مذكرات علوم 4متوسط.exe

SuperCharging

New IT Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application مذكرات علوم 4متوسط.exe by New IT Limited has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the New IT Desktop Setup installer.
Publisher:
SPC LLC  (signed by New IT Limited)

Product:
SuperCharging

Description:
DWD

Version:
3, 3, 17, 0

MD5:
71d4541716791c91e7be30e32fb053ee

SHA-1:
c62e55f3a950c59fe25d39e19ee3bd2d5d4cd48a

SHA-256:
9b60ce4070501fd37249f776ef702884bb6295ac40bb4813586b6555c953d602

Scanner detections:
14 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/18/2024 2:53:09 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.206.64

avast!
Win32:FourShared-D [PUP]
150101-1

AVG
Newitli
2016.0.3213

ESET NOD32
Win32/4Shared.S potentially unwanted application
7.0.302.0

F-Prot
W32/A-01474e23
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.193.14818

McAfee
Obfosha
5600.6869

NANO AntiVirus
Trojan.Win32.MLW.dcdomp
0.30.0.65070

Reason Heuristics
PUP.New IT Limited
15.1.31.8

Sophos
PUA '4Share Downloader'
5.10

Vba32 AntiVirus
Downloader.GetFaster
3.12.26.3

VIPRE Antivirus
Threat.4895345
36666

Zillya! Antivirus
Backdoor.PePatch.Win32.40003
2.0.0.2049

File size:
450.2 KB (460,960 bytes)

Product version:
3, 3, 17, 0

Copyright:
2013

Trademarks:
-

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\?????? ???? 4?????.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
4/10/2014 4:50:45 PM

Valid to:
12/30/2016 8:33:53 AM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B90BA60B54B37

File PE Metadata
Compilation timestamp:
4/17/2014 6:26:16 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:HneADuJuYPG6g3uFLnd2wSFfJUQwhinV26tKkJZXlBu9zXYbB:HndDahG6g3I2wWfqrhiV2+LVBua

Entry address:
0x29944

Entry point:
E8, 54, 98, 00, 00, E9, 78, FE, FF, FF, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B, 4C, 24, 04...
 
[+]

Code size:
316 KB (323,584 bytes)

Remove مذكرات علوم 4متوسط.exe - Powered by Reason Core Security