wxkeg45p.4r3.exe

FastFreeInstall.com

This is the installer for Wajam, a potentially unwanted program that displays social media posts from the user's contacts in search results. The application wxkeg45p.4r3.exe by FastFreeInstall.com has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Open Downloader Manager by Installer Technology Co which is a potentially unwanted software program. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from 113.171.224.168 and multiple other hosts.
Publisher:
FastFreeInstall.com  (signed and verified)

MD5:
c80db840ac2597b988e1c88b5d7015f2

SHA-1:
343f9ab838ed64e862bbf8ff0ce723222ca97f90

SHA-256:
ce755f50d228d92aca01a54b81bd534f188a93e74c73160e008e7cc81480bba0

Scanner detections:
17 / 68

Status:
Adware

Analysis date:
11/27/2024 3:58:41 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11959248
789

Bitdefender
Trojan.Generic.11959248
1.0.20.1705

Dr.Web
Threat.Undefined
9.0.1.0268

Emsisoft Anti-Malware
Trojan.Generic.11959248
8.14.12.07.12

F-Prot
W32/A-77a4fa28
v6.4.7.1.166

F-Secure
Trojan.Generic.11959248
11.2014-07-12_1

G Data
Trojan.Generic.11959248
14.12.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.7.8.0

Malwarebytes
PUP.Optional.Wajam
v2014.09.25.06

MicroWorld eScan
Trojan.Generic.11959248
15.0.0.1023

nProtect
Trojan.Generic.11959248
14.10.22.01

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.FastFreeInstall.L
14.10.8.13

Trend Micro House Call
TROJ_GE.6E5867BF
7.2.268

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.26.3

VIPRE Antivirus
Wajam
33420

Zillya! Antivirus
Trojan.Win32.1DB12147
2.0.0.1933

File size:
2.2 MB (2,266,800 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\wxkeg45p.4r3.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/30/2014 9:00:00 PM

Valid to:
7/31/2015 8:59:59 PM

Subject:
CN=FastFreeInstall.com, OU=Insta-Download.com, O=FastFreeInstall.com, STREET=4115 Boul Saint-Laurent, L=Montreal, S=Quebec, PostalCode=H2W 1Y7, C=CA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009915504505808BBF6AAC2C2CD2A8C3BE

File PE Metadata
Compilation timestamp:
12/5/2009 8:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:UU6Z/xfp8bkTK2di7x2VciXuzhc/7dCCbn0Y5eINqFpB:d6Z/z8bkTImci8qACF5u

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file wxkeg45p.4r3.exe has been discovered within the following program.

Open Downloader Manager  by Installer Technology Co
ODM is a download manager that plugs into various web browsers (IE, Chrome and Firefox). The installer is designed to bundle and offer various additional offers including toolbars and other potentially harmful programs.
opendownloadmanager.com
73% remove it
 
Powered by Should I Remove It?

The file wxkeg45p.4r3.exe has been seen being distributed by the following 6 URLs.

http://113.171.224.168/.../WIE_2.15.2.5.exe

http://i.vertitechnologygroup.com/inst/software/58469E13-5DA8-4677-8D99-59C645547170/.../WIE_2.15.2.5.exe

Remove wxkeg45p.4r3.exe - Powered by Reason Core Security