أهمية المحاسبة التحليلية وأثرها في المؤسسة الإقتصادية.exe

4shared Desktop Setup

New IT Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application أهمية المحاسبة التحليلية وأثرها في المؤسسة الإقتصادية.exe by New IT Limited has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the New IT Desktop Setup installer. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension.
Publisher:
New IT Solutions  (signed by New IT Limited)

Product:
4shared Desktop Setup

Version:
4.0.3.1

MD5:
b2d8f42fd2389bbb34deccc9599dc943

SHA-1:
77a96275ec269ed6f03b73e7826224a90fca50a1

SHA-256:
f5631d8e5e2621dbf997538a5c02ac412fb0ec1d686373c18a554c492dbfc0ff

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Bundles that Ask.com toolbar as a third-party offer, a web browser extension that may modify a user's search and home pages.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 11:37:52 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Ask
7.1.1

avast!
Win32:Toolbar-N [PUP]
2014.9-150131

Bkav FE
W32.Clod979.Trojan
1.3.0.4613

Comodo Security
Application.Win32.NewIT.B
17947

Dr.Web
Adware.Downware.1417
9.0.1.031

ESET NOD32
Win32/Bundled.Toolbar.Ask.D potentially unsafe application
9.7.0.302.0

Malwarebytes
PUP.Optional.4Shared
v2015.01.31.07

McAfee
Artemis!A8563F17A5F3
5600.6869

NANO AntiVirus
Trojan.Win32.Downware.cumjmn
0.28.0.58491

Reason Heuristics
PUP.Installer.New IT Limited
15.1.31.8

Rising Antivirus
PE:PUF.4Shared!1.9C25
23.00.65.15129

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10082

Trend Micro House Call
TROJ_GEN.F47V0831
7.2.31

File size:
5.5 MB (5,770,848 bytes)

Copyright:
New IT Solutions

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\????? ???????? ????????? ?????? ?? ??????? ??????????.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/16/2012 6:16:05 PM

Valid to:
11/16/2013 4:30:34 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B2A165690BBAA

File PE Metadata
Compilation timestamp:
4/10/2010 2:19:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:sWO7Z+ByxlOyexgcs6ArgkStxQM7osPuI+sPtumURA8oGNoD8MyeDFtGi5PHgS4A:st78By/OyexgT1l+P7jPz+dtHoKc/GMH

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)