
24.5 KB (25,088 bytes)

The file wajam_install.exe has been seen being distributed by the following URL.

Remove wajam_install.exe - Powered by Reason Core Security