xxgsgz5w.l03.exe

FastFreeInstall.com

This is the installer for Wajam, a potentially unwanted program that displays social media posts from the user's contacts in search results. The application xxgsgz5w.l03.exe by FastFreeInstall.com has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Open Downloader Manager by Installer Technology Co which is a potentially unwanted software program. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from wajam-download.com and multiple other hosts.
Publisher:
FastFreeInstall.com  (signed and verified)

MD5:
11983ae2d07c02cf2afda9c564c2f95d

SHA-1:
26c9fd3f195b755dec327002ab181e95c9b94d7f

SHA-256:
03ca72a3dd8cc79af52df1238766b3d573273dac3c25d6fdedc2f205632b7f0a

Scanner detections:
8 / 68

Status:
Adware

Analysis date:
11/27/2024 2:37:35 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Searcher.2673
9.0.1.0317

Malwarebytes
PUP.Optional.Wajam
v2014.11.13.12

McAfee
Artemis!11983AE2D07C
5600.6948

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.FastFreeInstall.L
14.11.13.0

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.26.3

VIPRE Antivirus
Wajam
34748

Zillya! Antivirus
Trojan.Win32.1DB12147
2.0.0.1981

File size:
2.2 MB (2,266,960 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\xxgsgz5w.l03.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/30/2014 7:00:00 PM

Valid to:
7/31/2015 6:59:59 PM

Subject:
CN=FastFreeInstall.com, OU=Insta-Download.com, O=FastFreeInstall.com, STREET=4115 Boul Saint-Laurent, L=Montreal, S=Quebec, PostalCode=H2W 1Y7, C=CA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009915504505808BBF6AAC2C2CD2A8C3BE

File PE Metadata
Compilation timestamp:
12/5/2009 4:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:4drMLz7rUMQs26FL1EG7TEtJJfE8Hlx0Gb3vTEw76HDqVmTih:crMOsPx+TM8Hlxp7YwGHFTA

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Entropy:
7.9912

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file xxgsgz5w.l03.exe has been discovered within the following program.

Open Downloader Manager  by Installer Technology Co
ODM is a download manager that plugs into various web browsers (IE, Chrome and Firefox). The installer is designed to bundle and offer various additional offers including toolbars and other potentially harmful programs.
opendownloadmanager.com
73% remove it
 
Powered by Should I Remove It?

The file xxgsgz5w.l03.exe has been seen being distributed by the following 4 URLs.

Remove xxgsgz5w.l03.exe - Powered by Reason Core Security