wajam_install.exe

Wajam

Wajam

The file is part of Wajam, a web browser extension that injects social search integration into various search portals such as Google. The application wajam_install.exe by Wajam has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.wajam.com.
Publisher:
Wajam  (signed and verified)

Product:
Wajam

Version:
1.77

MD5:
4d5c96cc27a42e817fae2fc5fd4ec6d9

SHA-1:
c1ec7b55c5d37d314f01afcf47a48083681977e7

SHA-256:
d3cb5d7d31b37927b044b142e2f9dbce2c270551372e8d4df62b7ba270cb14e5

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
2/24/2025 9:22:14 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.Wajam.N
188838

Dr.Web
Adware.Searcher.2467
9.0.1.0111

ESET NOD32
Win32/Wajam
8.9190

Malwarebytes
PUP.Optional.Wajam.A
v2014.04.21.01

Reason Heuristics
PUP.Wajam.N
14.8.7.17

VIPRE Antivirus
Wajam
24664

File size:
450 KB (460,848 bytes)

Copyright:
© Wajam. All right reserved.

Trademarks:
Wajam – Great minds search alike.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\wajam_install.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/16/2012 2:00:00 AM

Valid to:
5/17/2013 1:59:59 AM

Subject:
CN=Wajam, O=Wajam, STREET="4115 Boulevard Saint-Laurent suite #200", L=Montreal, S=Quebec, PostalCode=H2W1Y7, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
175B7FEB5E5C08B00F3B710CDD9D93EB

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:twJpdb+69zf2uxQUYvn1/GOO0prZxDVAv:tmLn9zjxzYEO1rZxxAv

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file wajam_install.exe has been seen being distributed by the following URL.

Remove wajam_install.exe - Powered by Reason Core Security